Commit Graph

491 Commits

Author SHA1 Message Date
Anas Rashid
91a7517d31 Remove music features (Spotify, Golha, Beeptunes, music index, song suggestions)
Pages, API endpoints, services and assets removed; music DB models/tables kept
so the feature can be rebuilt for Urdu later.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 23:41:02 +02:00
Anas Rashid
223166ef5e Divan: make env config work, ur-PK locale, own-site links relative
- AddEnvironmentVariables() where appsettings.json is read directly
- JWT ValidIssuer follows RSecurityBackend:ApplicationName (was hard-coded Ganjoor)
- deploy/entrypoint.sh: copy settings RSecurityBackend reads only from appsettings.json
- Dockerfile: pin SDK 10.0.302 (newer Razor rejects some upstream views)
- lang=ur-PK; ganjoor.net own-site links -> relative; api.ganjoor.net -> APIRoot; search.xml
- DIVAN.md: first admin password is Test!123 (upstream doc is wrong)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 23:32:16 +02:00
Anas Rashid
1811572d9e Divan: Urdu classical poetry fork of GanjoorService
- Rebrand گنجور -> دیوان across GanjooRazor; lang=ur; Urdu home page and footer
- Hijri century groups with Urdu names
- Noto Nastaliq Urdu (default) / Noto Naskh Arabic switch
- Remove footer links to Ganjoor-only services; link Wikisource, data and code
- Linux deployment: Dockerfile, docker-compose (SQL Server 2022, API, site, Caddy)
- DIVAN.md: changes and deploy guide

