mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#1709
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @sevenlayercookie on GitHub (Feb 4, 2024).
Describe the issue
It is possible to submit any number of failed login requests without limit, and without rate limit. This makes Audiobookshelf susceptible to brute force login methods.
as @nichwall noted, this appears to have broken in v2.6.0 with OIDC implementation.
related issue: #2533 no auth log entries.
Steps to reproduce the issue
Audiobookshelf version
V2.7.2
How are you running audiobookshelf?
Docker
@Sapd commented on GitHub (Feb 4, 2024):
Probably was removed during the Auth/passport rerwite.
I think instead of implementing that directly, better would be a middleware:
https://www.npmjs.com/package/express-slow-down
Advantage is, it could be also used against other public API endpoints.
Also one should be able to turn it off. Some people like to user other means. Also some don't forward the Client IPs from their reverse proxies (which is at some architectures even by design).If the default suggestion is used it probably it is not needed to be configurable:Because this way it does not block completely but adds a delay of 250ms. Should be enough to make every brute force attempt too slow, but still work with other configurations without forwarded IPs.
@bytebone commented on GitHub (Feb 6, 2024):
No need to solve problems the complicated way. Just fix the logging component so that IPs of unsuccessful login attempts are in logfiles, and let users figure out how to handle this with fail2ban / crowdsec / whatever else.
I would much rather ban IPs that are consistently trying to bruteforce usernames / passwords, than allowing them to slowly but surely chip away at the login form.
@plague-doctor commented on GitHub (Nov 14, 2024):
To enhance our security posture against brute-force attacks, I've integrated AudiobookShelf with crowdsec . This addition specifically addresses the challenge of protecting against unauthorised access attempts through repeated login failures.
The AudiobookShelf collection now actively monitors and mitigates potential threats, ensuring a more robust defence against malicious actors attempting to gain unauthorised access to our systems through brute-force methods.
@Guruleenyc commented on GitHub (Apr 10, 2025):
Has anyone got fail2ban jail and filter working for audiobookshelf yet?
@sevenlayercookie commented on GitHub (Apr 10, 2025):
I ended going for crowdsec because it's more sophisticated. It was complicated to set up because I use Cloudflare tunnels so Linux firewall doesn't apply. So I ended up setting crowdsec to parse my Caddy logs for Audiobookshelf subdomain for suspicious traffic and then crowdsec tells
Caddy to block further traffic from that IP address.
I haven't used fail2ban, but I imagine that aspect of setup is similar.
@CTalvio commented on GitHub (Jul 2, 2025):
@Guruleenyc
Setting up fail2ban to watch any arbitrary log file is not difficult. You can find fairly simple guides for how to set up custom jails. If you have access to the log, and a regex string that matches with log entries for failed logins, you're set. Here's the filter I wrote for my system just now:
If you need to create one in the future, you can do that by doing a few incorrect logins yourself, then finding them in the log. Copy that section of the log into a regex tester like this one and tweak your way to a regex string that will match with a failed login line. Replace the the section of the line with the ip with
<HOST>and you have a failregex for fail2ban.@plague-doctor commented on GitHub (Jul 16, 2025):
@advplyr
The latest version introduced a new logging mechanism, which also altered how authentication-related issues are logged. Instead of the original "[Auth] ..." prefix, it now uses "[LocalAuth] ..." in the log files.
Could we please revert to using "[Auth]" again? Many of us rely on tools like fail2ban or Crowdsec, which depend on specific log patterns to detect and block brute-force attacks. The current change is causing these systems to fail silently, as they can no longer recognise the log entries.
This is a minor adjustment that would restore compatibility with existing security mechanisms. Without reverting, all currently configured tools would effectively stop working, leaving our systems vulnerable.
@DerLeole commented on GitHub (Jan 26, 2026):
Has anything been done regarding @plague-doctor 's last message?
As far as I can see, the lastest version of the audiobookshelf parser on crowdsec still uses the [Auth] notation, while the lastest version of audiobookshelf still uses [LocalAuth]?
Is that change permanent @advplyr ? Then an update to the crowdsec parser might be in order?