mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-02 04:16:38 +08:00
fix: add global adult library visibility controls
This commit is contained in:
@@ -182,10 +182,19 @@ func updateSettingHandler(svc *service.Container) gin.HandlerFunc {
|
||||
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
oldValue := ""
|
||||
if req.Key == service.AdultLibraryIDsSettingKey {
|
||||
oldValue, _ = svc.Repo.Setting.Get(c.Request.Context(), req.Key)
|
||||
}
|
||||
if err := svc.Repo.Setting.Set(c.Request.Context(), req.Key, req.Value); err != nil {
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
oldAdultLibraryIDs := service.DecodeAllowedLibraryIDs(oldValue)
|
||||
newAdultLibraryIDs := service.DecodeAllowedLibraryIDs(req.Value)
|
||||
if req.Key == service.AdultLibraryIDsSettingKey && len(oldAdultLibraryIDs) == 0 && len(newAdultLibraryIDs) > 0 {
|
||||
_ = svc.Repo.DB.WithContext(c.Request.Context()).Model(&model.User{}).Where("hide_adult = ?", false).Update("hide_adult", true).Error
|
||||
}
|
||||
service.ApplyRuntimeSetting(svc.Cfg, req.Key, req.Value)
|
||||
if req.Key == "transcode.enabled" && !svc.Cfg.Transcoder.Enabled {
|
||||
svc.Transcoder.StopAll()
|
||||
|
||||
@@ -9,6 +9,7 @@ import (
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
|
||||
"github.com/ShukeBta/MediaStationGo/internal/middleware"
|
||||
"github.com/ShukeBta/MediaStationGo/internal/service"
|
||||
)
|
||||
|
||||
@@ -25,6 +26,17 @@ func listLibrariesHandler(svc *service.Container) gin.HandlerFunc {
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
role, _ := c.Get(middleware.CtxUserRole)
|
||||
if role != "admin" {
|
||||
visibility := mediaVisibilityForRequest(c, svc)
|
||||
filtered := libs[:0]
|
||||
for _, lib := range libs {
|
||||
if service.LibraryVisibleForUser(c.Request.Context(), svc.Repo, lib, visibility) {
|
||||
filtered = append(filtered, lib)
|
||||
}
|
||||
}
|
||||
libs = filtered
|
||||
}
|
||||
c.JSON(http.StatusOK, libs)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -18,8 +18,8 @@ func recentMediaHandler(svc *service.Container) gin.HandlerFunc {
|
||||
if limit <= 0 || limit > 100 {
|
||||
limit = 12
|
||||
}
|
||||
var items []model.Media
|
||||
if err := svc.Repo.DB.Order("created_at desc").Limit(limit).Find(&items).Error; err != nil {
|
||||
items, err := svc.Media.SearchMediaVisible(c.Request.Context(), "", limit, mediaVisibilityForRequest(c, svc))
|
||||
if err != nil {
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
|
||||
@@ -25,6 +25,12 @@ type seasonGroup struct {
|
||||
func listSeasonsHandler(svc *service.Container) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
libID := c.Param("id")
|
||||
if lib, err := svc.Repo.Library.FindByID(c.Request.Context(), libID); err == nil && lib != nil {
|
||||
if !service.LibraryVisibleForUser(c.Request.Context(), svc.Repo, *lib, mediaVisibilityForRequest(c, svc)) {
|
||||
c.JSON(http.StatusNotFound, gin.H{"error": "not found"})
|
||||
return
|
||||
}
|
||||
}
|
||||
var rows []model.Media
|
||||
err := svc.Repo.DB.Where(&model.Media{LibraryID: libID}).
|
||||
Order("season_num asc, episode_num asc").