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 23:14:25 +02:00
Hamid Reza Mohammadi
2e0e87d277 people tags #387 2026-10-04 07:58:00 +03:30
Hamid Reza Mohammadi
15c8f8f526 people tags #387 2026-10-03 21:22:12 +03:30
Hamid Reza Mohammadi
3493225dc5 people tags #387 2026-10-03 21:16:42 +03:30
Hamid Reza Mohammadi
4ca749bad5 people tags #387 2026-10-03 19:07:05 +03:30
Hamid Reza Mohammadi
fecbf0ec3b people tags #387 2026-10-03 18:05:55 +03:30
Hamid Reza Mohammadi
00f98bb611 editor improvements 2026-10-03 17:22:57 +03:30
Hamid Reza Mohammadi
24dc4da51b editor improvements 2026-10-03 16:49:27 +03:30
Hamid Reza Mohammadi
9176c62cfe editor improvements 2026-10-03 16:43:39 +03:30
Hamid Reza Mohammadi
4ba7da57b8 people tags #387 2026-10-03 08:41:31 +03:30
Hamid Reza Mohammadi
0c98df8526 editor service errors are displayed better 2026-10-03 08:17:31 +03:30
Hamid Reza Mohammadi
5ce8973ca3 people tags #387 2026-10-03 08:10:12 +03:30
Hamid Reza Mohammadi
f4b522e980 people tags #387 2026-10-02 21:24:05 +03:30
Hamid Reza Mohammadi
1f80d03fef people tags #387 2026-10-02 08:14:09 +03:30
Hamid Reza Mohammadi
433cffa5ae people tags #387 2026-10-02 08:06:26 +03:30
Hamid Reza Mohammadi
b20281df7b people tags #387 2026-10-01 14:43:45 +03:30
Hamid Reza Mohammadi
4f1f155266 people tags #387 2026-10-01 08:07:46 +03:30
Hamid Reza Mohammadi
cee01357fc people tags #387 2026-10-01 08:01:18 +03:30
Hamid Reza Mohammadi
ddbef76d94 people tags #387 2026-09-30 20:44:35 +03:30
Hamid Reza Mohammadi
800857aadc people tags #387 2026-09-30 19:14:17 +03:30
Hamid Reza Mohammadi
eb88056d0b people tags #387 2026-09-30 18:31:59 +03:30
Hamid Reza Mohammadi
fa8544b62d people tags #387 2026-09-28 15:06:14 +03:30
Hamid Reza Mohammadi
073222ec6d people tags #387 2026-09-28 13:48:43 +03:30
Hamid Reza Mohammadi
14461c362f #421 geo tag suggestion 2026-09-27 21:58:43 +03:30
Hamid Reza Mohammadi
601c29af36 logout from other sessions 2026-09-27 15:49:07 +03:30
Hamid Reza Mohammadi
7a722455ec CSRF antiforgery fixes 2026-09-27 14:03:38 +03:30
Hamid Reza Mohammadi
b94387d603 comments ui fix 2026-09-26 22:05:53 +03:30
Hamid Reza Mohammadi
226f7c3370 user sessions 2026-09-26 19:11:07 +03:30
Hamid Reza Mohammadi
7446057ca9 #421 geo tag moderation 2026-09-26 16:34:19 +03:30
Hamid Reza Mohammadi
af75cc18d9 xss vulnerability fix 2026-09-25 17:46:22 +03:30
Hamid Reza Mohammadi
ce05b9be0e #421 geo tag suggestion 2026-09-25 15:38:22 +03:30
Hamid Reza Mohammadi
f5f6ddf5b1 #421 geo tag moderation 2026-09-25 15:37:03 +03:30
Hamid Reza Mohammadi
6d2f59aa22 #421 geo tag moderation 2026-09-25 15:25:54 +03:30
Hamid Reza Mohammadi
fc241748e7 #421 geo tag suggestion + typo fixes in editors 2026-09-25 14:37:51 +03:30
Hamid Reza Mohammadi
aaacfe0442 #421 get tag suggestion 2026-09-25 14:06:58 +03:30
Hamid Reza Mohammadi
9cebdc7f5e #421 geo tag suggestion 2026-09-25 13:57:31 +03:30
Hamid Reza Mohammadi
7a7b2585b6 #421 geo tag suggestion 2026-09-25 13:49:54 +03:30
Hamid Reza Mohammadi
afa5b24ded geotag edit fix 2026-09-25 12:54:51 +03:30
Hamid Reza Mohammadi
aa84dca5be fixes 2026-09-25 12:13:30 +03:30
Hamid Reza Mohammadi
2e43b67ba1 geotag: warning fix 2026-09-25 11:55:54 +03:30
Hamid Reza Mohammadi
d39869f6e1 geotag couplet selection 2026-09-25 08:58:47 +03:30
Hamid Reza Mohammadi
295ece7c7c geo tag fix 2026-09-24 08:16:51 +03:30
Hamid Reza Mohammadi
78798feb19 geotag fixes 2026-09-23 20:16:03 +03:30
Hamid Reza Mohammadi
ff8f6f3a96 geotag suggestion 2026-09-23 08:11:58 +03:30
Hamid Reza Mohammadi
0b91762f64 geo tag fix 2026-09-22 20:12:53 +03:30
Hamid Reza Mohammadi
4aef7ace1b ui for enable users to suggest geo location tags #421 2026-09-20 06:43:36 +03:30
Hamid Reza Mohammadi
e6397afae4 fix shadow 2026-09-14 20:30:50 +03:30
Ehsan Mohandesi
cb7b1b03a3 Replace Spotify search with a validated music link box
The Spotify Web API integration stopped working, leaving /spotify unable to
suggest songs at all. Replace the artist/album/track search flow with a single
box where the user pastes a link to the track on a music service.

Links are checked against a hardcoded allow-list of legal streaming and store
domains so links to ripped audio cannot be submitted. The check lives in the
service layer, not just the page: any authenticated user can POST to
/api/ganjoor/song directly and bypass the UI. Hosts are matched against the
full host or a dot-prefixed suffix, so look-alikes such as
open.spotify.com.evil.com are rejected; https is required, and userinfo and
non-default ports are refused. Accepted URLs are canonicalised - https,
lowercased host, tracking parameters stripped - so the same track always yields
the same stored URL and duplicate detection actually works.

Links are stored under one new type, PoemMusicTrackType.MusicUrl, with the
platform derived from the host at render time. That needs no migration or
backfill, and supporting another service later needs no new enum value. The
duplicate check no longer keys on TrackType, which closes a gap where the same
URL could be resubmitted as a different type. Several links per poem remain
allowed; only an identical URL for the same poem is refused.

The Spotify search page and its OAuth plumbing are kept and simply redirect to
/musiclink while the existing SpotifyWorking flag is false, so the old flow can
be restored if that API ever works again.

Track URLs are no longer written through Html.Raw into href attributes. They
previously came from the Spotify API; now that they are user supplied, encoding
them prevents stored XSS.

Also fixes two latent bugs in SuggestSong that this flow would have hit: a null
dereference when TrackUrl is empty, and a singer lookup that matched any singer
with an empty Url.
2026-09-13 22:16:18 -05:00