navidrome/server/subsonic
Deluan Quintão 1f861d27ef
fix(plugins): build public URLs on the caller's address instead of localhost (#6059)
* fix(plugins): build public URLs on the caller's address instead of localhost

The artwork host service had no `*http.Request`, so it passed `nil` to
`publicurl.ImageURL`. With neither `ShareURL` nor `BaseURL` configured, that
produced `http://localhost/share/img/...`, which is useless to anything outside
the server. The Discord Rich Presence plugin explicitly drops localhost URLs, so
it fell back to the Navidrome logo instead of the real cover art.

`serverAddressMiddleware` already works out the client-facing scheme and host
from the `X-Forwarded-*` headers. It now also records them in the request
context, and `publicurl` takes a `context.Context` instead of an `*http.Request`
so any caller can reach them. Extism passes the caller's context through to host
functions, so plugins invoked during a request now get a reachable URL with no
configuration.

Switching the parameter also removes the need for a second, parallel entry
point: the package previously wanted only a scheme, a host, and a context, and
took a whole request to get them. `AbsoluteURL` no longer dereferences a
possibly-nil request on its parse-error path.

Plugin calls that start from `context.Background()` (scheduler and websocket
callbacks, the buffered scrobble drain) still fall back to localhost, since they
have no request to learn from. A debug log now points at `ShareURL` when that
happens.

* fix(publicurl): include the configured port in the localhost fallback

The last-resort fallback built `http://localhost/...`, which points at port 80
and so is unreachable for a server listening anywhere else — the default 4533
included. Use `conf.Server.Port` so a consumer on the same machine can actually
fetch the URL.

* fix(publicurl): use https in the localhost fallback when TLS is configured

The fallback hardcoded the http scheme, so a TLS-only server with no BaseURL
advertised a URL it does not answer on. Mirror the server's own switch, which
requires both a certificate and a key.

* refactor(publicurl): tidy the localhost fallback and its tests

Use gg.If for the fallback scheme so it reads as an expression, like the
BaseScheme branch above it, instead of assigning http and overwriting it.

Drop two tests the ctx refactor left redundant: one asserted PublicURL "works
without a request" but became a byte-identical copy of the ShareURL spec once
the *http.Request parameter went away, and the two port specs differed only in
the integer, where the non-default port is the stronger assertion.

* refactor(conf): add TLSEnabled and use it instead of repeating the predicate

Whether the server speaks HTTPS was decided inline in three unconnected
places. This PR added the third, in a URL-building package that has no
business inferring the transport config.

Move the rule to conf, next to the fields it derives from, and call it from
publicurl and the insights collector. server.Run keeps its own expression: it
takes the certificate and key as parameters, and its test passes values that
do not come from the config.
2026-08-31 21:27:43 -04:00
..
e2e feat(ui): add Refresh Metadata to the album and artist context menus (#6036) 2026-08-25 23:59:40 -04:00
responses feat(subsonic): add OpenSubsonic work and movement attributes (#5659) 2026-06-24 09:10:00 -04:00
album_lists.go perf(genre): index genre filtering via join tables across all APIs (#5940) 2026-08-11 08:00:50 -04:00
album_lists_test.go feat(subsonic): add sonicSimilarity extension as plugin capability (#5419) 2026-04-27 17:50:09 -04:00
api.go fix(playlist): block track edits on synced playlists across all APIs (#5984) 2026-08-19 08:47:53 -04:00
api_suite_test.go refactor(lyrics): single ParseLyrics entry point + all-format plugin lyrics (#5632) 2026-06-19 18:25:35 -04:00
api_test.go fix(share): enforce per-user ownership on share reads 2026-06-05 15:50:59 -04:00
bookmarks.go refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
browsing.go fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
browsing_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
helpers.go fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
helpers_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
jukebox.go refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
library_scanning.go refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
library_scanning_test.go fix(subsonic): require admin access for Subsonic management endpoints (#5510) 2026-05-19 14:23:38 -03:00
lyrics.go fix(subsonic): emit agent-specific cueLine values (#5679) 2026-06-28 18:14:18 -04:00
lyrics_test.go fix(scanner): stop logging expected lyrics sniff misses as warnings (#5702) 2026-07-02 09:46:57 -04:00
media_annotation.go refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
media_annotation_test.go feat(playlists): per-user starred/rating annotations (backend) (#5749) 2026-07-14 07:38:25 -04:00
media_retrieval.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
media_retrieval_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
middlewares.go feat(jellyfin): non-expiring, audience-scoped tokens revocable by password change (#6013) 2026-08-22 20:36:24 -04:00
middlewares_test.go feat(jellyfin): non-expiring, audience-scoped tokens revocable by password change (#6013) 2026-08-22 20:36:24 -04:00
opensubsonic.go feat(subsonic): Implement OpenSubsonic topSongsByArtistId extension (#5853) 2026-08-02 12:39:51 -04:00
opensubsonic_test.go feat(subsonic): Implement OpenSubsonic topSongsByArtistId extension (#5853) 2026-08-02 12:39:51 -04:00
playlists.go fix(playlist): block track edits on synced playlists across all APIs (#5984) 2026-08-19 08:47:53 -04:00
playlists_test.go fix(playlist): block track edits on synced playlists across all APIs (#5984) 2026-08-19 08:47:53 -04:00
radio.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
radio_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
searching.go fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
searching_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
sharing.go fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
sonic_similarity.go feat(subsonic): add sonicSimilarity extension as plugin capability (#5419) 2026-04-27 17:50:09 -04:00
stream.go fix(transcoding): cap concurrent transcodes to prevent ffmpeg DoS (#5522) 2026-05-24 00:24:30 -03:00
system.go Some cleanup, adding missing context handling 2022-12-06 19:57:47 -05:00
transcode.go fix(streaming): surface why a transcode decision failed (#5820) 2026-07-19 18:51:32 -04:00
transcode_test.go fix(streaming): surface why a transcode decision failed (#5820) 2026-07-19 18:51:32 -04:00
users.go refactor: multiple syntax updates for Go 1.26 2026-05-19 18:02:36 -03:00
users_test.go refactor: rename EnableCoverArtUpload to EnableArtworkUpload 2026-03-27 19:33:46 -04:00