Commit Graph
952 Commits
Author SHA1 Message Date
Andrew DeMaria 8c4b2aa1fb Merge remote-tracking branch 'origin/pr/808' 2018-10-21 14:32:27 -06:00
Andrew DeMaria 8c6ddb1aba Dependency tweaks and remove extraneous code
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-21 14:31:52 -06:00
Andrew DeMaria cd05af87dc Merge remote-tracking branch 'origin/pr/807' 2018-10-21 14:07:23 -06:00
Rémi Cocula 6b4874f33c archetype code for rest api integration tests 2018-10-21 14:27:08 +02:00
Andrew DeMaria 5fd50d4ec2 Merge remote-tracking branch 'origin/pr/813' 2018-10-20 15:33:42 -06:00
Andrew DeMaria f8686d9638 Tweaked logging around servlet container and added warning about jetty
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-20 15:30:37 -06:00
Andrew DeMaria afb0fb1d27 Merge remote-tracking branch 'origin/pr/814' 2018-10-20 14:58:19 -06:00
Andrew DeMaria 3288a75c3e Merge remote-tracking branch 'origin/pr/811' 2018-10-20 14:57:40 -06:00
Andrew DeMaria f8161f5184 White list jars that are scanned for tlds to prevent spurious logs
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-20 16:42:23 -04:00
Andrew DeMaria 377f68543d Added profile to make running within a ide easier
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-20 16:40:52 -04:00
Andrew DeMaria 609ca71307 Skip another irrelevant CVE
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-10-18 16:41:39 -04:00
Carlos Galindo f6b248495c Fixed github link opening in frame and not loading 2018-10-13 17:25:42 +02:00
jo e0746172c5 Pull translations from transifex 2018-10-12 10:36:37 +02:00
Andrew DeMaria 004b8bba37 Added docker based integration testing
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-09-30 22:53:12 -06:00
Andrew DeMaria 685f4fa7e5 Merge remote-tracking branch 'origin/pr/801' 2018-09-29 10:07:52 -06:00
Andrew DeMaria d257800e1d Merge remote-tracking branch 'origin/pr/802' 2018-09-29 10:07:08 -06:00
Andrew DeMaria 8e1470a45a Dependency updates
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-09-28 20:54:01 -04:00
Andrew DeMariaandGitHub 8876f5866b Update stale.yml 2018-09-19 22:48:35 -06:00
Michael Sabin 48c3286766 Allow building without Git
If Maven cannot find the git executable
the build fails.

Signed-off-by: Michael Sabin <m35@users.noreply.github.com>
2018-09-15 20:01:51 -07:00
Michael Sabin 32ed46e55e Fix test failure on Windows
Media directories are added to the test database
with the string essentially generated by this code:
new File(MusicFolderTestData.resolveMusicFolderPath()).getPath()

The directories are then queried by the string generated
by this code:
MusicFolderTestData.resolveMusicFolderPath()

On Windows the strings are not identical.
MusicFolderTestData.resolveMusicFolderPath()
is prefixed by an extra slash that is removed
when wrapped by a File()

Signed-off-by: Michael Sabin <m35@users.noreply.github.com>
2018-09-15 18:48:11 -07:00
Andrew DeMaria 995d1fa667 Remove potential cast exception
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-09-07 13:43:13 -06:00
Andrew DeMaria 30b767955e Merge remote-tracking branch 'origin/pr/790' 2018-09-07 13:24:31 -06:00
WillyPillow 84144f287a Add option to disable seeking on transcodes. (Mitigates #548 & #723)
As per #548, #723, and tsquillario/Jamstash#131, the current method of
estimating `Content-Length` creates various problems.

However, if headers such as `Accept-Ranges` is omitted, clients will only
use the first connection, which is `Transfer-Encoding: chunked`, and no
`Content-Length` is necessary.

Doing this has the side effect that (at least on the web player) seeking
to a specific time is no longer possible, thus this was made an opt-in
option.

