mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
[Bug]: download some rss feed error with v2.5.0 #1495
Closed
opened 2026-04-24 23:47:26 +02:00 by adam
·
9 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#1495
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Rookiewan on GitHub (Oct 31, 2023).
Describe the issue
My rss feed is generate by RssHub http://192.168.6.220:1200/163/music/djradio/12,It worked fine in previous versions.
Steps to reproduce the issue
Audiobookshelf version
v2.5.0
How are you running audiobookshelf?
Docker
@advplyr commented on GitHub (Oct 31, 2023):
Due to the security advisory submitted here https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-mgj7-rfx8-vhpr I added an SSRF request filter. https://github.com/y-mehta/ssrf-req-filter
That validates the path being entered is external. I suppose we could allow for disabling that at the users own risk so will leave this open for now to see if anyone has thoughts.
@Rookiewan commented on GitHub (Nov 1, 2023):
Thank you, I understand, but now I don't know how to make it available.
@advplyr commented on GitHub (Nov 1, 2023):
You can use a reverse proxy and serve it over https
@fmillion-mnsu commented on GitHub (Apr 21, 2024):
Came here from my issue. I definitely need the ability to load podcasts from internal network IP addresses. I would definitely like an option to allow internal IPs on podcast downloads with a link to info on SSRF. Alternatively, some sort of DNS or IP address allowlist would work and arguably be more secure, since you would explicitly state which internal IP address the podcast is hosted at and allow only that IP address.
@midasvo commented on GitHub (Apr 24, 2024):
I host an application locally that serves podcast feeds and I do not want to expose this to the internet. Would really appreciate a way to toggle this setting or whitelist a container name / ip.
@advplyr commented on GitHub (Apr 25, 2024):
I updated this issue to an enhancement for adding that server setting: https://github.com/advplyr/audiobookshelf/issues/2549
I'll try to get this in the next release
@MaxTan commented on GitHub (May 24, 2024):
use reverse proxy and services it over https still prompts failure.
log:
[podcastUtils] getPodcastFeed Error Error: Call to 192.168.1.2 is blocked.@fmillion-mnsu commented on GitHub (Jun 3, 2024):
yes, it looks like the ssrf-filter plugin is the "nuclear option" as it simply blocks ALL connections based on IP address, https/dns/etc. don't even matter to that filter. (it's also a very hacky way of implementing an ssrf filter to begin with.) ssrf-filter actually uses ipaddr.js which has its own issues with IP address classification.
The easy short-term fix is simply an environment variable that allows you to disable ssrf-filter. A better option would be an allowlist for domains or IP addresses that bypass any filtering.
I might dig into the code at some point to see if I can implement it, but in the meantime I ended up having to host my podcast feed on one of my DigitalOcean instances. I use Traefik so I just setup a service pointing to my internal server via my VPN, and added an IP whitelist filter so that only the egress IP of my ABS server can actually access the rss feed and audio files, but this still ends up creating a "round-trip" (ABS -> internet -> DigitalOcean -> VPN -> LAN WWW server).
@advplyr commented on GitHub (Jun 4, 2024):
That env variables was easy to add I just forgot about it. I just added it
It will be on
edgedocker image if you want to use that before the next releaseSet env variable
DISABLE_SSRF_REQUEST_FILTERto1