Commit Graph
624 Commits
Author SHA1 Message Date
François-Xavier Thomas f57ad3f27b Fix typo in anonymous user name (#663) 2019-04-29 23:30:02 +02:00
Andrew DeMaria ac0a722a10 Merge remote-tracking branch 'airsonic/pr/990' 2019-04-28 22:59:23 -04:00
Andrew DeMaria b51cdc1c5c Merge remote-tracking branch 'airsonic/pr/1028' 2019-04-28 22:58:29 -04:00
François-Xavier Thomas 8a90d9f77b Add system properties for persisting the 'remember me' key
This adds the 'airsonic.rememberMeKey' system property (can be set from
command-line with `-Dairsonic.rememberMeKey=<value>`) as well as a
'RememberMeKey' setting in airsonic.properties, so that the key used for
generating 'remember me' tokens can be persisted across server restarts.

It also adds a default, insecure key in case we are running in
development mode with the 'airsonic.development' property set.
2019-04-28 16:51:46 +02:00
jvoisin 3ee6fefe11 Bump jQuery/jquery-ui to the latest versions
I bumped it first to 2.X with jQuery migrate, played around but didn't manage
to trigger any warning.  So I bumped it again to the latest available version,
jQuery 3.4.0, which isn't triggering useful warnings either.
2019-04-28 16:26:36 +02:00
jvoisinandGitHub b663a2fb90 Fix a stored XSS 2019-04-28 08:49:25 +00:00
jvoisinandGitHub 348c698e35 Remove the /db page
This page wasn't linked anywhere, and was
allowing an administrator to issue arbitrary sql
comments, and was vulnerable to reflected XSS.

We should get rid of it. If you really want to issue
SQL commands, just ssh to your instance and do it from here.
2019-04-28 08:48:41 +00:00
jvoisinandGitHub d3970a5c62 Fix various minor issues found by LGTM
- Unnecessary boxing
- Integer overflow
- Path traversal via zip
- Dangerous synchronization pattern
2019-04-28 08:37:47 +00:00
Andrew DeMaria a911ebab80 Merge remote-tracking branch 'origin/pr/1027' 2019-04-27 20:27:37 -06:00
Andrew DeMaria df352d8cb0 Fix #611 Add support for Java 9 and greater
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2019-04-27 14:04:48 -06:00
Andrew DeMaria 2162250101 Revert "Minor frameset-related factorization"
This reverts commit e69287cfe6.

Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2019-04-27 14:00:52 -06:00
jvoisin 3d54ef1afb Mark the player cookie httpOnly
It doesn't improve much security-wise,
but it's a good practise anyway.
2019-04-27 20:37:41 +02:00
jvoisin 8f608485cb Fix a typo 2019-04-27 20:37:35 +02:00
jvoisin 8123716d52 Remove unused loggers 2019-04-27 20:37:35 +02:00
jvoisin 4a06823057 Balance some synchronized
Balance synchronized used on getters and not setters
as well as the other way around.
2019-04-27 20:36:08 +02:00
jvoisin d2f40b710b Fix a possible stacktrace on RandomPlayQueue 2019-04-27 20:35:41 +02:00
Andrew DeMaria a14c8549fa Merge remote-tracking branch 'origin/pr/963' 2019-04-27 11:56:46 -06:00
Andrew DeMaria a3e59e9724 Fix file encoding
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2019-04-27 10:56:09 -06:00
Andrew DeMaria e5c36d9854 Fix variable name
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2019-04-27 10:55:54 -06:00
Andrew DeMaria d8a5d1afad Merge remote-tracking branch 'origin/pr/1034' 2019-04-27 10:45:48 -06:00
François-Xavier Thomas 820a4faec2 Avoid logging sensitive URL parameters in the Subsonic API
In case of exceptions, Airsonic logs the full URL that triggered it
since 417583cc, including possibly sensitive query parameters such as
the authentication password/tokens passed to the Subsonic API.

