François-Xavier Thomas
820a4faec2
Avoid logging sensitive URL parameters in the Subsonic API
...
In case of exceptions, Airsonic logs the full URL that triggered it
since 417583cc
, including possibly sensitive query parameters such as
the authentication password/tokens passed to the Subsonic API.
This replaces the value set for this parameter in the URL by the
"<hidden>" string.
6 years ago
Andrew DeMaria
1463f75b06
Merge remote-tracking branch 'origin/pr/961'
6 years ago
Andrew DeMaria
693336af83
Merge remote-tracking branch 'origin/pr/967'
6 years ago
Andrew DeMaria
e2e1554e93
Merge remote-tracking branch 'origin/pr/968'
6 years ago
Andrew DeMaria
cddc2b2fa7
Merge remote-tracking branch 'origin/pr/983'
6 years ago
Andrew DeMaria
d03b4dd963
Merge remote-tracking branch 'origin/pr/984'
6 years ago
Andrew DeMaria
2030caa219
Merge remote-tracking branch 'origin/pr/994'
6 years ago
Andrew DeMaria
1bd70263bd
Merge remote-tracking branch 'origin/pr/989'
6 years ago
Andrew DeMaria
24f5c2d8f5
Merge remote-tracking branch 'origin/pr/1005'
6 years ago
Andrew DeMaria
3f9c525933
Merge remote-tracking branch 'origin/pr/1007'
6 years ago
Andrew DeMaria
50964fa378
Merge remote-tracking branch 'origin/pr/1002'
6 years ago
Andrew DeMaria
326583839e
Merge remote-tracking branch 'origin/pr/982'
6 years ago
Andrew DeMaria
a2b423aa82
Merge remote-tracking branch 'origin/pr/1020'
6 years ago
Andrew DeMaria
f5250e36f1
Merge remote-tracking branch 'origin/pr/1021'
6 years ago
Andrew DeMaria
fdfa244ad4
Merge remote-tracking branch 'origin/pr/1022'
6 years ago
Andrew DeMaria
fe08dd1c94
Merge remote-tracking branch 'origin/pr/1023'
6 years ago
Andrew DeMaria
969394a1c9
Merge remote-tracking branch 'origin/pr/1006'
6 years ago
jvoisin
a21188a064
Add a permission check for the podcast folder
...
This should make podcast-related stacktraces a bit
more obvious to debug for users.
6 years ago
jvoisin
716fd3635c
Remove a useless test page
6 years ago
jvoisin
e2683024af
Factorize a bit the checkbox-related CSS
...
Since the `border: 0;` property is applied
to every checkbox, there is no need for a class.
This is also a good opportunity to use ternaries
for the `checked` attribute, instead of clumsy `if`.
6 years ago
jvoisin
cf1f86f226
Move some video-cast-related inline js to an external file
6 years ago
jvoisin
af4165310f
Fix yet an other XSS
6 years ago
tesshucom
f54e72026f
version upgrade of spring-boot-dependencies,spring-boot-maven-plugin
...
- Safety version for CVE-2019-3795
- Match the new jetty ecj version because the version of ecj used by
tomcat and jetty is different.
6 years ago
jvoisin
e69287cfe6
Minor frameset-related factorization
6 years ago
Andrew DeMaria
10e90beb30
Refactor stream integration test
...
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
6 years ago
jvoisin
17f1d45e08
Remove mentions of subsonic premium
6 years ago
jvoisin
90cb02105e
Add a noopener and noreferrer to external urls
...
- noreferrer is used to prevent the browser from sending the referrer
to the visited site
- noopener fixes a fun class of bug: https://mathiasbynens.github.io/rel-noopener/
6 years ago
jvoisin
a200dd0c37
Don't autocomplete the password field
...
I guess that this is a bit silly in 2019,
but since people tend to use weird browsers in weird
places, disabling autocompletion here might prevent
the password from ending up in some local cache.
6 years ago
jvoisin
9dea3e9051
Add a CONTRIBUTING.md file
6 years ago
jvoisin
ec4b969e2c
Replace latin encoding with utf-8
6 years ago
jvoisin
5acabcae19
Remove resource bundles for messages as well
6 years ago
jo
eea9416fbe
[skip ci] Update stale labels
6 years ago
Andrew DeMaria
c3a1980ca2
Merge remote-tracking branch 'airsonic/pr/964'
6 years ago
Andrew DeMaria
15c6a8861b
Fix formatting on external player for firefox
...
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
6 years ago
Andrew DeMaria
b128479972
Merge remote-tracking branch 'airsonic/pr/962'
6 years ago
Andrew DeMaria
4b2cf99adf
Merge remote-tracking branch 'airsonic/pr/951'
6 years ago
Andrew DeMaria
8e0d49834c
Merge remote-tracking branch 'airsonic/pr/929'
6 years ago
Andrew DeMaria
ab33b34a67
Merge remote-tracking branch 'airsonic/pr/898'
...
Conflicts:
airsonic-main/src/main/java/org/airsonic/player/controller/StreamController.java
6 years ago
tesshucom
131713aaf4
With Jetty
...
Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
6 years ago
tesshucom
4cd9e9deac
revert cling-core, cling-support, seamless-util and configuration
6 years ago
Andrew DeMaria
8ed98ebb6b
Merge remote-tracking branch 'airsonic/pr/980'
6 years ago
jvoisin
9fb56c031b
Fix the systemd unit file for OpenJDK
6 years ago
jvoisin
7d865ea7a9
Add a lost meta back
6 years ago
jvoisin
8f74db2ec1
Remove the unused embedded copy of weupnp
6 years ago
jvoisin
5c54bff5ac
Remove the unused embedded copy of jarbundler
6 years ago
jvoisin
258c68dd4d
Remove the embedded copy of appbundler
6 years ago
jvoisin
422127e3f6
Replace the flash player with medialement.js for the shared media
6 years ago
François-Xavier Thomas
3f4a49c95a
Fix dependency error with org.eclipse.jetty.jetty
...
This is only used by reflection, and should be provided by the servlet
container (Tomcat or Jetty).
6 years ago
François-Xavier Thomas
51b738053f
Make it work even if Tomcat-specific exceptions are not available
...
When Tomcat is not available (for example, when using Jetty), the
ClientAbortException is not available either, causing an error when
starting the server.
This commit fixes that, and instead catches that exception (or its Jetty
equivalent) via reflection.
6 years ago
François-Xavier Thomas
ec96b9711d
Show more informative messages while streaming
...
When streaming, log messages now show the URL and IP of the originating
request, so that it's easier to determine what client is listening to
something on the server.
6 years ago