mirror of
https://github.com/truewhile/MeBox.git
synced 2026-09-29 11:36:36 +08:00
4b747c74ca
Audit-driven port from the original Python MediaStation. Eight major
subsystems that were absent from the Go rewrite are now in place,
each with its own service, handler, frontend page and smoke-test
assertions.
Backend services
- service/crypto.go: AES-256-GCM encrypt/decrypt for at-rest secrets
keyed off the JWT secret. Legacy plaintext rows pass through
unchanged for smooth upgrades. Unit-tested.
- service/api_config.go: third-party provider config (TMDb, Bangumi,
TheTVDB, Fanart, Douban, OpenAI). Seeds defaults on first run.
Encrypts api_key on write, returns masked 'abc1****wxyz' projection.
- service/duplicate.go: sparse-sample MD5 (head + middle + tail, 1MiB
each, plus file-size suffix) duplicate finder. Picks 'best' primary
(matched > size > id) and marks others is_duplicate=true.
- service/filemanager.go: server-side allow-listed file browser used
by the library-path picker. Strict path-traversal protection.
- service/dlna.go: real SSDP M-SEARCH discovery + AVTransport
SetAVTransportURI/Play SOAP cast. 30 s discovery cache.
- service/scheduler.go: 3 recurring background jobs (library_scan
60min, transcode_cleanup 24h, recycle_purge 24h with 30-day
cutoff). Status + run-now endpoints.
- service/cache_cleanup.go: walkAndPrune helper used by scheduler.
- service/storage.go: DB-only disk-usage breakdown by library and by
container format.
- service/emby_compat.go: read-only Emby/Jellyfin shim
(System/Info, Users, Users/x/Views, Items, PlaybackInfo) so Infuse
/ VidHub / Kodi can browse MediaStationGo libraries.
Model updates
- Media: new strm_url (302 redirect target), file_hash, is_duplicate,
duplicate_of fields.
- APIConfig: new table for encrypted provider secrets.
- AutoMigrate registers APIConfig.
Stream layer
- StreamService.ServeFile now redirects 302 to strm_url when set so
WebDAV / Alist / S3 / HTTP direct links work transparently.
Handlers + routes
- Authed: GET /files, GET /storage, GET /dlna/devices, POST /dlna/cast,
PUT/DELETE /media/:id/strm, POST /strm/import,
POST /duplicates/{scan,unmark}.
- Admin: GET/PUT/DELETE /admin/api-configs/:provider,
GET /admin/scheduler, POST /admin/scheduler/:name/run.
- New /emby/* group: System/Info, Users, Users/:userId/Views,
Users/:userId/Items, Items/:id/PlaybackInfo (auth-required).
Frontend pages (lazy-loaded, 7 new chunks)
- DlnaPage: device list + media picker + cast button.
- FileManagerPage: root selector + breadcrumb + sortable listing.
- APIConfigsPage: per-provider card with masked-key editor.
- StoragePage: usage tiles + per-library bars + per-container grid.
- DuplicatesPage: scan form + grouped report with primary highlight.
- SchedulerPage: live job table with run-now button (5s refresh).
- Sidebar reorganised: 自动化 group adds DLNA, 管理 group adds
存储 / 文件浏览 / 重复文件 / 定时任务 / API 配置.
Smoke test additions (all admin-only)
- api-configs seeded with 6 providers
- api-config encrypted in db (sqlite3 enc:v1: prefix check)
- storage breakdown
- file browser lists library root + rejects /etc (path traversal)
- dlna devices endpoint
- scheduler exposes 3 jobs + run library_scan
- emby /System/Info + /Users/{x}/Views
- strm set + stream 302 + strm clear
- duplicate scan
Verified: go build, go vet, go test (incl. new TestCrypto* suite + the
existing TestParseEpisode/TestCleanQuery/TestSrtToVTT/TestStripASSTags/
TestBuildFFmpegArgs); tsc -b && vite build emits 28 route chunks plus
the deferred hls chunk; main bundle 253 KB / 85 KB gzipped; smoke test
PASS=42 / FAIL=0.
187 lines
4.9 KiB
Go
187 lines
4.9 KiB
Go
// Package service — server-side file browser.
|
|
//
|
|
// FileManagerService exposes a strict, allow-listed view of the server's
|
|
// filesystem so the React Library / Storage tabs can let the operator
|
|
// pick library roots without typing absolute paths from memory.
|
|
//
|
|
// Allow-list rules:
|
|
//
|
|
// - Roots: every Library.Path + the configured app.data_dir +
|
|
// app.cache_dir, plus the operator-supplied app.media.* defaults.
|
|
// - Children must resolve under one of the roots after symlink-free
|
|
// filepath.Abs(). Anything else returns ErrPathOutOfBounds.
|
|
//
|
|
// We never write to the filesystem here; this is read-only browsing.
|
|
package service
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"os"
|
|
"path/filepath"
|
|
"sort"
|
|
"strings"
|
|
|
|
"go.uber.org/zap"
|
|
|
|
"github.com/ShukeBta/MediaStationGo/internal/config"
|
|
"github.com/ShukeBta/MediaStationGo/internal/repository"
|
|
)
|
|
|
|
// FileManagerService browses the server-side filesystem.
|
|
type FileManagerService struct {
|
|
cfg *config.Config
|
|
log *zap.Logger
|
|
repo *repository.Container
|
|
}
|
|
|
|
// NewFileManagerService is the constructor.
