Commit Graph
885 Commits
Author SHA1 Message Date
Andrew DeMariaandGitHub 8876f5866b Update stale.yml 2018-09-19 22:48:35 -06:00
Michael Sabin 48c3286766 Allow building without Git
If Maven cannot find the git executable
the build fails.

Signed-off-by: Michael Sabin <m35@users.noreply.github.com>
2018-09-15 20:01:51 -07:00
Michael Sabin 32ed46e55e Fix test failure on Windows
Media directories are added to the test database
with the string essentially generated by this code:
new File(MusicFolderTestData.resolveMusicFolderPath()).getPath()

The directories are then queried by the string generated
by this code:
MusicFolderTestData.resolveMusicFolderPath()

On Windows the strings are not identical.
MusicFolderTestData.resolveMusicFolderPath()
is prefixed by an extra slash that is removed
when wrapped by a File()

Signed-off-by: Michael Sabin <m35@users.noreply.github.com>
2018-09-15 18:48:11 -07:00
Andrew DeMaria 995d1fa667 Remove potential cast exception
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-09-07 13:43:13 -06:00
Andrew DeMaria 30b767955e Merge remote-tracking branch 'origin/pr/790' 2018-09-07 13:24:31 -06:00
WillyPillow 84144f287a Add option to disable seeking on transcodes. (Mitigates #548 & #723)
As per #548, #723, and tsquillario/Jamstash#131, the current method of
estimating `Content-Length` creates various problems.

However, if headers such as `Accept-Ranges` is omitted, clients will only
use the first connection, which is `Transfer-Encoding: chunked`, and no
`Content-Length` is necessary.

Doing this has the side effect that (at least on the web player) seeking
to a specific time is no longer possible, thus this was made an opt-in
option.

Signed-off-by: WillyPillow <wp@nerde.pw>
2018-09-06 02:11:01 +08:00
Carlos Galindo f78b108939 Optionally parse podcast episode duration in seconds to [hh:]mm:ss 2018-08-26 16:32:51 +02:00
Andrew DeMaria 8ba0bc88f0 Fix maven version
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-11 10:22:46 -06:00
Andrew DeMaria c56416a9ca Merge remote-tracking branch 'origin/pr/774'
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-11 10:04:18 -06:00
Andrew DeMaria 85bf4b268d Change mirror
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-11 10:03:26 -06:00
Peter Marheine 8b4037b549 Check reCAPTCHA v2 responses when enabled
Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine 1b833003fb Bring back an optional reCAPTCHA v2
Only showing it in the recovery view, not yet validating the result.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:05:07 +10:00
Peter Marheine a928b9ee3f Add settings for CAPTCHA in account recovery.
Allowing users to enable it and specify the site and secret key to use
with reCAPTCHA.

The old hard-coded keys were insecure; the secret key must not be
distributed publicly. The current defaults are the test keys provided at
https://developers.google.com/recaptcha/docs/faq#id-like-to-run-automated-tests-with-recaptcha-v2-what-should-i-do

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 21:04:57 +10:00
Peter Marheine 749342f25e Remove captcha support
It uses reCAPTCHA v1, which hasn't worked since March 2018.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-11 20:54:39 +10:00
Andrew DeMaria b6a9b32b1c Merge remote-tracking branch 'airsonic/pr/775' 2018-08-09 21:50:01 -04:00
Andrew DeMaria c2c14b0dbe Update dependency check
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-09 21:49:00 -04:00
Andrew DeMaria 5281d9ab6e Fix for false positive node vuln
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-08-09 21:48:49 -04:00
François-Xavier ThomasandJonas L caa1dac3a2 Use dark media player theme on groove theme (#777) 2018-08-09 22:41:58 +02:00
Peter Marheine ae7f35a9cd Don't use HTTPS for scrobbling
Turns out HTTPS isn't supported for the old API that we're using, so go
back to using plain HTTP.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-07 15:43:49 +10:00
Andrew DeMaria f6905dec1b Merge remote-tracking branch 'airsonic/pr/767' 2018-08-01 19:00:43 -04:00
jo 8735810215 Move github files to .github folder 2018-08-01 16:18:40 +02:00
Arne SchlüterandJonas L 237a05d272 Add v10.1.2 to changelog (#771) 2018-08-01 16:10:33 +02:00
Peter Marheine 69e2ba0825 Use HTTPS and java.net.URI for scrobbling
HTTPS will help prevent eavesdropping on the auth token, and using URI
will ensure unusual characters (like spaces, accidental or otherwise)
are escaped correctly.

