navidrome/persistence
Deluan Quintão 8e784b6af7
fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179)
On a multi-library instance, a few reads and writes built their own queries
without the per-user library filter that every other media read applies. A
user granted only some libraries could see, and store, tracks from libraries
they had no access to.

- getBookmarks now filters the query. It has to be the query and not the
  result: the loop below it pre-sizes the response from the bookmark count,
  so a row dropped afterwards would emit an empty bookmark entry.
- createBookmark rejects an id the caller cannot read, returning error 70 to
  match getSong. Stored rows are left alone rather than purged, so a
  temporary revoke does not lose saved playback positions.
- playlistTrackRepository Read, Count and GetAlbumIDs get the filter their
  siblings CountAll and GetMediaFileIDs already had. Read is the one that
  mattered most: its id is the integer playlist position, so it needed no
  track id at all.
- Playlist track writes are filtered in playlistRepository.addTracks, the
  only writer of playlist_tracks rows apart from smart playlists, so Add,
  Insert, AddAlbums/AddArtists/AddDiscs and a full replace through Put all
  go through it. Insert reserves a slot per requested id, so when the filter
  drops one it renumbers to close the hole.
- playTracker.GetNowPlaying honours its context instead of discarding it.
  The cache is process-global, so the filter belongs in the tracker rather
  than in the Subsonic handler, and any future caller inherits it.

Admins and single-library installs are unaffected: applyLibraryFilter and
HasLibraryAccess both short-circuit for them. Scanner playlist sync runs as
admin, and M3U and CLI imports already resolve tracks through FindByPaths as
the same user, so neither changes.
2026-09-20 12:37:18 -04:00
..
e2e feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
album_repository.go fix(artwork): never retry absent artwork on its own (#6054) 2026-09-01 20:48:41 -04:00
album_repository_test.go fix(artwork): never retry absent artwork on its own (#6054) 2026-09-01 20:48:41 -04:00
artist_repository.go Merge commit from fork 2026-09-12 13:37:33 -04:00
artist_repository_test.go Merge commit from fork 2026-09-12 13:37:33 -04:00
artwork_hydration.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
artwork_hydration_test.go fix(artwork): never retry absent artwork on its own (#6054) 2026-09-01 20:48:41 -04:00
artwork_queue_repository.go fix(artwork): never retry absent artwork on its own (#6054) 2026-09-01 20:48:41 -04:00
artwork_queue_repository_test.go fix(artwork): never retry absent artwork on its own (#6054) 2026-09-01 20:48:41 -04:00
artwork_repository.go feat(artwork): store the resolution trace so artwork explain works offline (#5980) 2026-08-21 10:24:01 -04:00
artwork_repository_test.go feat(artwork): store the resolution trace so artwork explain works offline (#5980) 2026-08-21 10:24:01 -04:00
collation_test.go perf(db): index media_file album/artist sort orders (#5706) 2026-07-03 08:58:55 -04:00
criteria_sql.go feat(smartplaylists): add support for referencing playlists using paths (#5187) 2026-09-19 21:05:58 -04:00
criteria_sql_benchmark_test.go feat(scrobbler): add per-user scrobble filter (#5964) 2026-08-15 16:10:53 -04:00
criteria_sql_test.go feat(smartplaylists): add support for referencing playlists using paths (#5187) 2026-09-19 21:05:58 -04:00
export_test.go feat(bfr): Big Refactor: new scanner, lots of new fields and tags, improvements and DB schema changes (#2709) 2025-02-19 20:35:17 -05:00
folder_repository.go fix(artwork): re-resolve artwork when image files change on disk (#5965) 2026-08-16 13:24:07 -04:00
folder_repository_test.go test: unskip path-separator tests on Windows (#5381) (#5916) 2026-08-19 11:50:32 -04:00
genre_repository.go fix(jellyfin): resolve genre id as a MusicGenre item 2026-08-10 21:37:57 -04:00
genre_repository_test.go refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
helpers.go feat: add optional natural sort order for names and titles (#6015) 2026-08-23 14:31:37 -04:00
helpers_test.go feat: add optional natural sort order for names and titles (#6015) 2026-08-23 14:31:37 -04:00
item_tags_test.go perf(genre): index genre filtering via join tables across all APIs (#5940) 2026-08-11 08:00:50 -04:00
library_repository.go fix(server): update StoreMusicFolder to skip updates when path is unchanged 2026-09-06 12:40:07 -04:00
library_repository_test.go fix(server): update StoreMusicFolder to skip updates when path is unchanged 2026-09-06 12:40:07 -04:00
mediafile_repository.go feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
mediafile_repository_test.go feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
persistence.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
persistence_suite_test.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
