navidrome/server/subsonic
Deluan Quintão 8e784b6af7
fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179)
On a multi-library instance, a few reads and writes built their own queries
without the per-user library filter that every other media read applies. A
user granted only some libraries could see, and store, tracks from libraries
they had no access to.

- getBookmarks now filters the query. It has to be the query and not the
  result: the loop below it pre-sizes the response from the bookmark count,
  so a row dropped afterwards would emit an empty bookmark entry.
- createBookmark rejects an id the caller cannot read, returning error 70 to
  match getSong. Stored rows are left alone rather than purged, so a
  temporary revoke does not lose saved playback positions.
- playlistTrackRepository Read, Count and GetAlbumIDs get the filter their
  siblings CountAll and GetMediaFileIDs already had. Read is the one that
  mattered most: its id is the integer playlist position, so it needed no
  track id at all.
- Playlist track writes are filtered in playlistRepository.addTracks, the
  only writer of playlist_tracks rows apart from smart playlists, so Add,
  Insert, AddAlbums/AddArtists/AddDiscs and a full replace through Put all
  go through it. Insert reserves a slot per requested id, so when the filter
  drops one it renumbers to close the hole.
- playTracker.GetNowPlaying honours its context instead of discarding it.
  The cache is process-global, so the filter belongs in the tracker rather
  than in the Subsonic handler, and any future caller inherits it.

Admins and single-library installs are unaffected: applyLibraryFilter and
HasLibraryAccess both short-circuit for them. Scanner playlist sync runs as
admin, and M3U and CLI imports already resolve tracks through FindByPaths as
the same user, so neither changes.
2026-09-20 12:37:18 -04:00
..
e2e fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
responses feat(subsonic): add OpenSubsonic work and movement attributes (#5659) 2026-06-24 09:10:00 -04:00
album_lists.go perf(genre): index genre filtering via join tables across all APIs (#5940) 2026-08-11 08:00:50 -04:00
album_lists_test.go feat(subsonic): add sonicSimilarity extension as plugin capability (#5419) 2026-04-27 17:50:09 -04:00
api.go fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
api_suite_test.go refactor(lyrics): single ParseLyrics entry point + all-format plugin lyrics (#5632) 2026-06-19 18:25:35 -04:00
api_test.go fix(share): enforce per-user ownership on share reads 2026-06-05 15:50:59 -04:00
bookmarks.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
bookmarks_test.go fix: apply the per-user library filter to bookmarks, playlists and now-playing (#6179) 2026-09-20 12:37:18 -04:00
browsing.go fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
browsing_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
helpers.go fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
helpers_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
jukebox.go refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
library_scanning.go refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
library_scanning_test.go fix(subsonic): require admin access for Subsonic management endpoints (#5510) 2026-05-19 14:23:38 -03:00
lyrics.go fix(subsonic): emit agent-specific cueLine values (#5679) 2026-06-28 18:14:18 -04:00
lyrics_test.go fix(scanner): stop logging expected lyrics sniff misses as warnings (#5702) 2026-07-02 09:46:57 -04:00
media_annotation.go refactor(server): drop redundant error return from req.Strings parsing (#5812) 2026-07-18 19:30:04 -04:00
media_annotation_test.go feat(playlists): per-user starred/rating annotations (backend) (#5749) 2026-07-14 07:38:25 -04:00
media_retrieval.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
media_retrieval_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
middlewares.go feat(jellyfin): non-expiring, audience-scoped tokens revocable by password change (#6013) 2026-08-22 20:36:24 -04:00
middlewares_test.go feat(jellyfin): non-expiring, audience-scoped tokens revocable by password change (#6013) 2026-08-22 20:36:24 -04:00
opensubsonic.go feat(subsonic): Implement OpenSubsonic topSongsByArtistId extension (#5853) 2026-08-02 12:39:51 -04:00
opensubsonic_test.go feat(subsonic): Implement OpenSubsonic topSongsByArtistId extension (#5853) 2026-08-02 12:39:51 -04:00
playlists.go fix(subsonic): update the playlist changed timestamp when renaming a smart playlist (#6082) 2026-09-03 16:07:53 -04:00
playlists_test.go fix(subsonic): update the playlist changed timestamp when renaming a smart playlist (#6082) 2026-09-03 16:07:53 -04:00
radio.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
radio_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
searching.go fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
searching_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
sharing.go fix(subsonic): honor DefaultDownloadableShare in createShare (#6121) 2026-09-09 20:29:00 -04:00
sonic_similarity.go feat(subsonic): add sonicSimilarity extension as plugin capability (#5419) 2026-04-27 17:50:09 -04:00
stream.go fix(transcoding): cap concurrent transcodes to prevent ffmpeg DoS (#5522) 2026-05-24 00:24:30 -03:00
system.go Some cleanup, adding missing context handling 2022-12-06 19:57:47 -05:00
transcode.go fix(subsonic): don't re-encode a source already in the player's forced format 2026-09-07 14:56:41 -04:00
transcode_test.go fix(jellyfin): match Jellyfin on login SessionInfo, item types and universal streams (#6161) 2026-09-17 23:48:39 -04:00
users.go refactor: multiple syntax updates for Go 1.26 2026-05-19 18:02:36 -03:00
users_test.go refactor: rename EnableCoverArtUpload to EnableArtworkUpload 2026-03-27 19:33:46 -04:00