mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
[ISSUE]: 404 errors for author photos triggers crowdsec http-probing ban for new devices #2832
Closed
opened 2026-04-25 00:11:04 +02:00 by adam
·
3 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#2832
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @iconoclasthero on GitHub (Jun 7, 2025).
What happened?
One of my users got a new phone and ended up getting her IP banned by my fairly stock CrowdSec config watching NGINX logs. This was discussed on Discord: https://discord.com/channels/942908292873723984/942914154254176257/1378468432143585330
From the logs and the CrowdSec Discord, what triggered this was the 404 errors resulting from the paucity of available author images that were generated upon first attempting to populate the client's app.
What did you expect to happen?
This totally caught me by surprise...I didn't expect my user to get banned.
Steps to reproduce the issue
/var/logs/nginx/abs-error.log; /var/logs/nginx/abs-access.log)sudo cscli decisions listAudiobookshelf version
v.2.23.0
How are you running audiobookshelf?
Docker
What OS is your Audiobookshelf server hosted from?
Linux
If the issue is being seen in the UI, what browsers are you seeing the problem on?
None
Logs
Additional Notes
From the CrowdSec Discord, this also happens with NextCloud:
https://discord.com/channels/921520481163673640/922593826986672178/1378512972686557264
and the suggestion was made that the number of 404 errors returned in such scenarios could be fixed to prevent triggering this http-probing ban: https://discord.com/channels/921520481163673640/922593826986672178/1378785541100802228
However, I wanted to post this here so that if someone else is having problems they can find the solution that worked for me suggested here: https://discord.com/channels/921520481163673640/922593826986672178/1380105164853088346
of
saved as
PATH_TO_CROWDSEC_CONFIG/parsers/s02-enrich/audiobookshelf-whitelist.yaml@Vito0912 commented on GitHub (Jun 7, 2025):
That is not a bug or issue with ABS.
If there is no image for an author, a 404 error will occur, which is the correct response for a missing file.
The website only tries to load the image if the item has a cover path (afaik -> https://github.com/advplyr/audiobookshelf/blob/4a3eb7727beab6f9bd859a351dfcf0dd8342212b/client/components/covers/AuthorImage.vue#L59).
Maybe at that time there was a problem and the files were no longer available to your server (e.g. wrong mounts, deleted manually etc. etc.).
You can check this by looking at the network activity in your browser and seeing if there are any 404 errors. But even if, 404 are totally normal "errors" to return in this case and this is a result in the strictness you setup crowdsec
Edit: Also the app checks for it https://github.com/advplyr/audiobookshelf-app/blob/d26403c8004fcc06509d87ec8ad6b31ac7fb7322/components/covers/AuthorImage.vue#L57
@nichwall commented on GitHub (Jun 8, 2025):
From further discussion in Discord, this was caused by a number of author images not existing in the
/metadata/authorsdirectory (where author images are stored) but paths to these missing files existed in the ABS database.A cached version of some images were available under
/metadata/cache, which made it appear that some images existed due to the same size already being generated. The 404 is correct due to the original image files not existing.@iconoclasthero commented on GitHub (Jun 16, 2025):
Yes, I was able to fix the author image issues and that should resolve it and I wasn't able to unlabel it a bug after I hit submit the first time. Like I said, I was adding it more for future reference than anything.