navidrome/core
Deluan Quintão 8e784b6af7
fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179)
On a multi-library instance, a few reads and writes built their own queries
without the per-user library filter that every other media read applies. A
user granted only some libraries could see, and store, tracks from libraries
they had no access to.

- getBookmarks now filters the query. It has to be the query and not the
  result: the loop below it pre-sizes the response from the bookmark count,
  so a row dropped afterwards would emit an empty bookmark entry.
- createBookmark rejects an id the caller cannot read, returning error 70 to
  match getSong. Stored rows are left alone rather than purged, so a
  temporary revoke does not lose saved playback positions.
- playlistTrackRepository Read, Count and GetAlbumIDs get the filter their
  siblings CountAll and GetMediaFileIDs already had. Read is the one that
  mattered most: its id is the integer playlist position, so it needed no
  track id at all.
- Playlist track writes are filtered in playlistRepository.addTracks, the
  only writer of playlist_tracks rows apart from smart playlists, so Add,
  Insert, AddAlbums/AddArtists/AddDiscs and a full replace through Put all
  go through it. Insert reserves a slot per requested id, so when the filter
  drops one it renumbers to close the hole.
- playTracker.GetNowPlaying honours its context instead of discarding it.
  The cache is process-global, so the filter belongs in the tracker rather
  than in the Subsonic handler, and any future caller inherits it.

Admins and single-library installs are unaffected: applyLibraryFilter and
HasLibraryAccess both short-circuit for them. Scanner playlist sync runs as
admin, and M3U and CLI imports already resolve tracks through FindByPaths as
the same user, so neither changes.
2026-09-20 12:37:18 -04:00
..
agents feat(plugins): surface the valid agent names in logs and the Plugins UI (#5910) 2026-08-30 11:11:35 -04:00
artwork test(artwork): cover artist folder lookup for a single album without images 2026-09-17 10:59:28 -04:00
auth feat(jellyfin): non-expiring, audience-scoped tokens revocable by password change (#6013) 2026-08-22 20:36:24 -04:00
external chore(deps): upgrade to Go 1.27 (#5990) 2026-08-30 12:43:15 -04:00
ffmpeg fix(transcoding): make piped FLAC transcodes seekable 2026-09-07 16:47:42 -04:00
lyrics fix(scanner): stop logging expected lyrics sniff misses as warnings (#5702) 2026-07-02 09:46:57 -04:00
matcher feat(listenbrainz): match collaboration top-songs via all credited artist MBIDs (#5670) 2026-06-26 17:06:14 -04:00
metrics fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
playback chore(deps): upgrade to Go 1.27 (#5990) 2026-08-30 12:43:15 -04:00
playlists feat(jellyfin): advertise Jellyfin 12.1.0 and add the missing 12.x quick wins (#6163) 2026-09-19 13:19:48 -04:00
publicurl fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
quickconnect feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
scrobbler fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
sonic feat(jellyfin): AudioMuse-AI compatible sonic endpoints (#5782) 2026-07-15 20:44:56 -04:00
storage fix: miscellaneous fixes for shares, artwork resize, auth limits, and watcher start (#6098) 2026-09-11 15:03:54 -04:00
stream fix(jellyfin): match Jellyfin on login SessionInfo, item types and universal streams (#6161) 2026-09-17 23:48:39 -04:00
archiver.go feat(artist): add Share and Download actions to the Artist detail page (#5944) 2026-08-12 11:59:56 -04:00
archiver_test.go feat(artist): add Share and Download actions to the Artist detail page (#5944) 2026-08-12 11:59:56 -04:00
common.go feat(bfr): Big Refactor: new scanner, lots of new fields and tags, improvements and DB schema changes (#2709) 2025-02-19 20:35:17 -05:00
common_test.go test: unskip path-separator tests on Windows (#5381) (#5916) 2026-08-19 11:50:32 -04:00
core_suite_test.go Rename log.LevelCritical to log.LevelFatal 2022-12-21 14:53:36 -05:00
inspect.go refactor: multiple syntax updates for Go 1.26 2026-05-19 18:02:36 -03:00
library.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
library_test.go fix(nativeapi): stop partial PUTs from clearing untouched columns (#6058) 2026-08-31 11:21:32 -04:00
maintenance.go feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
maintenance_test.go feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
players.go feat(server): group Subsonic config options together 2025-03-05 12:29:30 -08:00
players_test.go Use userId in player, other fixes (#3182) 2024-08-03 13:37:21 -04:00
share.go Merge commit from fork 2026-09-12 13:38:08 -04:00
share_test.go Merge commit from fork 2026-09-12 13:38:08 -04:00
user.go refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
user_test.go feat(plugins): New Plugin System with multi-language PDK support (#4833) 2026-01-14 19:22:48 -05:00
wire_providers.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00