mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
[Bug]: missing crossorigin="use-credentials" property #1671
Open
opened 2026-04-24 23:54:10 +02:00 by adam
·
5 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#1671
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @prof729 on GitHub (Jan 18, 2024).
Describe the issue
When using ADB that is behind traefik + authelia (that is used as identity provider) in the console there is error regarding fetching manifest file.

This is caused as manifest was expected to be json file but was returned as HTML and can't be parsed. And it's returned as HTML as authelia that is checking the requests didn't see any cookies in the request fetching manifest.json file. And this is cased as currently manifest link is missing
crossorigin="use-credentials"property (https://developer.mozilla.org/en-US/docs/Web/HTML/Element/link#crossorigin). Without this property browser does not send a cookies with request for manifest file and then authelia can not see if user is logged.As far as I've check it should be added probably somewhere here https://github.com/advplyr/audiobookshelf/blob/v2.7.2/client/nuxt.config.js#L103 in the config file:
After edditing manually compiled js file and adding this attribute it works correctly.
Thanks
Steps to reproduce the issue
Audiobookshelf version
v2.7.2
How are you running audiobookshelf?
Docker
@advplyr commented on GitHub (Feb 16, 2024):
Have you tested adding that crossorigin without going through traefik? Some users may not be using Abs that way
@prof729 commented on GitHub (Feb 16, 2024):
Yes, thats exactlly what I've done :)
So I've found in which js file there is this manifest defined (currently in

1c1d57b.jsfor version 2.7.2):Modified it manually to have also

"crossorigin":"use-credentials":and the error is gone in the browser and it's working corrently.
I just don't want to do it every time ABS updates 😄 (find the file and correct it 😉).
Here is how it looks like in more details on browser side:
Without this property when the browser sends a request for manifest it does not include

Cookieheader (as per specification):but the cookie have the information to authenticate a request that I'm logged in for Authelia. And when it's missing then the Authelia can not confirm that I'm logged in. And it will issue 302 redirect to login page triggering the error about "Manifest syntax error" as the manifest is expected by the browser to be a json file not HTML document with login page.
Here is how it looks like after adding

"crossorigin":"use-credentials"(Cookieheader is present):Hope it explains it better.
Thanks
@advplyr commented on GitHub (Feb 16, 2024):
Thanks, I understood that part. What I'm wondering about is the users that are not using traefik. How will they be impacted by this update?
See:
@prof729 commented on GitHub (Feb 16, 2024):
No idea how to understand that part in regard to manifest file. Maybe it's just general statement for all link elements that can potentially direct outside your domain/application?
On another page https://developer.mozilla.org/en-US/docs/Web/Manifest#deploying_a_manifest I've found only this statement:
There is also this old discussion https://github.com/w3c/manifest/issues/535 with this comment https://github.com/w3c/manifest/issues/535#issuecomment-435739223 that tries to explain it a bit more.
So for more streight forward setup of running ABS I think this will just add this header
Cookiethat will be send to ABS node and it will just be ignored there. As there is no logic to check if js/img/style etc files can be served to not logged in users, right?@dfunkt commented on GitHub (Jul 7, 2025):
This is still an issue when using something like Cloudflare Access for authentication.
As an example, Home Assistant includes
use-credentialsfor theirmanifest.json:https://github.com/home-assistant/frontend/blob/2e8203f666f6363e5d49bcf385eea1e31a46bd9b/src/html/_header.html.template#L2