This replaces the value set for this parameter in the URL by the
"<hidden>" string.
2019-04-26 22:18:23 +02:00
jvoisin 41408bc2c3 Replace the double-mustache anti-pattern
Because Double Brace Initialization (DBI) creates an anonymous class with a
reference to the instance of the owning object, its use can lead to memory
leaks if the anonymous inner class is returned and held by other objects. Even
when there's no leak, DBI is so obscure that it's bound to confuse most
maintainers.
2019-04-25 22:32:45 +02:00
jvoisin c6825cf0d7 Minor refactorization of two methods in AbstractDao 2019-04-24 22:40:38 +02:00
François-Xavier Thomas d9f164499f Fix cancel button colors in 'Groove' dark theme 2019-04-22 15:15:36 +02:00
Andrew DeMaria 1463f75b06 Merge remote-tracking branch 'origin/pr/961' 2019-04-19 09:51:41 -06:00
Andrew DeMaria cddc2b2fa7 Merge remote-tracking branch 'origin/pr/983' 2019-04-19 09:48:05 -06:00
Andrew DeMaria 2030caa219 Merge remote-tracking branch 'origin/pr/994' 2019-04-19 09:46:40 -06:00
Andrew DeMaria 1bd70263bd Merge remote-tracking branch 'origin/pr/989' 2019-04-19 09:41:06 -06:00
Andrew DeMaria 24f5c2d8f5 Merge remote-tracking branch 'origin/pr/1005' 2019-04-19 09:40:48 -06:00
Andrew DeMaria 3f9c525933 Merge remote-tracking branch 'origin/pr/1007' 2019-04-19 09:39:48 -06:00
Andrew DeMaria 50964fa378 Merge remote-tracking branch 'origin/pr/1002' 2019-04-19 09:39:17 -06:00
Andrew DeMaria 326583839e Merge remote-tracking branch 'origin/pr/982' 2019-04-19 08:17:33 -06:00
Andrew DeMaria a2b423aa82 Merge remote-tracking branch 'origin/pr/1020' 2019-04-19 08:17:18 -06:00
Andrew DeMaria f5250e36f1 Merge remote-tracking branch 'origin/pr/1021' 2019-04-19 08:17:06 -06:00
Andrew DeMaria fdfa244ad4 Merge remote-tracking branch 'origin/pr/1022' 2019-04-19 08:16:57 -06:00
Andrew DeMaria fe08dd1c94 Merge remote-tracking branch 'origin/pr/1023' 2019-04-19 08:16:43 -06:00
jvoisin a21188a064 Add a permission check for the podcast folder
This should make podcast-related stacktraces a bit
more obvious to debug for users.
2019-04-17 23:08:26 +02:00
jvoisin 716fd3635c Remove a useless test page 2019-04-17 22:26:45 +02:00
jvoisin e2683024af Factorize a bit the checkbox-related CSS
Since the `border: 0;` property is applied
to every checkbox, there is no need for a class.
This is also a good opportunity to use ternaries
for the `checked` attribute, instead of clumsy `if`.
2019-04-17 22:20:11 +02:00
jvoisin cf1f86f226 Move some video-cast-related inline js to an external file 2019-04-17 21:58:49 +02:00
jvoisin af4165310f Fix yet an other XSS 2019-04-12 22:39:45 +02:00
tesshucom f54e72026f version upgrade of spring-boot-dependencies,spring-boot-maven-plugin
- Safety version for CVE-2019-3795
 - Match the new jetty ecj version because the version of ecj used by
tomcat and jetty is different.
2019-04-13 02:21:57 +09:00
jvoisin e69287cfe6 Minor frameset-related factorization 2019-04-11 23:15:09 +02:00
jvoisin 17f1d45e08 Remove mentions of subsonic premium 2019-04-10 22:49:08 +02:00
tesshucom 133cf666b7 Fix processing when artist and albumArtist are null 2019-04-11 05:26:56 +09:00
tesshucom f5f1ec336f Fix to get fields when file format is ID3v2.4 2019-04-10 19:24:27 +09:00
jvoisin 90cb02105e Add a noopener and noreferrer to external urls
- noreferrer is used to prevent the browser from sending the referrer
  to the visited site
- noopener fixes a fun class of bug: https://mathiasbynens.github.io/rel-noopener/
2019-04-08 23:13:47 +02:00
jvoisin cdd47b36d2 Clicking on the logo now redirects to home instead of about
The previous behaviour was confusing, because on
most websites, clicking on the logo will redirect
to the main page, and not on the about one.
2019-04-08 18:17:19 +02:00
jvoisin a200dd0c37 Don't autocomplete the password field
I guess that this is a bit silly in 2019,
but since people tend to use weird browsers in weird
places, disabling autocompletion here might prevent
the password from ending up in some local cache.
2019-04-08 17:25:30 +02:00
jvoisin ec4b969e2c Replace latin encoding with utf-8 2019-04-07 09:27:22 +02:00