Fixes #588

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-08-01 18:04:22 +10:00
Peter MarheineandAndrew DeMaria cfdedea452 Suppress CVE-2018-13684 for dependency-check
False positive matching ant-zip against a CVE for ZIP, an Ethereum
token.

Signed-off-by: Peter Marheine <peter@taricorp.net>
2018-07-31 12:00:05 -06:00
jo 467d9420b7 Extends time before issue close (stalebot) 2018-07-29 21:09:13 +02:00
jo 74a13fc615 Add stale bot 2018-07-29 06:29:06 +02:00
Andrew DeMaria e3ea7beb96 Fix #764
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-07-28 13:38:15 -06:00
Andrew DeMaria 8d3c0ec9a0 Updates
- Update Spring boot Version
- Update dependency check version
- Exclude irrelevant nodejs cve

Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-07-08 00:20:44 -04:00
Andrew Rabert 83ef76a098 Add Docker health check
Signed-off-by: Andrew Rabert <ar@nullsum.net>
2018-06-18 18:39:00 -04:00
Andrew DeMaria 3e1ea6f913 Fix #749 Ensure transcode settings are protected
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-06-14 19:39:50 -04:00
Andrew DeMaria 431c98b496 Exclude cve CVE-2018-1115
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-06-14 18:58:58 -04:00
Andrew DeMaria a097597bca Merge remote-tracking branch 'airsonic/pr/700' 2018-06-14 18:49:23 -04:00
snw35 6a44c5c815 Handle player id as an Integer instead of String 2018-06-04 20:19:12 +01:00
François-Xavier Thomas b3f432a545 Issue #164: Add tests for reading MusicBrainz release tags 2018-05-22 23:33:27 +02:00
François-Xavier Thomas c76a92746d Issue #164: Show link to MusicBrainz release on album pages 2018-05-22 23:17:33 +02:00
Andrew DeMaria 40c9debf8e Merge remote-tracking branch 'airsonic/pr/698' 2018-05-07 19:44:02 -04:00
Andrew DeMaria 36d773dbfc Update cxf
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-05-03 20:28:10 -04:00
Andrew DeMaria 2ea980d642 Update spring boot
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-05-03 20:25:57 -04:00
jo 30ffc9560b Fix wrong case 2018-05-04 01:45:00 +02:00
Andrew DeMaria bbccce2303 Merge remote-tracking branch 'airsonic/pr/699' 2018-05-03 19:37:59 -04:00
Andrew DeMaria 5cca85f516 Ignore irrelevant CVE
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-04-08 14:05:17 -04:00
Andrew DeMaria 893b652bcd Update dependency checker with updated maven too
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2018-04-08 14:04:45 -04:00
Bonome 070df25f45 catch exceptions ClientAbortException display a short message and return, to avoid the massive useless traceback in log
Signed-off-by: Bonome <bonome@tak.blue>
2018-04-04 17:39:44 +02:00
jo b259f32bc4 Fix themes using dark background with me_js 2018-02-27 20:01:17 +01:00
jo d1e190af0c Remove margin of media_control bar 2018-02-27 20:00:39 +01:00
jo 159d5f67fa Fix #596 2018-02-27 17:45:28 +01:00
jo 6204409c5e New add_album to play queue 2018-02-27 15:58:44 +01:00
Romain DEP. c2416a57a8 deps: update jackson to a vuln-free version,
bump java-jwt in the process
2018-02-27 02:28:58 +01:00
Rémi Cocula be91fb08c4 fix issues #638 and #574 2018-01-20 22:38:33 +01:00
Andrew DeMaria ce5920ce4c Merge remote-tracking branch 'origin/pr/674' 2018-01-11 10:34:24 -07:00