Commit Graph

19 Commits

Author SHA1 Message Date
Hamid Reza Mohammadi
7a722455ec CSRF antiforgery fixes 2026-09-27 14:03:38 +03:30
Hamid Reza Mohammadi
ca84dab8d5 removing half baked music link page 2026-09-15 12:05:22 +03:30
Hamid Reza Mohammadi
3d94c92620 caching control fixes 2026-09-15 07:57:27 +03:30
Ehsan Mohandesi
cb7b1b03a3 Replace Spotify search with a validated music link box
The Spotify Web API integration stopped working, leaving /spotify unable to
suggest songs at all. Replace the artist/album/track search flow with a single
box where the user pastes a link to the track on a music service.

Links are checked against a hardcoded allow-list of legal streaming and store
domains so links to ripped audio cannot be submitted. The check lives in the
service layer, not just the page: any authenticated user can POST to
/api/ganjoor/song directly and bypass the UI. Hosts are matched against the
full host or a dot-prefixed suffix, so look-alikes such as
open.spotify.com.evil.com are rejected; https is required, and userinfo and
non-default ports are refused. Accepted URLs are canonicalised - https,
lowercased host, tracking parameters stripped - so the same track always yields
the same stored URL and duplicate detection actually works.

Links are stored under one new type, PoemMusicTrackType.MusicUrl, with the
platform derived from the host at render time. That needs no migration or
backfill, and supporting another service later needs no new enum value. The
duplicate check no longer keys on TrackType, which closes a gap where the same
URL could be resubmitted as a different type. Several links per poem remain
allowed; only an identical URL for the same poem is refused.

The Spotify search page and its OAuth plumbing are kept and simply redirect to
/musiclink while the existing SpotifyWorking flag is false, so the old flow can
be restored if that API ever works again.

Track URLs are no longer written through Html.Raw into href attributes. They
previously came from the Spotify API; now that they are user supplied, encoding
them prevents stored XSS.

Also fixes two latent bugs in SuggestSong that this flow would have hit: a null
dereference when TrackUrl is empty, and a singer lookup that matched any singer
with an empty Url.
2026-09-13 22:16:18 -05:00
Hamid Reza Mohammadi
da0648606e caching improvements 2026-09-12 15:05:43 +03:30
Hamid Reza Mohammadi
11a085efb3 fixes for caching 2026-09-01 16:14:47 +03:30
Hamid Reza Mohammadi
497e769c6d refactoring 2026-07-17 08:53:51 +03:30
Hamid Reza Mohammadi
6cda2ab299 refactoring 2026-07-16 16:39:13 +03:30
Hamid Reza Mohammadi
64ab66aacd refactoring 2026-07-15 08:43:40 +03:30
Hamid Reza Mohammadi
68e652db4a fix for antiforgery exceptions 2025-01-27 09:56:32 +03:30
Hamid Reza Mohammadi
ede63c2f8f CORS policy fixed 2023-08-04 09:14:01 +03:30
Hamid Reza Mohammadi
be577b6477 #404 a temporary CORS fix 2023-07-31 13:27:02 +03:30
Hamid Reza Mohammadi
d8ce761f4e #122 adding Access-Control-Allow-Origin: https://museum.ganjoor.net to pages 2021-05-21 12:39:58 +04:30
Hamid Reza Mohammadi
19e21f3097 switching back to httpclient from db access in GanjooRazor 2021-05-17 14:13:26 +04:30
Hamid Reza Mohammadi
cf3b10549c switching back to httpclient instead of direct db access in GanjooRazor 2021-05-17 12:39:39 +04:30
Hamid Reza Mohammadi
e0883cf0ae fixing mistake on using AddDbContextPool 2021-05-16 19:52:23 +04:30
Hamid Reza Mohammadi
9feecb624f using AddDbContextPool 2021-05-13 19:03:34 +04:30
Hamid Reza Mohammadi
a541dbb7c1 #112 the first working version 2021-05-09 20:11:14 +04:30
Hamid Reza Mohammadi
078893f6df #112 GanjooRazor project added 2021-05-08 18:59:39 +04:30