diff --git a/CMakeLists.txt b/CMakeLists.txt index b5ecf689..b34a72cc 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -8,6 +8,7 @@ set(CMAKE_CXX_STANDARD 17) set(CMAKE_CXX_STANDARD_REQUIRED True) include(CTest) +find_package(PkgConfig REQUIRED) find_package(Threads REQUIRED) find_package(Filesystem REQUIRED) find_package(FFMPEGAV REQUIRED) diff --git a/INSTALL.md b/INSTALL.md index 3a15efb6..63691737 100644 --- a/INSTALL.md +++ b/INSTALL.md @@ -173,9 +173,9 @@ server { location / { + proxy_set_header Client-IP $remote_addr; proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_pass http://localhost:5082/; diff --git a/README.md b/README.md index 1d8d524f..6dc0a0ef 100644 --- a/README.md +++ b/README.md @@ -77,6 +77,14 @@ $setmulti(albumartistssort,%_albumartists_sort%) * Previous track: Ctrl + Left * Next track: Ctrl + Right +## Security considerations +_Wt_ (the web framework used) has some [built-in security measures](https://www.webtoolkit.eu/wt/features#security), but _LMS_ also has some too: +* to mitigate brute force login attempts, _LMS_ uses an internal login throttler based on the client IP address. The `Client-IP` or `X-Forwarded-For` headers are used to determined the real IP adress, so make sure to properly configure your reverse proxy to filter or even erase the values (see example in [INSTALL.md](INSTALL.md)). +* all passwords are stored hashed and salted using [bcrypt](https://fr.wikipedia.org/wiki/Bcrypt) +* all the resources relative to the music collection (tracks, covers, etc.) are private to a session + +## Keyboard shortcuts + ## Installation See [INSTALL.md](INSTALL.md) file. diff --git a/src/lms/ui/explore/ReleaseCollector.cpp b/src/lms/ui/explore/ReleaseCollector.cpp index c9b84bb6..552f2e66 100644 --- a/src/lms/ui/explore/ReleaseCollector.cpp +++ b/src/lms/ui/explore/ReleaseCollector.cpp @@ -22,6 +22,7 @@ #include #include "database/Release.hpp" +#include "database/Session.hpp" #include "database/User.hpp" #include "database/TrackList.hpp" #include "scrobbling/IScrobbling.hpp" @@ -79,6 +80,8 @@ namespace UserInterface std::vector ReleaseCollector::getAll() { + auto transaction {LmsApp->getDbSession().createSharedTransaction()}; + bool moreResults; const auto releases {get(std::nullopt, moreResults)}; diff --git a/src/lms/ui/explore/TrackCollector.cpp b/src/lms/ui/explore/TrackCollector.cpp index 6d51d4ea..ffcebf4c 100644 --- a/src/lms/ui/explore/TrackCollector.cpp +++ b/src/lms/ui/explore/TrackCollector.cpp @@ -21,9 +21,10 @@ #include +#include "database/Session.hpp" #include "database/Track.hpp" -#include "database/User.hpp" #include "database/TrackList.hpp" +#include "database/User.hpp" #include "scrobbling/IScrobbling.hpp" #include "utils/Service.hpp" #include "Filters.hpp" @@ -79,6 +80,8 @@ namespace UserInterface std::vector TrackCollector::getAll() { + auto transaction {LmsApp->getDbSession().createSharedTransaction()}; + bool moreResults; const auto releases {get(std::nullopt, moreResults)};