navidrome/server/nativeapi
Adrián Sánchez Zapico 27483a46dc
fix(server): fail startup on initial setup errors and fix JSON/M3U response headers (#5897)
* fix(server): stop swallowing errors and correct two response bugs

Four independent bugs found while reviewing the HTTP layer:

initial_setup.go: createInitialAdminUser assigned the users.Put error to a
shadowed err, so the outer err (always nil by then, since a CountAll failure
panics) was returned instead. A failure to create the admin user was reported
as success, and initialSetup went on to commit the "setup complete" property
in the same transaction — so no admin user existed and initial setup was
skipped on every later boot.

auth.go: createAdminUser logged the Put error but returned nil, so createAdmin
fell through to doLogin and answered 401 "Invalid username or password"
instead of surfacing the real failure. It also logged the whole model.User,
which puts the new admin's password in the log in clear text; every other call
site logs user.UserName.

native_api.go: writeDeleteManyResponse did not return after http.Error when
marshaling failed, then wrote a nil body over the 500. It also built the
single-id body by hand with html.EscapeString, which does not escape
backslashes, so an id ending in one produced `{"id":"a\"}` — invalid JSON.
Both shapes now go through json.Marshal. A failed Write is now logged rather
than answered with http.Error, which could not work once the body had started.

handle_shares.go: handleM3U set Content-Type after WriteHeader, so it was
never sent and shared playlists were served with a sniffed type.

Signed-off-by: zapisanchez <zapisanchez@gmail.com>

* fix(server): address review feedback

- writeDeleteManyResponse uses rest.RespondWithJSON, so the response now
  has Content-Type: application/json. This also removes a marshal error
  branch that could never run.
- createInitialAdminUser returns the CountAll error instead of panicking,
  and wraps its errors. initialSetup now stops the server with log.Fatal
  when setup fails. Before, the error was dropped and the server started
  with a half-done setup.
- Trim comments that described PR history.

---------

Signed-off-by: zapisanchez <zapisanchez@gmail.com>
Co-authored-by: Deluan <deluan@navidrome.org>
2026-09-23 12:10:25 -04:00
..
artists.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
config.go refactor(conf): replace eager dir creation with lazy Dir type (#5495) 2026-05-13 17:44:22 -03:00
config_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
delete_many_response_test.go fix(server): fail startup on initial setup errors and fix JSON/M3U response headers (#5897) 2026-09-23 12:10:25 -04:00
image_upload.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
inspect.go chore(deps): bump golangci-lint to v2.10.0 and suppress new gosec false positives 2026-02-17 09:28:42 -05:00
library.go fix: album statistics not updating after deleting missing files (#4668) 2025-11-08 20:11:00 -05:00
library_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
metadata.go feat(ui): add Refresh Metadata to the album and artist context menus (#6036) 2026-08-25 23:59:40 -04:00
metadata_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
missing.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
missing_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
native_api.go fix(server): fail startup on initial setup errors and fix JSON/M3U response headers (#5897) 2026-09-23 12:10:25 -04:00
native_api_song_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
native_api_suite_test.go Rename log.LevelCritical to log.LevelFatal 2022-12-21 14:53:36 -05:00
playlists.go sec(server): sanitize user-controlled filenames in Content-Disposition (#5895) 2026-09-23 09:47:16 -04:00
playlists_test.go sec(server): sanitize user-controlled filenames in Content-Disposition (#5895) 2026-09-23 09:47:16 -04:00
plugin.go feat(plugins): allow mounting library directories as read-write (#5122) 2026-02-28 10:59:13 -05:00
plugin_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
queue.go chore(deps): bump golangci-lint to v2.10.0 and suppress new gosec false positives 2026-02-17 09:28:42 -05:00
queue_test.go refactor: multiple syntax updates for Go 1.26 2026-05-19 18:02:36 -03:00
quickconnect.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
quickconnect_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
radios.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
translations.go feat(ui): show translation completion percentage in the language selector (#5979) 2026-08-18 09:32:26 -04:00
translations_test.go test: unskip path-separator tests on Windows (#5381) (#5916) 2026-08-19 11:50:32 -04:00
user_password_token_refresh_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00