3cfe2b31a1 
								
									
								
							
								 
							
						 
						
							
							
								
								Move some cast-related inline js to an external file  
							
							... 
							
							
 
							
							There is no point in having such a massive
blob of javascript inline in the page. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								7b628ed8dd 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1056'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								58daacd9ab 
								
							
								 
							
						 
						
							
							
								
								Jetty is only used by developers, and never in production  
							
							... 
							
							
 
							
							So we're free to completely ignore CVE against it. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								2c3ba680d8 
								
									
								
							
								 
							
						 
						
							
							
								
								[ci skip] Add Java version in issue template  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								ab03526620 
								
									
								
							
								 
							
						 
						
							
							
								
								Fix two NULL-deref  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								ac0a722a10 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'airsonic/pr/990'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								b51cdc1c5c 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'airsonic/pr/1028'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								4537495baf 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'airsonic/pr/1012'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								3cdecb87f4 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'airsonic/pr/1037'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								8a90d9f77b 
								
							
								 
							
						 
						
							
							
								
								Add system properties for persisting the 'remember me' key  
							
							... 
							
							
 
							
							This adds the 'airsonic.rememberMeKey' system property (can be set from
command-line with `-Dairsonic.rememberMeKey=<value>`) as well as a
'RememberMeKey' setting in airsonic.properties, so that the key used for
generating 'remember me' tokens can be persisted across server restarts.
It also adds a default, insecure key in case we are running in
development mode with the 'airsonic.development' property set. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								b663a2fb90 
								
									
								
							
								 
							
						 
						
							
							
								
								Fix a stored XSS  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								348c698e35 
								
									
								
							
								 
							
						 
						
							
							
								
								Remove the /db page  
							
							... 
							
							
 
							
							This page wasn't linked anywhere, and was
allowing an administrator to issue arbitrary sql
comments, and was vulnerable to reflected XSS.
We should get rid of it. If you really want to issue
SQL commands, just ssh to your instance and do it from here. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								d3970a5c62 
								
									
								
							
								 
							
						 
						
							
							
								
								Fix various minor issues found by LGTM  
							
							... 
							
							
 
							
							- Unnecessary boxing
- Integer overflow
- Path traversal via zip
- Dangerous synchronization pattern 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								a911ebab80 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1027'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								2162250101 
								
									
								
							
								 
							
						 
						
							
							
								
								Revert "Minor frameset-related factorization"  
							
							... 
							
							
 
							
							This reverts commit e69287cfe6 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								925ecdaa03 
								
							
								 
							
						 
						
							
							
								
								Add a gitlab-ci file  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								a14c8549fa 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/963'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								a3e59e9724 
								
									
								
							
								 
							
						 
						
							
							
								
								Fix file encoding  
							
							... 
							
							
 
							
							Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com> 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								e5c36d9854 
								
									
								
							
								 
							
						 
						
							
							
								
								Fix variable name  
							
							... 
							
							
 
							
							Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com> 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								d8a5d1afad 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1034'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								afc2f58ac5 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1036'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								ab07462530 
								
									
								
							
								 
							
						 
						
							
							
								
								Update tomcat to 8.5.40  
							
							... 
							
							
 
							
							Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com> 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								820a4faec2 
								
							
								 
							
						 
						
							
							
								
								Avoid logging sensitive URL parameters in the Subsonic API  
							
							... 
							
							
 
							
							In case of exceptions, Airsonic logs the full URL that triggered it
since 417583cc 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								41408bc2c3 
								
							
								 
							
						 
						
							
							
								
								Replace the double-mustache anti-pattern  
							
							... 
							
							
 
							
							Because Double Brace Initialization (DBI) creates an anonymous class with a
reference to the instance of the owning object, its use can lead to memory
leaks if the anonymous inner class is returned and held by other objects. Even
when there's no leak, DBI is so obscure that it's bound to confuse most
maintainers. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								c6825cf0d7 
								
							
								 
							
						 
						
							
							
								
								Minor refactorization of two methods in AbstractDao  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								d9f164499f 
								
							
								 
							
						 
						
							
							
								
								Fix cancel button colors in 'Groove' dark theme  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								1463f75b06 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/961'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								693336af83 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/967'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								e2e1554e93 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/968'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								cddc2b2fa7 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/983'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								d03b4dd963 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/984'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								2030caa219 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/994'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								1bd70263bd 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/989'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								24f5c2d8f5 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1005'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								3f9c525933 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1007'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								50964fa378 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1002'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								326583839e 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/982'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								a2b423aa82 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1020'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								f5250e36f1 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1021'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								fdfa244ad4 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1022'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								fe08dd1c94 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1023'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								969394a1c9 
								
									
								
							
								 
							
						 
						
							
							
								
								Merge remote-tracking branch 'origin/pr/1006'  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								a21188a064 
								
							
								 
							
						 
						
							
							
								
								Add a permission check for the podcast folder  
							
							... 
							
							
 
							
							This should make podcast-related stacktraces a bit
more obvious to debug for users. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								716fd3635c 
								
							
								 
							
						 
						
							
							
								
								Remove a useless test page  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								e2683024af 
								
							
								 
							
						 
						
							
							
								
								Factorize a bit the checkbox-related CSS  
							
							... 
							
							
 
							
							Since the `border: 0;` property is applied
to every checkbox, there is no need for a class.
This is also a good opportunity to use ternaries
for the `checked` attribute, instead of clumsy `if`. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								cf1f86f226 
								
							
								 
							
						 
						
							
							
								
								Move some video-cast-related inline js to an external file  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								af4165310f 
								
							
								 
							
						 
						
							
							
								
								Fix yet an other XSS  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								f54e72026f 
								
							
								 
							
						 
						
							
							
								
								version upgrade of spring-boot-dependencies,spring-boot-maven-plugin  
							
							... 
							
							
 
							
							- Safety version for CVE-2019-3795
 - Match the new jetty ecj version because the version of ecj used by
tomcat and jetty is different. 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								e69287cfe6 
								
							
								 
							
						 
						
							
							
								
								Minor frameset-related factorization  
							
							
 
							
						 
						
							7 years ago  
				
					
						
							
							
								 
						
							
							
								10e90beb30 
								
									
								
							
								 
							
						 
						
							
							
								
								Refactor stream integration test  
							
							... 
							
							
 
							
							Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com> 
							
						 
						
							7 years ago