|
||||
@@ -33,8 +39,12 @@ func listSeasonsHandler(svc *service.Container) gin.HandlerFunc {
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
visibility := mediaVisibilityForRequest(c, svc)
|
||||
buckets := make(map[int][]model.Media)
|
||||
for _, r := range rows {
|
||||
if !visibility.Allows(&r) {
|
||||
continue
|
||||
}
|
||||
buckets[r.SeasonNum] = append(buckets[r.SeasonNum], r)
|
||||
}
|
||||
out := make([]seasonGroup, 0, len(buckets))
|
||||
|
||||
@@ -33,6 +33,11 @@ func mediaVisibilityForRequest(c *gin.Context, svc *service.Container) service.M
|
||||
}
|
||||
visibility.IncludeNSFW = adultEnabled && profile.AllowAdult && !userHidesAdult
|
||||
visibility.AllowedLibraryIDs = profileAllowedLibraryIDs(*profile)
|
||||
if !visibility.IncludeNSFW {
|
||||
visibility.HiddenLibraryIDs = service.AdultLibraryIDs(c.Request.Context(), svc.Repo)
|
||||
} else {
|
||||
visibility.HiddenLibraryIDs = nil
|
||||
}
|
||||
return visibility
|
||||
}
|
||||
|
||||
|
||||
@@ -40,7 +40,7 @@ type User struct {
|
||||
Nickname string `gorm:"size:128" json:"nickname,omitempty"`
|
||||
Email string `gorm:"size:128" json:"email,omitempty"`
|
||||
AvatarURL string `gorm:"size:255" json:"avatar_url,omitempty"`
|
||||
HideAdult bool `gorm:"default:false" json:"hide_adult"`
|
||||
HideAdult bool `gorm:"default:true" json:"hide_adult"`
|
||||
ForcePasswordReset bool `gorm:"default:false" json:"force_password_reset"`
|
||||
IsActive bool `gorm:"default:true" json:"is_active"`
|
||||
LastLoginAt *time.Time `json:"last_login_at,omitempty"`
|
||||
|
||||
@@ -212,12 +212,16 @@ type MediaRepository struct{ db *gorm.DB }
|
||||
type MediaQueryFilter struct {
|
||||
IncludeNSFW bool
|
||||
AllowedLibraryIDs []string
|
||||
HiddenLibraryIDs []string
|
||||
}
|
||||
|
||||
func applyMediaQueryFilter(q *gorm.DB, filter MediaQueryFilter) *gorm.DB {
|
||||
if !filter.IncludeNSFW {
|
||||
q = q.Where("nsfw = ?", false)
|
||||
}
|
||||
if len(filter.HiddenLibraryIDs) > 0 {
|
||||
q = q.Where("library_id NOT IN ?", filter.HiddenLibraryIDs)
|
||||
}
|
||||
if len(filter.AllowedLibraryIDs) > 0 {
|
||||
q = q.Where("library_id IN ?", filter.AllowedLibraryIDs)
|
||||
}
|
||||
|
||||
@@ -68,6 +68,7 @@ func (s *AuthService) SeedAdmin(ctx context.Context) error {
|
||||
PasswordHash: hash,
|
||||
Role: "admin",
|
||||
Tier: "plus",
|
||||
HideAdult: true,
|
||||
ForcePasswordReset: pwd == "admin123",
|
||||
}
|
||||
if err := s.repo.User.Create(ctx, user); err != nil {
|
||||
@@ -112,6 +113,7 @@ func (s *AuthService) Register(ctx context.Context, username, password string) (
|
||||
PasswordHash: hash,
|
||||
Role: role,
|
||||
Tier: "free",
|
||||
HideAdult: true,
|
||||
}
|
||||
if err := s.repo.User.Create(ctx, u); err != nil {
|
||||
return nil, nil, err
|
||||
|
||||
@@ -55,6 +55,17 @@ func TestRegisterRejectsMoreThanTwentyUsers(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestRegisterDefaultsAdultLibrariesHidden(t *testing.T) {
|
||||
_, auth, _, _ := newAuthTestServices(t)
|
||||
user, _, err := auth.Register(context.Background(), "viewer", "password")
|
||||
if err != nil {
|
||||
t.Fatalf("register: %v", err)
|
||||
}
|
||||
if !user.HideAdult {
|
||||
t.Fatal("new users should hide adult libraries by default")
|
||||
}
|
||||
}
|
||||
|
||||
func TestDefaultPermissionsAreViewerOnly(t *testing.T) {
|
||||
perms := DefaultPermissions("user-1")
|
||||
if !perms.CanViewDashboard || !perms.CanPlayMedia || !perms.CanExternalPlayer {
|
||||
|
||||
@@ -175,6 +175,9 @@ func TestEmbyHidesAdultLibrariesForUserLock(t *testing.T) {
|
||||
if err := svc.repo.Library.Create(t.Context(), &adult); err != nil {
|
||||
t.Fatalf("create adult library: %v", err)
|
||||
}
|
||||
if err := svc.repo.Setting.Set(t.Context(), AdultLibraryIDsSettingKey, `["`+adult.ID+`"]`); err != nil {
|
||||
