mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-06 13:26:38 +08:00
fix(auth/images): long-lived Emby token, unthrottle refresh, serve library posters
Three regressions reported on third-party clients and the web UI: - Third-party clients (Emby/Jellyfin) dropped login / could not play / could not refresh the library, roughly hourly. The Emby AuthenticateByName response returned the 60-minute access token, but Emby clients have no refresh mechanism and reuse the AccessToken until logout. Issue a long-lived (30d) token for the Emby compat layer via AuthService.IssueEmbyToken so device sessions persist. - Web could be thrown back to login under load: /auth/refresh was inside the IP rate-limited /auth group, so multiple users/tabs behind one reverse-proxy/NAT IP exhausted the budget and refresh failed -> logout. Only login/register are rate-limited now (raised to 30/min for shared IPs); refresh is excluded (already protected by a one-time refresh token). - Posters/images stopped displaying on the web home and other pages (refresh did not help). The SSRF/path hardening (a) blocked the image proxy whenever a hostname *resolved* to a private IP, which happens under GFW DNS poisoning of public CDNs like image.tmdb.org, and (b) restricted local image reads to data/cache/movies/tv/anime dirs only, dropping sidecar posters stored under arbitrary per-library roots to a placeholder. isPrivateHost now only blocks literal private/loopback IPs (real SSRF vectors) and ImageProxy also allows reads under configured library roots. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -5,8 +5,10 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/glebarez/sqlite"
|
||||
"github.com/golang-jwt/jwt/v5"
|
||||
"go.uber.org/zap"
|
||||
"gorm.io/gorm"
|
||||
|
||||
@@ -190,3 +192,35 @@ func TestDefaultAdminCannotBeDemoted(t *testing.T) {
|
||||
t.Fatal("expected default admin demotion to be rejected")
|
||||
}
|
||||
}
|
||||
|
||||
// TestIssueEmbyTokenIsLongLived verifies the Emby/Jellyfin compatibility token
|
||||
// outlives the 60-minute access token (Emby clients have no refresh mechanism,
|
||||
// so a short token caused them to drop login / fail playback hourly), parses
|
||||
// with the JWT secret, and carries the user's identity/role/tier.
|
||||
func TestIssueEmbyTokenIsLongLived(t *testing.T) {
|
||||
_, auth, _, _ := newAuthTestServices(t)
|
||||
u := &model.User{Base: model.Base{ID: "u-emby"}, Username: "emby", Role: "user", Tier: "plus"}
|
||||
|
||||
tok, err := auth.IssueEmbyToken(u)
|
||||
if err != nil {
|
||||
t.Fatalf("IssueEmbyToken: %v", err)
|
||||
}
|
||||
|
||||
claims := &Claims{}
|
||||
parsed, err := jwt.ParseWithClaims(tok, claims, func(*jwt.Token) (interface{}, error) {
|
||||
return []byte("test-secret"), nil
|
||||
})
|
||||
if err != nil || !parsed.Valid {
|
||||
t.Fatalf("token did not parse/validate: %v", err)
|
||||
}
|
||||
if claims.UserID != "u-emby" || claims.Role != "user" || claims.Tier != "plus" {
|
||||
t.Fatalf("unexpected claims: %+v", claims)
|
||||
}
|
||||
ttl := time.Until(claims.ExpiresAt.Time)
|
||||
if ttl <= AccessTokenDuration {
|
||||
t.Fatalf("emby token ttl %v not longer than access token ttl %v", ttl, AccessTokenDuration)
|
||||
}
|
||||
if ttl < EmbyTokenDuration-time.Hour {
|
||||
t.Fatalf("emby token ttl %v shorter than expected ~%v", ttl, EmbyTokenDuration)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user