mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 13:00:23 +00:00
[Backport release-26.05] jellyfin: miscellaneous security fixes from 12.0 (#562686)
This commit is contained in:
26
pkgs/by-name/je/jellyfin/fix-playlist-visibility.patch
Normal file
26
pkgs/by-name/je/jellyfin/fix-playlist-visibility.patch
Normal file
@@ -0,0 +1,26 @@
|
||||
From 5f13afa1cecfae398ff7d84ed89fc45b14b71c61 Mon Sep 17 00:00:00 2001
|
||||
From: Shadowghost <Ghost_of_Stone@web.de>
|
||||
Date: Thu, 4 Jun 2026 19:00:03 +0200
|
||||
Subject: [PATCH] Fix playlist visibility
|
||||
|
||||
---
|
||||
MediaBrowser.Controller/Entities/Folder.cs | 5 ++++-
|
||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/MediaBrowser.Controller/Entities/Folder.cs b/MediaBrowser.Controller/Entities/Folder.cs
|
||||
--- a/MediaBrowser.Controller/Entities/Folder.cs
|
||||
+++ b/MediaBrowser.Controller/Entities/Folder.cs
|
||||
@@ -811,7 +811,10 @@ namespace MediaBrowser.Controller.Entities
|
||||
|
||||
private bool RequiresPostFiltering2(InternalItemsQuery query)
|
||||
{
|
||||
- if (query.IncludeItemTypes.Length == 1 && query.IncludeItemTypes[0] == BaseItemKind.BoxSet)
|
||||
+ // BoxSets and Playlists can have per-user visibility (shares/open access) that is stored in the
|
||||
+ // serialized item data and cannot be evaluated by the database query, so filter them in memory.
|
||||
+ if (query.IncludeItemTypes.Length > 0
|
||||
+ && query.IncludeItemTypes.All(t => t == BaseItemKind.BoxSet || t == BaseItemKind.Playlist))
|
||||
{
|
||||
Logger.LogDebug("Query requires post-filtering due to BoxSet query");
|
||||
return true;
|
||||
--
|
||||
2.51.0
|
||||
@@ -1,6 +1,7 @@
|
||||
{
|
||||
lib,
|
||||
fetchFromGitHub,
|
||||
fetchpatch,
|
||||
nixosTests,
|
||||
dotnetCorePackages,
|
||||
buildDotnetModule,
|
||||
@@ -23,6 +24,34 @@ buildDotnetModule (finalAttrs: {
|
||||
hash = "sha256-HCs4ZsutVoVH+bBZANjpPeMyV8e63Yemjg9DSr0R9zg=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
# Prevent SSRF, local file disclosure and DoS via external references in SVG rendering.
|
||||
# (No public PR.)
|
||||
(fetchpatch {
|
||||
url = "https://github.com/jellyfin/jellyfin/commit/cefa78fc1de2410e5c5c6da5062c98fe98b22d17.patch";
|
||||
hash = "sha256-TxGo+sLLG+C9omxrwvO6byzw+iRqONVLXrQKwkrY22s=";
|
||||
})
|
||||
|
||||
# Fix MaxLoginAttempts not honored.
|
||||
# https://github.com/jellyfin/jellyfin/pull/17274
|
||||
(fetchpatch {
|
||||
url = "https://github.com/jellyfin/jellyfin/commit/8b826d981bcfec22063d6008e38016f4b77790d0.patch";
|
||||
hash = "sha256-Nav05TcpjBJABybU0BVyJ0UyxKi+6nDNBQ6tjY0DPT8=";
|
||||
})
|
||||
|
||||
# GHSA-9x85-gx46-6522
|
||||
# Reject user impersonation when retrieving private playlist items.
|
||||
# (No public PR.)
|
||||
(fetchpatch {
|
||||
url = "https://github.com/jellyfin/jellyfin/commit/911ac3769cdcce50a8f6e0b3c0739d509bd9a23f.patch";
|
||||
hash = "sha256-MwaTwqhuBc7yWW3cL6htlyDQ9O1wt5iFCOM/oVTi6P0=";
|
||||
})
|
||||
|
||||
# Don't let unauthorized users to list other's private playlists.
|
||||
# https://github.com/jellyfin/jellyfin/pull/17025
|
||||
./fix-playlist-visibility.patch
|
||||
];
|
||||
|
||||
propagatedBuildInputs = [ sqlite ];
|
||||
|
||||
projectFile = "Jellyfin.Server/Jellyfin.Server.csproj";
|
||||
|
||||
Reference in New Issue
Block a user