t.Fatalf("set adult libraries: %v", err)
|
||||
}
|
||||
if err := svc.repo.DB.Create(&model.Media{LibraryID: safe.ID, Title: "安全电影", Path: `/media/movies/a.mkv`}).Error; err != nil {
|
||||
t.Fatalf("create safe media: %v", err)
|
||||
}
|
||||
@@ -205,7 +208,7 @@ func newTestEmbyService(t *testing.T) *EmbyService {
|
||||
if err != nil {
|
||||
t.Fatalf("open db: %v", err)
|
||||
}
|
||||
if err := db.AutoMigrate(&model.Library{}, &model.Series{}, &model.Media{}, &model.Favorite{}, &model.PlaybackHistory{}, &model.User{}); err != nil {
|
||||
if err := db.AutoMigrate(&model.Library{}, &model.Series{}, &model.Media{}, &model.Favorite{}, &model.PlaybackHistory{}, &model.User{}, &model.Setting{}); err != nil {
|
||||
t.Fatalf("migrate: %v", err)
|
||||
}
|
||||
repos := repository.New(db)
|
||||
|
||||
@@ -26,6 +26,7 @@ type MediaService struct {
|
||||
type MediaVisibility struct {
|
||||
IncludeNSFW bool
|
||||
AllowedLibraryIDs []string
|
||||
HiddenLibraryIDs []string
|
||||
}
|
||||
|
||||
func (v MediaVisibility) Allows(media *model.Media) bool {
|
||||
@@ -35,6 +36,11 @@ func (v MediaVisibility) Allows(media *model.Media) bool {
|
||||
if !v.IncludeNSFW && media.NSFW {
|
||||
return false
|
||||
}
|
||||
for _, id := range v.HiddenLibraryIDs {
|
||||
if id == media.LibraryID {
|
||||
return false
|
||||
}
|
||||
}
|
||||
if len(v.AllowedLibraryIDs) == 0 {
|
||||
return true
|
||||
}
|
||||
@@ -182,6 +188,7 @@ func (s *MediaService) ListMediaVisible(ctx context.Context, libraryID string, p
|
||||
return s.repo.Media.ListByLibraryFiltered(ctx, libraryID, (page-1)*pageSize, pageSize, repository.MediaQueryFilter{
|
||||
IncludeNSFW: visibility.IncludeNSFW,
|
||||
AllowedLibraryIDs: visibility.AllowedLibraryIDs,
|
||||
HiddenLibraryIDs: visibility.HiddenLibraryIDs,
|
||||
})
|
||||
}
|
||||
|
||||
@@ -197,6 +204,7 @@ func (s *MediaService) SearchMediaVisible(ctx context.Context, query string, lim
|
||||
return s.repo.Media.SearchFiltered(ctx, query, limit, repository.MediaQueryFilter{
|
||||
IncludeNSFW: visibility.IncludeNSFW,
|
||||
AllowedLibraryIDs: visibility.AllowedLibraryIDs,
|
||||
HiddenLibraryIDs: visibility.HiddenLibraryIDs,
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
@@ -17,7 +17,7 @@ func TestMediaVisibilityFiltersNSFWAndLibraries(t *testing.T) {
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := db.AutoMigrate(&model.Library{}, &model.Media{}); err != nil {
|
||||
if err := db.AutoMigrate(&model.Library{}, &model.Media{}, &model.Setting{}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
repos := repository.New(db)
|
||||
@@ -31,6 +31,9 @@ func TestMediaVisibilityFiltersNSFWAndLibraries(t *testing.T) {
|
||||
if err := db.Create(&libB).Error; err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := repos.Setting.Set(t.Context(), AdultLibraryIDsSettingKey, `["`+libB.ID+`"]`); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
rows := []model.Media{
|
||||
{LibraryID: libA.ID, Title: "普通电影", Path: "/media/movies/a.mkv"},
|
||||
{LibraryID: libA.ID, Title: "成人电影", Path: "/media/movies/b.mkv", NSFW: true},
|
||||
@@ -40,11 +43,15 @@ func TestMediaVisibilityFiltersNSFWAndLibraries(t *testing.T) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
items, err := svc.SearchMediaVisible(t.Context(), "电影", 20, MediaVisibility{IncludeNSFW: false})
|
||||
hiddenAdultLibraries := AdultLibraryIDs(t.Context(), repos)
|
||||
items, err := svc.SearchMediaVisible(t.Context(), "电影", 20, MediaVisibility{
|
||||
IncludeNSFW: false,
|
||||
HiddenLibraryIDs: hiddenAdultLibraries,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got := sortedMediaTitles(items); !slices.Equal(got, []string{"普通电影", "限制媒体库电影"}) {
|
||||
if got := sortedMediaTitles(items); !slices.Equal(got, []string{"普通电影"}) {
|
||||
t.Fatalf("NSFW-filtered search = %#v", got)
|
||||
}
|
||||
|
||||