Signed-off-by: WillyPillow <wp@nerde.pw>
2018-09-06 02:11:01 +08:00
Carlos Galindo f78b108939 Optionally parse podcast episode duration in seconds to [hh:]mm:ss 2018-08-26 16:32:51 +02:00
Andrew DeMaria 8ba0bc88f0 Fix maven version
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-11 10:22:46 -06:00
Andrew DeMaria c56416a9ca Merge remote-tracking branch 'origin/pr/774'
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-11 10:04:18 -06:00
Andrew DeMaria 85bf4b268d Change mirror
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-11 10:03:26 -06:00
Peter Marheine 8b4037b549 Check reCAPTCHA v2 responses when enabled
Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine 1b833003fb Bring back an optional reCAPTCHA v2
Only showing it in the recovery view, not yet validating the result.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine a928b9ee3f Add settings for CAPTCHA in account recovery.
Allowing users to enable it and specify the site and secret key to use
with reCAPTCHA.

The old hard-coded keys were insecure; the secret key must not be
distributed publicly. The current defaults are the test keys provided at
https://developers.google.com/recaptcha/docs/faq#id-like-to-run-automated-tests-with-recaptcha-v2-what-should-i-do

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:04:57 +10:00
Peter Marheine 749342f25e Remove captcha support
It uses reCAPTCHA v1, which hasn't worked since March 2018.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 20:54:39 +10:00
Andrew DeMaria b6a9b32b1c Merge remote-tracking branch 'airsonic/pr/775' 2018-08-09 21:50:01 -04:00
Andrew DeMaria c2c14b0dbe Update dependency check
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-09 21:49:00 -04:00
Andrew DeMaria 5281d9ab6e Fix for false positive node vuln
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-09 21:48:49 -04:00
François-Xavier ThomasandJonas L caa1dac3a2 Use dark media player theme on groove theme (#777) 2018-08-09 22:41:58 +02:00
Peter Marheine ae7f35a9cd Don't use HTTPS for scrobbling
Turns out HTTPS isn't supported for the old API that we're using, so go
back to using plain HTTP.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-07 15:43:49 +10:00
Andrew DeMaria f6905dec1b Merge remote-tracking branch 'airsonic/pr/767' 2018-08-01 19:00:43 -04:00
jo 8735810215 Move github files to .github folder 2018-08-01 16:18:40 +02:00
Arne SchlüterandJonas L 237a05d272 Add v10.1.2 to changelog (#771) 2018-08-01 16:10:33 +02:00
Peter Marheine 69e2ba0825 Use HTTPS and java.net.URI for scrobbling
HTTPS will help prevent eavesdropping on the auth token, and using URI
will ensure unusual characters (like spaces, accidental or otherwise)
are escaped correctly.

Fixes #588

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-01 18:04:22 +10:00
Peter MarheineandAndrew DeMaria cfdedea452 Suppress CVE-2018-13684 for dependency-check
False positive matching ant-zip against a CVE for ZIP, an Ethereum
token.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-07-31 12:00:05 -06:00
jo 467d9420b7 Extends time before issue close (stalebot) 2018-07-29 21:09:13 +02:00
jo 74a13fc615 Add stale bot 2018-07-29 06:29:06 +02:00
Andrew DeMaria e3ea7beb96 Fix #764
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-07-28 13:38:15 -06:00
Andrew DeMaria 8d3c0ec9a0 Updates
- Update Spring boot Version
- Update dependency check version
- Exclude irrelevant nodejs cve

Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-07-08 00:20:44 -04:00
Andrew Rabert 83ef76a098 Add Docker health check
Signed-off-by: Andrew Rabert <ar@nullsum.net>
2018-06-18 18:39:00 -04:00
Andrew DeMaria 3e1ea6f913 Fix #749 Ensure transcode settings are protected
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-06-14 19:39:50 -04:00
Andrew DeMaria 431c98b496 Exclude cve CVE-2018-1115
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-06-14 18:58:58 -04:00
Andrew DeMaria a097597bca Merge remote-tracking branch 'airsonic/pr/700' 2018-06-14 18:49:23 -04:00
snw35 6a44c5c815 Handle player id as an Integer instead of String 2018-06-04 20:19:12 +01:00