navidrome/utils
Deluan Quintão 237276efcd
fix(artwork): block private and loopback addresses in remote image fetches (#6181)
* fix(artwork): block private and loopback addresses in remote image fetches

fromURL fetched any URL with a plain HTTP client, and two untrusted inputs reach it. A playlist
can set #EXTALBUMARTURL to an http(s) URL, which the artwork worker later fetches when
EnableM3UExternalAlbumArt is on, so any user who can import a playlist controls the target.
Metadata agents, including WASM plugins without the http permission, return image URLs that the
core fetches too. Either path could make the server request loopback, LAN or link-local
addresses and store the response as artwork that is served back.

Add httpclient.NewExternal, which dials through a net.Dialer Control hook that rejects private,
loopback, link-local and unspecified addresses. The check runs at dial time on the resolved IP,
so DNS names, redirects and DNS rebinding are covered. fromURL now uses one shared client built
with it and treats a refused address as a definitive miss, so the item settles absent instead of
retrying and tripping the agent's circuit breaker. httpclient.New is unchanged for the other callers.

The IP classification moves from plugins to the new utils/netguard package, shared by the plugin
host client and the new constructor. The artwork test suite swaps in a client that allows
loopback so existing specs can keep using httptest servers; the fromURL specs use the production
client to assert the refusal.

* fix(httpclient): keep dialing a configured proxy in the guarded client

The guard runs on the resolved address, and with HTTP_PROXY set that address is the proxy, not
the image host. A proxy on a private address would have had every remote artwork fetch refused,
and a refusal settles the item as absent, so covers would silently disappear for those setups.

Dial the configured proxy endpoint directly and keep the guard for every other dial. A proxy
relays the request itself, so it is the operator's egress policy, the same one every other
httpclient.New caller already goes through.

* fix(httpclient): exempt only the hop that actually goes through the proxy

The exemption matched any dial to a configured proxy's address, but net/http never proxies
loopback targets, so a URL aimed at a loopback proxy was dialed directly and skipped the guard.
That let an image URL reach that one address.

Tag each request with the proxy it resolves to and exempt a dial only when it is that hop.
Redirects re-enter the RoundTripper, so every hop is tagged on its own.
2026-09-20 20:46:46 -04:00
..
cache fix(stream): abort the response when a transcoded stream is truncated (#6035) 2026-08-25 18:48:43 -04:00
chrono refactor: multiple syntax updates for Go 1.26 2026-05-19 18:02:36 -03:00
gg feat(subsonic): add structured sidecar lyrics support with OpenSubsonic v2 karaoke cues and agent layers (#5076) 2026-06-19 12:00:58 -04:00
gravatar feat(bfr): Big Refactor: new scanner, lots of new fields and tags, improvements and DB schema changes (#2709) 2025-02-19 20:35:17 -05:00
hasher refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
httpclient fix(artwork): block private and loopback addresses in remote image fetches (#6181) 2026-09-20 20:46:46 -04:00
ioutils fix: handle UTF BOM in lyrics and playlist files (#4637) 2025-10-31 09:07:23 -04:00
jsoncommentstrip refactor(jsoncommentstrip): replace go-jsoncommentstrip with custom JSON comment stripping 2026-03-14 10:18:56 -04:00
merge Upgrade Go to 1.23 (#3190) 2024-08-19 17:47:54 -04:00
nanoid refactor(nanoid): replace gonanoid with custom nanoid implementation for ID generation 2026-03-13 21:06:26 -04:00
natural feat: add optional natural sort order for names and titles (#6015) 2026-08-23 14:31:37 -04:00
netguard fix(artwork): block private and loopback addresses in remote image fetches (#6181) 2026-09-20 20:46:46 -04:00
number chore(deps): remove direct dependency on golang.org/x/exp 2025-12-31 17:03:44 -05:00
pl chore: upgrade golangci-lint to 2.11 and fix lint issues 2026-03-06 19:23:47 -05:00
random refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
req refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
run refactor: rename chain package to run and update references 2025-06-14 17:19:06 -04:00
shellquote refactor(shellquote): replace go-shellquote with custom shell quoting implementation 2026-03-14 10:23:45 -04:00
singleton fix: assorted scanner, plugin, and server fixes from the Go 1.27 work (#6050) 2026-08-30 21:24:50 -04:00
slice perf(subsonic): speed up artist search3 deep-offset pagination (#5620) 2026-06-16 21:47:15 -04:00
str fix(search): artists with atomic non-ASCII names unfindable after FTS5 migration (#5703) 2026-07-02 12:53:10 -04:00
context.go Refactored agents calling into its own struct 2021-06-08 17:00:02 -04:00
context_test.go Upgrade Ginkgo to V2 2022-07-26 16:53:17 -04:00
encrypt.go feat(bfr): Big Refactor: new scanner, lots of new fields and tags, improvements and DB schema changes (#2709) 2025-02-19 20:35:17 -05:00
encrypt_test.go Upgrade Ginkgo to V2 2022-07-26 16:53:17 -04:00
files.go feat(playlist): support #EXTALBUMARTURL directive and sidecar images (#5131) 2026-03-02 11:39:59 -05:00
files_test.go ci: run Go tests on Windows (#5380) 2026-04-19 13:16:47 -04:00
index_group_parser.go refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
index_group_parser_test.go Upgrade Ginkgo to V2 2022-07-26 16:53:17 -04:00
limiter.go feat(bfr): Big Refactor: new scanner, lots of new fields and tags, improvements and DB schema changes (#2709) 2025-02-19 20:35:17 -05:00
time.go feat(smartplaylist): per-playlist refreshDelay for stable daily/weekly playlists (#5790) 2026-07-16 22:20:35 -04:00
time_test.go feat(smartplaylist): per-playlist refreshDelay for stable daily/weekly playlists (#5790) 2026-07-16 22:20:35 -04:00
utils_suite_test.go Upgrade Ginkgo to V2 2022-07-26 16:53:17 -04:00