@@ -59,13 +66,27 @@ func TestMediaVisibilityFiltersNSFWAndLibraries(t *testing.T) {
|
||||
t.Fatalf("library-filtered search = %#v", got)
|
||||
}
|
||||
|
||||
listed, total, err := svc.ListMediaVisible(t.Context(), libA.ID, 1, 20, MediaVisibility{IncludeNSFW: false})
|
||||
listed, total, err := svc.ListMediaVisible(t.Context(), libA.ID, 1, 20, MediaVisibility{
|
||||
IncludeNSFW: false,
|
||||
HiddenLibraryIDs: hiddenAdultLibraries,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if total != 1 || len(listed) != 1 || listed[0].Title != "普通电影" {
|
||||
t.Fatalf("NSFW-filtered list total=%d rows=%#v", total, sortedMediaTitles(listed))
|
||||
}
|
||||
|
||||
listed, total, err = svc.ListMediaVisible(t.Context(), libB.ID, 1, 20, MediaVisibility{
|
||||
IncludeNSFW: false,
|
||||
HiddenLibraryIDs: hiddenAdultLibraries,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if total != 0 || len(listed) != 0 {
|
||||
t.Fatalf("adult library should be hidden total=%d rows=%#v", total, sortedMediaTitles(listed))
|
||||
}
|
||||
}
|
||||
|
||||
func sortedMediaTitles(rows []model.Media) []string {
|
||||
|
||||
@@ -9,20 +9,24 @@ import (
|
||||
"github.com/ShukeBta/MediaStationGo/internal/repository"
|
||||
)
|
||||
|
||||
const AdultLibraryIDsSettingKey = "adult.library_ids"
|
||||
|
||||
// AdultContentEnabled reads the global Adult / NSFW switch.
|
||||
func AdultContentEnabled(ctx context.Context, repo *repository.Container) bool {
|
||||
if repo == nil || repo.Setting == nil {
|
||||
return false
|
||||
return true
|
||||
}
|
||||
value, err := repo.Setting.Get(ctx, "adult.enabled")
|
||||
if err != nil {
|
||||
return false
|
||||
return true
|
||||
}
|
||||
switch strings.ToLower(strings.TrimSpace(value)) {
|
||||
case "1", "true", "yes", "on", "enabled", "启用", "开启":
|
||||
return true
|
||||
default:
|
||||
case "0", "false", "no", "off", "disabled", "禁用", "关闭":
|
||||
return false
|
||||
default:
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
@@ -45,6 +49,7 @@ func UserDefaultMediaVisibility(ctx context.Context, repo *repository.Container,
|
||||
if UserHidesAdult(ctx, repo, userID) {
|
||||
visibility.IncludeNSFW = false
|
||||
}
|
||||
visibility.HiddenLibraryIDs = hiddenAdultLibraryIDs(ctx, repo, visibility.IncludeNSFW)
|
||||
if userID == "" || repo.PlayProfile == nil {
|
||||
return visibility
|
||||
}
|
||||
@@ -58,6 +63,7 @@ func UserDefaultMediaVisibility(ctx context.Context, repo *repository.Container,
|
||||
}
|
||||
visibility.IncludeNSFW = visibility.IncludeNSFW && row.AllowAdult
|
||||
visibility.AllowedLibraryIDs = DecodeAllowedLibraryIDs(row.AllowedLibraryIDs)
|
||||
visibility.HiddenLibraryIDs = hiddenAdultLibraryIDs(ctx, repo, visibility.IncludeNSFW)
|
||||
break
|
||||
}
|
||||
return visibility
|
||||
@@ -99,6 +105,11 @@ func LibraryVisibleForUser(ctx context.Context, repo *repository.Container, lib
|
||||
if visibility.IncludeNSFW {
|
||||
return true
|
||||
}
|
||||
for _, id := range visibility.HiddenLibraryIDs {
|
||||
if id == lib.ID {
|
||||
return false
|
||||
}
|
||||
}
|
||||
if LibraryLooksAdult(lib) {
|
||||
return false
|
||||
}
|
||||
@@ -127,3 +138,21 @@ func LibraryLooksAdult(lib model.Library) bool {
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func AdultLibraryIDs(ctx context.Context, repo *repository.Container) []string {
|
||||
if repo == nil || repo.Setting == nil {
|
||||
return nil
|
||||
}
|
||||
raw, err := repo.Setting.Get(ctx, AdultLibraryIDsSettingKey)
|
||||
if err != nil {
|
||||
return nil
|
||||
}
|
||||
return DecodeAllowedLibraryIDs(raw)
|
||||
}
|
||||
|
||||
func hiddenAdultLibraryIDs(ctx context.Context, repo *repository.Container, includeNSFW bool) []string {
|
||||
if includeNSFW {
|
||||
return nil
|
||||
}
|
||||
return AdultLibraryIDs(ctx, repo)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user