soldosluka857
e97891175a
fix: security hardening and HTTP status code corrections
...
- importSTRMHandler: add URL scheme validation (blocks file://, ftp://, etc.)
- backup Delete/Restore: harden path traversal check (block backslash, require .db extension)
- HTTP 201 for create endpoints: register, subscription, download client, notify channel, library, STRM import
- Error handling: return 500 for service/infra errors in download client and notify channel handlers
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-30 10:44:47 +08:00
soldosluka857
0572612833
fix: add field whitelist to site update, fix HTTP status codes in site handlers
...
- SiteService.Update: whitelist updatable fields to prevent injection of
id, created_at, deleted_at, login_status, upload_bytes, download_bytes
- createSiteHandler: return 201 Created (was 200 OK)
- siteSearchHandler: return 500 for infra errors (was 400)
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-30 10:31:54 +08:00
soldosluka857
2c45fa596a
fix: improve play profile input validation, error responses, and HTTP status codes
...
- createPlayProfileHandler: return 201 Created (not 200) on success
- create/update handlers: return 500 for infra errors, 400 only for
validation errors (using new ErrPlayProfileValidation sentinel)
- deletePlayProfileHandler: validate JSON body (was silently ignored)
- verifyPlayProfilePINHandler: validate JSON body (was silently ignored)
- verify handler catch-all: return 500 (not 400) for unexpected errors
- Service layer: wrap validation errors with ErrPlayProfileValidation
so handlers can distinguish client vs server errors
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-30 10:19:57 +08:00
soldosluka857
5bbc9fadfe
security: fix SSRF, restrict CORS, add rate limiting on auth endpoints
...
- Add isPrivateHost() to block image proxy requests to loopback/private/
link-local IPs (SSRF mitigation)
- Add isAllowedLocalPath() to restrict local file reads to configured
data/cache/media directories only
- CORS middleware now takes debug flag; wildcard only when debug=true,
production omits headers (same-origin enforced)
- Add per-IP sliding-window rate limiter (10 req/min) on login/register
and Emby AuthenticateByName endpoints
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-30 10:03:43 +08:00
Shuke
d22b48a801
Update README.md
...
Signed-off-by: Shuke <272197458+ShukeBta@users.noreply.github.com >
2026-05-30 09:18:15 +08:00
ShukeBta
d35086f49d
fix: hide adult libraries across dashboard views
2026-05-30 03:50:52 +08:00
ShukeBta
e8c2cf1ea4
fix: require password only for adult visibility changes
2026-05-30 03:45:01 +08:00
ShukeBta
ce9abf6306
fix: repair user password reset and recreate flow
2026-05-30 03:33:36 +08:00
ShukeBta
99ecae0c44
fix: add global adult library visibility controls
2026-05-30 03:24:08 +08:00
ShukeBta
ce8ffabba7
fix: ignore non-command telegram group messages
2026-05-30 03:04:30 +08:00
ShukeBta
f8ef35c8e1
fix: stabilize telegram bot proxy and legacy permissions
2026-05-30 02:54:25 +08:00
ShukeBta
67ba1bdcce
fix: clarify telegram member binding permissions
2026-05-30 02:19:22 +08:00
ShukeBta
3c946559f5
fix: simplify telegram channel access rules
2026-05-30 02:16:18 +08:00
ShukeBta
7e01c42857
fix: improve telegram channel connectivity
2026-05-30 02:07:09 +08:00
ShukeBta
be6b8bf27f
fix: tighten telegram channel binding
2026-05-30 01:54:26 +08:00
ShukeBta
b5e11b6938
fix: secure adult visibility and telegram bot access
2026-05-30 01:39:11 +08:00
ShukeBta
db65e54c45
fix: avoid duplicate subscription downloads
2026-05-29 17:39:57 +08:00
ShukeBta
99fe7329f7
fix: isolate play profiles per user
2026-05-29 15:56:51 +08:00
ShukeBta
633a8cf715
fix: enforce adult profile pin visibility
2026-05-29 15:16:20 +08:00
ShukeBta
931db7a242
fix: handle wrapped permission responses
2026-05-29 14:11:51 +08:00
Shuke
7500cf07cb
Update README.md
...
