Commit Graph
622 Commits
Author SHA1 Message Date
Andrew DeMaria 4d56df06ba Merge remote-tracking branch 'airsonic/pr/844' 2018-12-09 23:40:31 -05:00
Benz0X af93f1eed1 Correct corrupted downloaded zip
Prevent the zipping of twice the same file (resulting in an error and a corrupted zip on Linux) when the cover is embedded in tags
2018-12-08 15:10:12 +01:00
Michel Néron 16b22f3501 - Correct test for use not a hardcoded value but the referenced value. The first in select on multi value didn't ordered is not assured. 2018-12-08 11:31:48 +01:00
Arne Schlüter fec8f0ba95 Update favicons in webapp 2018-12-03 10:42:04 +01:00
Andrew DeMaria 4dde6de2e8 Merge remote-tracking branch 'airsonic/pr/839' 2018-12-02 18:26:14 -05:00
Andrew DeMaria 3efd278799 Merge remote-tracking branch 'airsonic/pr/810' 2018-12-02 18:26:00 -05:00
Andrew DeMaria 5202845373 Bump version of guava to deal with CVE-2018-10237
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-12-02 16:27:21 -05:00
Shawn Bruce df5f6f2aaf Display folders as a list in Settings->Users and include the path. 2018-12-02 16:12:42 -05:00
jo e72147b76b Update languages from tx 2018-11-04 14:07:08 +01:00
jo 607f4c8720 Clean source i18n file 2018-11-04 14:06:18 +01:00
jo 75410aaea2 Update translation files 2018-11-04 13:59:29 +01:00
jo b8b5dc59a0 Merge branch 'master' of https://github.com/airsonic/airsonic into transifex_update 2018-11-04 13:52:50 +01:00
Andrew DeMaria 8c6ddb1aba Dependency tweaks and remove extraneous code
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-21 14:31:52 -06:00
Andrew DeMaria cd05af87dc Merge remote-tracking branch 'origin/pr/807' 2018-10-21 14:07:23 -06:00
Rémi Cocula 6b4874f33c archetype code for rest api integration tests 2018-10-21 14:27:08 +02:00
Andrew DeMaria 5fd50d4ec2 Merge remote-tracking branch 'origin/pr/813' 2018-10-20 15:33:42 -06:00
Andrew DeMaria f8686d9638 Tweaked logging around servlet container and added warning about jetty
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-20 15:30:37 -06:00
Andrew DeMaria afb0fb1d27 Merge remote-tracking branch 'origin/pr/814' 2018-10-20 14:58:19 -06:00
Andrew DeMaria 3288a75c3e Merge remote-tracking branch 'origin/pr/811' 2018-10-20 14:57:40 -06:00
Andrew DeMaria f8161f5184 White list jars that are scanned for tlds to prevent spurious logs
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-20 16:42:23 -04:00
Andrew DeMaria 377f68543d Added profile to make running within a ide easier
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-20 16:40:52 -04:00
Andrew DeMaria 609ca71307 Skip another irrelevant CVE
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-18 16:41:39 -04:00
Carlos Galindo f6b248495c Fixed github link opening in frame and not loading 2018-10-13 17:25:42 +02:00
jo e0746172c5 Pull translations from transifex 2018-10-12 10:36:37 +02:00
Andrew DeMaria 685f4fa7e5 Merge remote-tracking branch 'origin/pr/801' 2018-09-29 10:07:52 -06:00
Michael Sabin 48c3286766 Allow building without Git
If Maven cannot find the git executable
the build fails.

Signed-off-by: Michael Sabin <m35@users.noreply.github.com>
2018-09-15 20:01:51 -07:00
Michael Sabin 32ed46e55e Fix test failure on Windows
Media directories are added to the test database
with the string essentially generated by this code:
new File(MusicFolderTestData.resolveMusicFolderPath()).getPath()

The directories are then queried by the string generated
by this code:
MusicFolderTestData.resolveMusicFolderPath()

On Windows the strings are not identical.
MusicFolderTestData.resolveMusicFolderPath()
is prefixed by an extra slash that is removed
when wrapped by a File()

Signed-off-by: Michael Sabin <m35@users.noreply.github.com>
2018-09-15 18:48:11 -07:00
Andrew DeMaria 995d1fa667 Remove potential cast exception
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-09-07 13:43:13 -06:00
Andrew DeMaria 30b767955e Merge remote-tracking branch 'origin/pr/790' 2018-09-07 13:24:31 -06:00
WillyPillow 84144f287a Add option to disable seeking on transcodes. (Mitigates #548 & #723)
As per #548, #723, and tsquillario/Jamstash#131, the current method of
estimating `Content-Length` creates various problems.