|
|
func NewFileManagerService(cfg *config.Config, log *zap.Logger, repo *repository.Container) *FileManagerService {
|
|
return &FileManagerService{cfg: cfg, log: log, repo: repo}
|
|
}
|
|
|
|
// Entry is one file or directory shown in the browser.
|
|
type Entry struct {
|
|
Name string `json:"name"`
|
|
Path string `json:"path"`
|
|
IsDir bool `json:"is_dir"`
|
|
Size int64 `json:"size"`
|
|
Modified int64 `json:"modified"`
|
|
}
|
|
|
|
// Listing describes the contents of a directory plus navigation hints.
|
|
type Listing struct {
|
|
Path string `json:"path"`
|
|
Parent string `json:"parent,omitempty"`
|
|
Roots []Root `json:"roots,omitempty"`
|
|
Entries []Entry `json:"entries"`
|
|
}
|
|
|
|
// Root is the entry-point label shown when no path is given.
|
|
type Root struct {
|
|
Label string `json:"label"`
|
|
Path string `json:"path"`
|
|
}
|
|
|
|
// ErrPathOutOfBounds is returned when path falls outside every allowed root.
|
|
var ErrPathOutOfBounds = errors.New("path is outside the allowed roots")
|
|
|
|
// List enumerates a directory under one of the allowed roots, returning
|
|
// up to maxEntries items sorted by (dir-first, alphabetical).
|
|
func (s *FileManagerService) List(path string, maxEntries int) (*Listing, error) {
|
|
if maxEntries <= 0 || maxEntries > 5000 {
|
|
maxEntries = 1000
|
|
}
|
|
roots, err := s.allowedRoots()
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
rootList := make([]Root, 0, len(roots))
|
|
seen := map[string]struct{}{}
|
|
for label, p := range roots {
|
|
if _, ok := seen[p]; ok {
|
|
continue
|
|
}
|
|
seen[p] = struct{}{}
|
|
rootList = append(rootList, Root{Label: label, Path: p})
|
|
}
|
|
sort.Slice(rootList, func(i, j int) bool { return rootList[i].Label < rootList[j].Label })
|
|
|
|
if path == "" {
|
|
// Listing the (virtual) root: just hand back the labels.
|
|
return &Listing{Path: "", Roots: rootList}, nil
|
|
}
|
|
|
|
abs, err := filepath.Abs(path)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
if !s.withinAllowed(abs, roots) {
|
|
return nil, ErrPathOutOfBounds
|
|
}
|
|
|
|
entries, err := os.ReadDir(abs)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
out := &Listing{Path: abs, Roots: rootList}
|
|
parent := filepath.Dir(abs)
|
|
if parent != abs && s.withinAllowed(parent, roots) {
|
|
out.Parent = parent
|
|
}
|
|
|
|
for i, e := range entries {
|
|
if i >= maxEntries {
|
|
break
|
|
}
|
|
name := e.Name()
|
|
if strings.HasPrefix(name, ".") {
|
|
continue
|
|
}
|
|
full := filepath.Join(abs, name)
|
|
info, err := e.Info()
|
|
if err != nil {
|
|
continue
|
|
}
|
|
out.Entries = append(out.Entries, Entry{
|
|
Name: name,
|
|
Path: full,
|
|
IsDir: e.IsDir(),
|
|
Size: info.Size(),
|
|
Modified: info.ModTime().Unix(),
|
|
})
|
|
}
|
|
sort.Slice(out.Entries, func(i, j int) bool {
|
|
if out.Entries[i].IsDir != out.Entries[j].IsDir {
|
|
return out.Entries[i].IsDir
|
|
}
|
|
return strings.ToLower(out.Entries[i].Name) < strings.ToLower(out.Entries[j].Name)
|
|
})
|
|
return out, nil
|
|
}
|
|
|
|
// allowedRoots returns the union of {libraries, data_dir, cache_dir,
|
|
// media.movies/tv/anime} as label → absolute-path.
|
|
func (s *FileManagerService) allowedRoots() (map[string]string, error) {
|
|
roots := map[string]string{}
|
|
add := func(label, p string) {
|
|
if p == "" {
|
|
return
|
|
}
|
|
abs, err := filepath.Abs(p)
|
|
if err != nil {
|
|
return
|
|
}
|
|
if _, err := os.Stat(abs); err != nil {
|
|
return
|
|
}
|
|
roots[label] = abs
|
|
}
|
|
add("data", s.cfg.App.DataDir)
|
|
add("cache", s.cfg.Cache.CacheDir)
|
|
add("movies", s.cfg.Media.MoviesDir)
|
|
add("tv", s.cfg.Media.TVDir)
|
|
add("anime", s.cfg.Media.AnimeDir)
|
|
libs, err := s.repo.Library.List(context.Background()) // librarian list is fast; ctx not propagated from request
|
|
if err == nil {
|
|
for _, l := range libs {
|
|
add("library:"+l.Name, l.Path)
|
|
}
|
|
}
|
|
return roots, nil
|
|
}
|
|
|
|
// withinAllowed reports whether path lives under any allowed root.
|
|
func (s *FileManagerService) withinAllowed(path string, roots map[string]string) bool {
|
|
for _, r := range roots {
|
|
rel, err := filepath.Rel(r, path)
|
|
if err != nil {
|
|
continue
|
|
}
|
|
if !strings.HasPrefix(rel, "..") && !filepath.IsAbs(rel) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|