navidrome/server
Deluan Quintão fb45ad7b9c
fix(auth): ExtAuth logout redirect on unauthenticated loads, and warning spam from untrusted sources (#6176)
* fix(ui): only redirect to ExtAuth logout URL for proxy-authenticated sessions

react-admin calls authProvider.logout() when the boot-time checkAuth fails
and after a 401, not only when the user clicks Logout. With
ExtAuth.LogoutURL set, every unauthenticated page load (e.g. direct LAN
access that bypasses the auth proxy) was sent to the IdP sign-out page and
the login form was never shown.

Redirect only when the page was authenticated by the reverse proxy
(config.auth is present). Other sessions fall back to the login form.

Fixes #6175

Signed-off-by: Deluan <deluan@navidrome.org>

* fix(server): only warn about untrusted ExtAuth sources when the header is sent

UsernameFromExtAuthHeader checked the source IP before looking for the user
header, so every request from an IP outside ExtAuth.TrustedSources logged a
warning, even when it carried no header at all. With direct LAN access
alongside a forward-auth proxy, a single polling client produced a constant
stream of warnings (twice per Subsonic request, since the middleware chain
resolves the username in both checkRequiredParameters and authenticate).

Look for the header first and warn only when an untrusted source actually
sends it, which is the case worth seeing: a misconfigured proxy or a spoof
attempt.

Signed-off-by: Deluan <deluan@navidrome.org>

---------

Signed-off-by: Deluan <deluan@navidrome.org>
2026-09-19 17:08:49 -04:00
..
backgrounds fix: assorted scanner, plugin, and server fixes from the Go 1.27 work (#6050) 2026-08-30 21:24:50 -04:00
events fix(ui): activity Indicator switching constantly between online/offline (#5054) 2026-02-17 14:47:20 -05:00
filter perf(genre): index genre filtering via join tables across all APIs (#5940) 2026-08-11 08:00:50 -04:00
imghttp feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
jellyfin feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
nativeapi feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
public fix(plugins): build public URLs on the caller's address instead of localhost (#6059) 2026-08-31 21:27:43 -04:00
subsonic fix(jellyfin): match Jellyfin on login SessionInfo, item types and universal streams (#6161) 2026-09-17 23:48:39 -04:00
testdata fix(server): improve error message for encrypted TLS private keys (#4742) 2025-11-28 17:08:34 -05:00
auth.go fix(auth): ExtAuth logout redirect on unauthenticated loads, and warning spam from untrusted sources (#6176) 2026-09-19 17:08:49 -04:00
auth_test.go fix(auth): ExtAuth logout redirect on unauthenticated loads, and warning spam from untrusted sources (#6176) 2026-09-19 17:08:49 -04:00
initial_setup.go fix(transcoding): include ffprobe in MSI and fall back gracefully when absent (#5326) 2026-04-07 20:11:38 -04:00
initial_setup_test.go Upgrade Ginkgo to V2 2022-07-26 16:53:17 -04:00
middlewares.go fix(server): key the login rate limit on a trust-aware client IP 2026-09-10 08:59:01 -04:00
middlewares_test.go fix(server): key the login rate limit on a trust-aware client IP 2026-09-10 08:59:01 -04:00
serve_index.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
serve_index_test.go feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
server.go fix: miscellaneous fixes for shares, artwork resize, auth limits, and watcher start (#6098) 2026-09-11 15:03:54 -04:00
server_suite_test.go Rename log.LevelCritical to log.LevelFatal 2022-12-21 14:53:36 -05:00
server_test.go ci: run Go tests on Windows (#5380) 2026-04-19 13:16:47 -04:00
throttle_backlog.go chore: go fix 2026-05-28 22:13:05 -03:00
throttle_backlog_test.go fix(test): prevent flaky deadlock in throttle backlog test (#5474) 2026-05-06 11:03:11 -04:00