Changeset f2eacca in Klonkt for src/routes
- Timestamp:
- 06/30/2026 01:50:00 AM (2 months ago)
- Branches:
- main
- Children:
- 084d1c0
- Parents:
- 80797d7
- Location:
- src/routes
- Files:
-
- 2 edited
-
admin-audio.js (modified) (2 diffs)
-
audio.js (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
src/routes/admin-audio.js
r80797d7 rf2eacca 96 96 const rows = db.prepare(` 97 97 SELECT t.id, t.title, t.artist, t.album, t.duration, t.cover_url, 98 t.position, t.created_at, t.downloadable, m.filename, m.size, m.mime_type98 t.position, t.created_at, t.downloadable, t.fedi_open, m.filename, m.size, m.mime_type 99 99 FROM audio_tracks t 100 100 LEFT JOIN media m ON m.id = t.media_id … … 288 288 }); 289 289 290 // Federate-the-file (fedi_open) per track on/off. When on, this track's audio file is shared 291 // as a real AS2 Audio attachment + served ungated → it plays inline in EVERY fediverse client 292 // (incl. the Mastodon apps), but the file is downloadable. Off (default) = gated, web-player only. 293 router.post('/:id/fedi-open', requireGod, (req, res) => { 294 const site = res.locals.site; 295 if (!site) return res.status(404).send('Site required'); 296 const row = db.prepare('SELECT fedi_open FROM audio_tracks WHERE id = ? AND site_id = ?').get(req.params.id, site.id); 297 if (row) { 298 db.prepare('UPDATE audio_tracks SET fedi_open = ? WHERE id = ? AND site_id = ?') 299 .run(row.fedi_open ? 0 : 1, req.params.id, site.id); 300 } 301 res.redirect('/admin/audio'); 302 }); 303 290 304 router.post('/:id/delete', requireGod, (req, res) => { 291 305 const site = res.locals.site; -
src/routes/audio.js
r80797d7 rf2eacca 54 54 }; 55 55 56 // Access gate: allow only same-origin browser fetches / media loads.57 function isAllowedAudioRequest(req ) {56 // Access gate: same-origin browser fetches / media loads — PLUS fediverse-shared tracks. 57 function isAllowedAudioRequest(req, filename) { 58 58 if (req.get('X-Audio-Player') === '1') return true; // our blob fetch 59 59 const site = req.get('Sec-Fetch-Site'); // set by modern browsers 60 return site === 'same-origin' || site === 'same-site'; 60 if (site === 'same-origin' || site === 'same-site') return true; 61 // fedi_open tracks are deliberately served ungated so remote servers (Mastodon, …) can 62 // fetch + play the file inline. The operator opted this specific track in (per-track flag). 63 if (filename) { 64 try { 65 const r = db.prepare(`SELECT 1 FROM audio_tracks t JOIN media m ON t.media_id = m.id 66 WHERE t.fedi_open = 1 AND (m.storage_path = ? OR m.storage_path LIKE ?) LIMIT 1`).get(filename, '%' + filename); 67 if (r) return true; 68 } catch { /* ignore */ } 69 } 70 return false; 61 71 } 62 72 … … 64 74 const { filename } = req.params; 65 75 66 if (!isAllowedAudioRequest(req )) {76 if (!isAllowedAudioRequest(req, filename)) { 67 77 return res.status(403).send('Direct access not allowed'); 68 78 }
Note:
See TracChangeset
for help on using the changeset viewer.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)