2778 Commits

Author SHA1 Message Date
DariusIII 5ee33502b1 Update nzb creation 2026-07-13 16:51:10 +02:00
DariusIII 0eae1a7ca9 Harden 2FA 2026-07-13 13:07:17 +02:00
DariusIII b5b6841eca Update admin area views and controllers 2026-07-13 11:36:42 +02:00
DariusIII 645eba20e2 Update additional PP 2026-07-12 16:30:39 +02:00
DariusIII 1e6c6f5193 Update APIv2 controller 2026-07-12 12:03:34 +02:00
DariusIII 11734a4163 Small speedup 2026-07-12 11:10:20 +02:00
DariusIII 01ee665a24 Update APIv2 speed 2026-07-12 11:06:31 +02:00
DariusIII 16388f1666 Make small speed improvements in XML_Response 2026-07-12 10:52:53 +02:00
DariusIII e11318eb2c Update XML_Response for API 2026-07-12 10:20:19 +02:00
DariusIII 138c0bfc30 Fix remember me behavior 2026-07-12 09:46:19 +02:00
DariusIII 5a54fbe457 Fix issue in XMLResponse class 2026-07-11 15:22:49 +02:00
DariusIII a3a6fd8e4a Add missing files 2026-07-11 12:05:47 +02:00
DariusIII 254faf3050 Update series page 2026-07-11 11:40:39 +02:00
DariusIII ccb79f13b9 Update API handling 2026-07-11 10:00:01 +02:00
DariusIII b0c781421c Update admin views and controllers 2026-07-10 22:35:32 +02:00
DariusIII f6c18cdeac Update views and related controllers 2026-07-10 21:31:19 +02:00
DariusIII 67be01c5ad Update health check 2026-07-10 16:30:46 +02:00
DariusIII 06379f25cb Revert "Fix getCategoryExclusionById() excluding every category for role-only users" 2026-07-09 08:14:18 +02:00
DariusIII 8a63ee6700 Merge pull request #1860 from joemeyer76/fix/category-exclusion-role-permissions
Fix getCategoryExclusionById() excluding every category for role-only users
2026-07-04 09:29:36 +02:00
joemeyer76 b0fd5491a0 Fix NNTPService::getXOVER() TypeError on NNTP error responses
getXOVER() declared its return type as `array|string|NNTPService`, which
does not include DariusIII\NetNntp\Error. The underlying NNTP client
legitimately returns an Error object whenever the server responds with
an error to an XOVER command (e.g. a group with no matching articles,
or a range past the group's high-water mark) -- both call sites in
BinariesService already guard for exactly this case via
NNTPService::isError($result). Because the declared return type
excluded Error, PHP raised a TypeError before either caller ever got a
chance to run that check:

    App\Services\NNTP\NNTPService::getXOVER(): Return value must be of
    type App\Services\NNTP\NNTPService|array|string, DariusIII\NetNntp\Error
    returned

In practice this crashed the first XOVER call that hit any error
response, which made historical backfill (`update:backfill` /
`multiprocessing:backfill`) unusable beyond the very first successful
chunk for a group -- backfill by its nature keeps requesting older and
older ranges until it walks off the group's actual history, at which
point the server error becomes inevitable.

Every sibling method on this class that the NNTP client can answer with
an Error object (doConnect, doQuit, getOverview, getGroups, getMessages,
getMessagesByMessageID) already declares `mixed` for this same reason.
This change brings getXOVER() in line with that existing convention
rather than introducing a new pattern.

Added a regression test that uses reflection to assert getXOVER()'s
return type permits DariusIII\NetNntp\Error (or is unrestricted via
`mixed`), plus a sanity check that NNTPService::isError() correctly
identifies Error instances. Verified the test fails against the old
`array|string|NNTPService` signature and passes against `mixed`.

Manually verified against a live NNTP server: `update:backfill` on a
real group ran 15+ chunks past the point where it previously crashed on
the very first error response, with no exceptions.
2026-07-03 20:21:36 -04:00
joemeyer76 e62724f2cd Fix getCategoryExclusionById() excluding every category for role-only users
RolesAndPermissionsSeeder grants every 'view *' permission via
Role::givePermissionTo() only -- it never grants permissions directly to a
user with User::givePermissionTo(). That is true for every seeded role,
including Admin.

User::getCategoryExclusionById() computed the allowed permission set as:

    $userAllowed = $user->getDirectPermissions()->pluck('name')->toArray();
    $roleAllowed = $user->getAllPermissions()->pluck('name')->toArray();
    $allowed = array_intersect($roleAllowed, $userAllowed);

getAllPermissions() already includes permissions granted via the user's
role(s), so intersecting it with getDirectPermissions() (permissions
assigned directly to the user, bypassing roles) means $allowed is empty
for any user whose permissions come only from their role. Since every
seeded role works this way, this silently excluded every category root
for every user on a fresh install, and any subsequent Newznab/Torznab API
search or browse request returned zero results with no visible error.