Signed-off-by: Shuke <272197458+ShukeBta@users.noreply.github.com >
2026-05-29 14:01:00 +08:00
ShukeBta
a8395c9de7
fix: enforce transcoding resource controls
2026-05-29 13:54:19 +08:00
ShukeBta
27df93fa3d
feat: add licensing and access controls
2026-05-29 12:47:54 +08:00
ShukeBta
2f7ec3ab17
fix: group local search series results
2026-05-29 10:55:01 +08:00
ShukeBta
4361ba73ba
fix: show latest media per library directory
2026-05-29 10:36:47 +08:00
ShukeBta
00b9c1bb79
fix: refresh library artwork previews
2026-05-29 10:13:34 +08:00
ShukeBta
bbf8f41507
chore: mark docker update helper executable
2026-05-29 10:03:23 +08:00
ShukeBta
b430b5e638
docs: add docker image cleanup update helper
2026-05-29 10:03:05 +08:00
ShukeBta
dfe2b3f017
fix: prioritize local poster artwork
2026-05-29 09:52:16 +08:00
ShukeBta
12e12bfa28
docs: remove default proxy environment
2026-05-29 09:40:45 +08:00
ShukeBta
7b2241ffeb
docs: add docker proxy environment
2026-05-29 09:22:12 +08:00
ShukeBta
b7ea68a67c
fix: make qbittorrent login compatible
2026-05-29 04:15:44 +08:00
ShukeBta
2d90d9cba5
fix: improve qbittorrent host connectivity
2026-05-29 03:35:14 +08:00
ShukeBta
ab64101141
docs: document NAS direct path compose setup
2026-05-29 03:12:22 +08:00
ShukeBta
48d33275cb
fix: keep existing library files in place
2026-05-29 03:04:27 +08:00
ShukeBta
fc0dc70bad
fix: avoid repeated category organization
2026-05-29 02:55:46 +08:00
ShukeBta
1b86de7c26
docs: bump release examples to v0.0.6
2026-05-29 02:47:09 +08:00
ShukeBta
3031893156
fix: map docker host library paths
2026-05-29 02:44:52 +08:00
ShukeBta
5a7d90289b
docs: clarify NAS absolute volume paths
2026-05-29 02:38:22 +08:00
ShukeBta
00b5418fb0
feat: align smart media classification paths
2026-05-29 02:08:38 +08:00
ShukeBta
4f8831c8fd
docs: add nas paths and organization templates
2026-05-29 01:52:34 +08:00
ShukeBta
773343d744
docs: add ghcr pull troubleshooting
2026-05-29 01:44:38 +08:00
ShukeBta
895444b90f
ci: restore ghcr docker image publishing
2026-05-29 01:21:17 +08:00
ShukeBta
b0387ed40e
ci: publish docker image to docker hub
2026-05-29 01:13:47 +08:00
ShukeBta
af4bb04fa4
docs: remove release publishing guide from readme
2026-05-29 01:00:19 +08:00
ShukeBta
890d8e49c7
docs: expand docker deployment guide
2026-05-29 00:50:45 +08:00
Shuke
02ab0b0c9d
Update README_EN.md
...
Signed-off-by: Shuke <272197458+ShukeBta@users.noreply.github.com >
2026-05-29 00:34:58 +08:00
ShukeBta
32d7fb0f45
ci: publish artifacts only on version tags
2026-05-29 00:33:39 +08:00
Shuke
fef90aea5d
Update README.md
...
Signed-off-by: Shuke <272197458+ShukeBta@users.noreply.github.com >
2026-05-29 00:26:25 +08:00
ShukeBta
5924204e01
docs: rewrite project readmes
2026-05-29 00:20:06 +08:00