persistence_test.go fix(server): play queue should not return empty entries for deleted tracks 2024-09-20 11:22:37 -04:00
player_repository.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
player_repository_test.go fix(share): enforce per-user ownership on share reads 2026-06-05 15:50:59 -04:00
playlist_repository.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
playlist_repository_test.go fix(artwork): never retry absent artwork on its own (#6054) 2026-09-01 20:48:41 -04:00
playlist_track_repository.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
playlist_track_repository_test.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
playqueue_repository.go refactor: multiple syntax updates for Go 1.26 2026-05-19 18:02:36 -03:00
playqueue_repository_test.go fix(server): ensure single record per user by reusing existing playqueue ID 2025-06-11 17:26:13 -04:00
plugin_cleanup.go feat(plugins): New Plugin System with multi-language PDK support (#4833) 2026-01-14 19:22:48 -05:00
plugin_cleanup_test.go feat(plugins): New Plugin System with multi-language PDK support (#4833) 2026-01-14 19:22:48 -05:00
plugin_repository.go fix(nativeapi): stop partial PUTs from clearing untouched columns (#6058) 2026-08-31 11:21:32 -04:00
plugin_repository_test.go fix(plugins): clear plugin errors on startup to allow retrying 2026-03-02 08:56:56 -05:00
property_repository.go Replace beego/orm with dbx (#2693) 2023-12-09 13:52:17 -05:00
property_repository_test.go revert: separation of write and read DBs 2024-11-19 18:41:50 -05:00
radio_repository.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
radio_repository_test.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
scrobble_buffer_repository.go fix(plugins): discard buffered scrobbles when a plugin is removed (#5737) 2026-07-08 12:37:17 -04:00
scrobble_buffer_repository_test.go fix(plugins): discard buffered scrobbles when a plugin is removed (#5737) 2026-07-08 12:37:17 -04:00
scrobble_repository.go feat(server): add scrobble history Native API (#5761) 2026-07-13 11:32:03 -04:00
scrobble_repository_test.go feat(server): add scrobble history Native API (#5761) 2026-07-13 11:32:03 -04:00
share_repository.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
share_repository_test.go Merge commit from fork 2026-09-12 13:38:08 -04:00
smart_playlist_repository.go feat(smartplaylists): add support for referencing playlists using paths (#5187) 2026-09-19 21:05:58 -04:00
smart_playlist_repository_test.go feat(smartplaylists): add support for referencing playlists using paths (#5187) 2026-09-19 21:05:58 -04:00
sort_index_coverage_test.go perf(db): index media_file album/artist sort orders (#5706) 2026-07-03 08:58:55 -04:00
sql_annotations.go feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
sql_annotations_test.go feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
sql_base_repository.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
sql_base_repository_test.go fix(jellyfin): honor the Filters, SortBy and MaxHeight params clients actually send (#5981) 2026-08-19 08:36:44 -04:00
sql_bookmarks.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
sql_bookmarks_test.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
sql_participations.go perf(persistence): use *_artists join tables for artist participant filters (#5930) 2026-08-10 11:42:27 -04:00
sql_restful.go fix(jellyfin): honor the Filters, SortBy and MaxHeight params clients actually send (#5981) 2026-08-19 08:36:44 -04:00
sql_restful_test.go feat(subsonic): sort search3 results by relevance (#5086) 2026-02-23 08:51:54 -05:00
sql_search.go perf(subsonic): speed up artist search3 deep-offset pagination (#5620) 2026-06-16 21:47:15 -04:00
sql_search_fts.go feat(search): rank exact matches above prefix matches (#5704) 2026-07-02 15:51:03 -04:00
sql_search_fts_test.go feat(search): rank exact matches above prefix matches (#5704) 2026-07-02 15:51:03 -04:00
sql_search_like.go chore: go fix 2026-05-28 22:13:05 -03:00
sql_search_like_test.go feat(subsonic): sort search3 results by relevance (#5086) 2026-02-23 08:51:54 -05:00
sql_search_test.go feat(subsonic): sort search3 results by relevance (#5086) 2026-02-23 08:51:54 -05:00
sql_tags.go perf(genre): index genre filtering via join tables across all APIs (#5940) 2026-08-11 08:00:50 -04:00
tag_library_filtering_test.go refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
tag_repository.go feat(jellyfin): filter items by year and record label (#5817) 2026-07-19 12:39:31 -04:00
tag_repository_test.go refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
transcoding_repository.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
transcoding_repository_test.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
user_props_repository.go Replace beego/orm with dbx (#2693) 2023-12-09 13:52:17 -05:00
user_repository.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
user_repository_test.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00