Fix: use getAllPermissions() directly, since it already reflects both
role-granted and directly-granted permissions.

Added a regression test (test_role_only_permissions_are_not_excluded)
that mirrors the real seeder setup -- role-only permissions, nothing
granted directly to the user -- to make sure this doesn't regress.
2026-07-03 18:18:46 -04:00
DariusIII 7b5313e97e Update detection 2026-07-02 11:43:08 +02:00
DariusIII 3faeb1d63a Fix blocking issue 2026-07-01 14:44:16 +02:00
DariusIII 0790d2290c Hide sensitive info from log 2026-06-30 19:05:15 +02:00
DariusIII 5b927b4581 Update blocking of abusive services 2026-06-30 17:28:09 +02:00
DariusIII afe6202460 Fix multiple user id queries 2026-06-26 23:19:30 +02:00
DariusIII bb2658c48f Fix update command 2026-06-24 20:33:02 +02:00
DariusIII dbeb6a3c49 Add missing class 2026-06-22 21:59:31 +02:00
DariusIII 5f5ce7b4b1 Add missing files 2026-06-22 21:24:58 +02:00
DariusIII 74d874c17b Update manticoresearch support for latest version changes 2026-06-22 21:12:38 +02:00
DariusIII 8d1d238f5f Update Trakt support 2026-06-19 23:22:16 +02:00
DariusIII 2f96d921df Fix RSS health check 2026-06-17 13:34:13 +02:00
DariusIII 995c215be9 CS fixes 2026-06-17 12:31:33 +02:00
DariusIII 580f5a1589 Fix issues in GDPR support 2026-06-17 12:26:04 +02:00
DariusIII ab41b91af5 Add GDPR compliance 2026-06-17 09:49:39 +02:00
DariusIII ca76cebbaf Fix error in admin 2026-06-15 12:31:39 +02:00
DariusIII d9c4cf2d7e Update bulk user actions 2026-06-15 12:15:10 +02:00
DariusIII 96f6900306 Add user bulk actions 2026-06-15 11:36:03 +02:00
DariusIII a7a6479e93 Fix email verification url 2026-06-15 01:26:34 +02:00
DariusIII b6b3828d5a Merge pull request #1858 from Kcchouette/fix/stripos-reversed-args
fix: correct reversed stripos/strpos arguments in ConsoleService
2026-06-13 23:07:19 +02:00
Kcchouette e5df723720 fix: correct reversed stripos/strpos arguments in ConsoleService
Fix 5 instances of stripos('literal', ) where arguments were
reversed, causing the needle to be searched inside a short literal
instead of the literal inside the variable:

- Line 599: stripos('dlc', ) → stripos(, 'dlc') — DLC
  branch was never entered for real game titles
- Line 601: stripos('Rock Band Network', ) → stripos(, ...)
  — Rock Band check was dead code inside the dead DLC branch
- Line 603: strpos('-', ) → str_contains(, '-') — DLC
  hyphen splitting never triggered
- Line 622: stripos('PSX2PSP', ) → stripos(, ...)
  — worked by accident (PSX is prefix of PSX2PSP)
- Line 626: stripos('XBLA', ) + stripos('dlc', ) →
  stripos(, ...) + stripos(, ...)

Also adds ConsoleServiceDlcParsingTest (9 tests) covering DLC title
parsing, Rock Band Network handling, hyphen splitting, and XBLA
platform upgrade.
2026-06-13 21:05:15 +02:00
Kcchouette 062548f57a refactor: replace strpos with PHP 8.x string functions
- IRCClient: strpos(..., 'PONG') !== 0 → ! str_starts_with(...)
- IGDBService: strpos(, '//') === 0 → str_starts_with(...)
- Settings: strpos(, '.') !== false → str_contains(...)
- NntmuxCheckIndex: 3x strpos → str_contains

strpos with offset (YencService, MovieService, ReleaseRemoverService)
is left untouched as it is a legitimate use case.
2026-06-13 18:12:22 +02:00
DariusIII 937913cbf8 CS fixes 2026-06-12 10:16:12 +02:00
DariusIII d970bbffc6 Improve security 2026-06-12 10:11:15 +02:00
DariusIII 499d6d8cfc CS fixes 2026-06-11 10:32:38 +02:00
DariusIII 832fb5fb59 Fix couple of security issues 2026-06-11 10:26:29 +02:00
DariusIII 5a837e52af Update release reporting 2026-06-08 16:42:06 +02:00
DariusIII f8294f1b0a Add release report response 2026-06-08 16:31:15 +02:00
DariusIII 2d6194fb3c Don't cache User cart RSS feed 2026-06-05 00:08:14 +02:00
DariusIII a8f79c05b1 Fix in process count 2026-06-04 09:54:43 +02:00