17 Commits
Author SHA1 Message Date
Peter Marheine 3efa2d3e2c Remove the option to never set Content-Length
This workaround is obsolete with correct handling of ranges when
requested.
2019-05-23 10:54:06 +10:00
Peter Marheine 9be2a8892f More correctly handle stream ranges
When transcoding, always use chunked transfers and report that ranges
are not supported. When not transcoding, support returning ranges but
only if requested.
2019-05-23 10:51:37 +10:00
Peter Marheine 3e97186043 Omit unnecessary null check on ranges 2019-05-23 10:50:20 +10:00
Peter Marheine 47eefc1369 Refactor output streaming for readability
The core loop was put together confusingly; this encapsulates the
process of constructing an OutputStream and reformats some.
2019-05-23 10:48:09 +10:00
Peter Marheine cae8f8b4e5 Reformat stream controller some
Mostly just whitespace changes, shortening lines for readability. Adds a
few comments that outline what's supposed to happen.
2019-05-23 10:43:51 +10:00
Peter Marheine d42af4575f Add some @Nullable annotations
Making it easier to tell where API contracts allow nulls, where it's
otherwise unclear without reading the implementation.
2019-05-23 10:37:35 +10:00
Peter Marheine 5077e0d5e1 Short circuit RangeOutputStream for open ranges
There's no reason to wrap a stream in an output that will do nothing, as
when the requested range is 0-; eg the entire stream.
2019-05-23 10:34:57 +10:00
Peter Marheine 8b4037b549 Check reCAPTCHA v2 responses when enabled
Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine 1b833003fb Bring back an optional reCAPTCHA v2
Only showing it in the recovery view, not yet validating the result.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine a928b9ee3f Add settings for CAPTCHA in account recovery.
Allowing users to enable it and specify the site and secret key to use
with reCAPTCHA.

The old hard-coded keys were insecure; the secret key must not be
distributed publicly. The current defaults are the test keys provided at
https://developers.google.com/recaptcha/docs/faq#id-like-to-run-automated-tests-with-recaptcha-v2-what-should-i-do

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:04:57 +10:00
Peter Marheine 749342f25e Remove captcha support
It uses reCAPTCHA v1, which hasn't worked since March 2018.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 20:54:39 +10:00
Peter Marheine ae7f35a9cd Don't use HTTPS for scrobbling
Turns out HTTPS isn't supported for the old API that we're using, so go
back to using plain HTTP.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-07 15:43:49 +10:00
Peter Marheine 69e2ba0825 Use HTTPS and java.net.URI for scrobbling
HTTPS will help prevent eavesdropping on the auth token, and using URI
will ensure unusual characters (like spaces, accidental or otherwise)
are escaped correctly.

Fixes #588

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-01 18:04:22 +10:00
Peter MarheineandAndrew DeMaria cfdedea452 Suppress CVE-2018-13684 for dependency-check
False positive matching ant-zip against a CVE for ZIP, an Ethereum
token.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-07-31 12:00:05 -06:00
Peter Marheine b7d3e1d67d Write a real issue template. 2017-10-09 16:12:54 +11:00
Peter Marheine f05237f059 Use ffprobe and not ffmpeg to scrape metadata
This changes the behavior by searching for `ffprobe` in the trancode
directory and falling back to using `PATH` to locate `ffprobe` if it
doesn't exist in the transcode directory.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2017-10-08 18:29:27 +11:00
Peter Marheine 64846da360 Localize artist bios from last.fm
Using the current user's locale.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2017-10-07 18:30:28 +11:00