However, if headers such as `Accept-Ranges` is omitted, clients will only
use the first connection, which is `Transfer-Encoding: chunked`, and no
`Content-Length` is necessary.

Doing this has the side effect that (at least on the web player) seeking
to a specific time is no longer possible, thus this was made an opt-in
option.

Signed-off-by: WillyPillow <wp@nerde.pw>
2018-09-06 02:11:01 +08:00
Carlos Galindo f78b108939 Optionally parse podcast episode duration in seconds to [hh:]mm:ss 2018-08-26 16:32:51 +02:00
Peter Marheine 8b4037b549 Check reCAPTCHA v2 responses when enabled
Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine 1b833003fb Bring back an optional reCAPTCHA v2
Only showing it in the recovery view, not yet validating the result.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine a928b9ee3f Add settings for CAPTCHA in account recovery.
Allowing users to enable it and specify the site and secret key to use
with reCAPTCHA.

The old hard-coded keys were insecure; the secret key must not be
distributed publicly. The current defaults are the test keys provided at
https://developers.google.com/recaptcha/docs/faq#id-like-to-run-automated-tests-with-recaptcha-v2-what-should-i-do

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:04:57 +10:00
Peter Marheine 749342f25e Remove captcha support
It uses reCAPTCHA v1, which hasn't worked since March 2018.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 20:54:39 +10:00
Andrew DeMaria b6a9b32b1c Merge remote-tracking branch 'airsonic/pr/775' 2018-08-09 21:50:01 -04:00
Andrew DeMaria 5281d9ab6e Fix for false positive node vuln
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-09 21:48:49 -04:00
François-Xavier ThomasandJonas L caa1dac3a2 Use dark media player theme on groove theme (#777) 2018-08-09 22:41:58 +02:00
Peter Marheine ae7f35a9cd Don't use HTTPS for scrobbling
Turns out HTTPS isn't supported for the old API that we're using, so go
back to using plain HTTP.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-07 15:43:49 +10:00
Peter Marheine 69e2ba0825 Use HTTPS and java.net.URI for scrobbling
HTTPS will help prevent eavesdropping on the auth token, and using URI
will ensure unusual characters (like spaces, accidental or otherwise)
are escaped correctly.

Fixes #588

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-01 18:04:22 +10:00
Peter MarheineandAndrew DeMaria cfdedea452 Suppress CVE-2018-13684 for dependency-check
False positive matching ant-zip against a CVE for ZIP, an Ethereum
token.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-07-31 12:00:05 -06:00
Andrew DeMaria e3ea7beb96 Fix #764
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-07-28 13:38:15 -06:00
Andrew DeMaria 8d3c0ec9a0 Updates
- Update Spring boot Version
- Update dependency check version
- Exclude irrelevant nodejs cve

Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-07-08 00:20:44 -04:00
Andrew DeMaria 3e1ea6f913 Fix #749 Ensure transcode settings are protected
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-06-14 19:39:50 -04:00
Andrew DeMaria 431c98b496 Exclude cve CVE-2018-1115
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-06-14 18:58:58 -04:00
Andrew DeMaria a097597bca Merge remote-tracking branch 'airsonic/pr/700' 2018-06-14 18:49:23 -04:00
snw35 6a44c5c815 Handle player id as an Integer instead of String 2018-06-04 20:19:12 +01:00
François-Xavier Thomas b3f432a545 Issue #164: Add tests for reading MusicBrainz release tags 2018-05-22 23:33:27 +02:00
François-Xavier Thomas c76a92746d Issue #164: Show link to MusicBrainz release on album pages 2018-05-22 23:17:33 +02:00
Andrew DeMaria 40c9debf8e Merge remote-tracking branch 'airsonic/pr/698' 2018-05-07 19:44:02 -04:00