fix: enforce user library ACL on mounted Emby libraries (#25)

Mounted Emby libraries were always appended to web/Emby library lists and
detail/play routes without checking allowed_library_ids, so restricted
users could still see and open them. Filter remotes with the same
visibility policy as local libraries across list/detail/series/stream and
Emby Views/Items/search/playback, and label mounts in the admin ACL UI.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: truewhile <truewhile@users.noreply.github.com>
This commit is contained in:
truewhile
2026-09-03 10:39:44 +08:00
committed by GitHub
parent 9ab32c10ca
commit 2b99f5f108
10 changed files with 172 additions and 18 deletions
@@ -278,12 +278,19 @@ export function AdminUserLibrariesDialog({
<div className="min-w-0 flex-1">
<p className="truncate text-xs font-semibold text-ink-600">
{lib.name}
{lib.is_remote_emby ? (
<span className="ml-1.5 rounded bg-sky-50 px-1.5 py-0.5 text-[10px] font-bold text-sky-700">
Emby 挂载
</span>
) : null}
</p>
<p
className="truncate text-[10px] text-sand-500"
title={lib.path}
title={lib.is_remote_emby ? lib.remote_source || lib.name : lib.path}
>
{lib.type} · {libraryDisplayPath(lib.path)}
{lib.is_remote_emby
? `远程 · ${lib.remote_source || 'Emby'}`
: `${lib.type} · ${libraryDisplayPath(lib.path)}`}
</p>
</div>
</div>