Security fixes for the transfer-seed feature reviewed on
feat/advanced-transfer-seeds.
SSRF via redirect (torrent.go):
- Source validation only pinned the first hop while http.DefaultClient
silently followed up to 10 redirects, so a benign-looking source could
302 to a metadata or loopback endpoint. Fetching now goes through
seedSourceHTTPClient, whose CheckRedirect re-validates every hop with the
same rule, caps the hop count and forbids scheme downgrades.
- Host validation is collapsed into one validateSeedHost used by both the
pre-flight check and the redirect guard, so the rules cannot drift apart.
- Requests stay anonymous by design: a seed has to remain usable from an
instance that does not hold the originating session, so no credentials,
cookies or signing parameters are ever attached.
Seed content fetching (torrent.go):
- Propagate the request context instead of context.Background(), so
cancellation actually stops the download.
- Stream the body through an io.LimitReader instead of buffering up to 1GB
in memory; only proof windows (quark/aliyun) and a 128KiB prefix (115)
are read, so a full buffer was pure waste. Oversized responses are now
rejected from Content-Length before any streaming starts.
Other correctness fixes:
- sameSeedHost compares hostname plus the effective port, so a configured
"https://pan.example.com" and an embedded "...:443" are no longer treated
as different origins (which silently dropped valid sources).
- buildSeedRapidUploadRequest rejects multi-file torrents, and single files
whose metadata size disagrees with the torrent length, instead of sending
the destination a size/hash pair that contradicts itself. Both call sites
now handle the nil result instead of dereferencing it.
- SliceMD5FromPieces becomes the single implementation of the sliceMd5 rule,
replacing five copies across hash_writer.go, torrent.go, generate.go,
189/torrent.go and 189pc/torrent.go. Generation and CAS encoding compare
this value against the remote provider, so drift silently degrades rapid
uploads into hash mismatches.
- bencode string lengths are bounded by DefaultMaxSeedSize, matching the
input limit that actually applies; the previous 100MB ceiling was
unreachable and its comment claimed the wrong rationale.
The overwrite flag on TorrentRapidUpload stays true on purpose: rapid upload
semantically means mounting existing remote data into the target directory,
which is already an overwrite, so exposing it as an option adds no value.
Tests:
- pkg/torrent/seed_security_test.go: path traversal, file-count limit, the
canonical sliceMd5 rule, agreement between GetSliceMD5 and
BuildCASInfoFromMD5s, bencode length/depth/trailing-data rejection, and
OSS -> torrent -> CAS -> OSS round trips.
- server/handles/torrent_seed_test.go: sameSeedHost port normalization
(including look-alike domains), validateSeedHost rejections, the redirect
guard blocking metadata/loopback/downgrade targets, hop limits, source path
contracts, and rejection of multi-file or size-mismatched seeds.
go build ./... passes; go test ./pkg/torrent/... and
go test ./server/handles/... pass.
The previous commit (624fdd24) introduced the authoritative
driver.SeedRapidUploader interface, but left every driver's seed_rapid.go
on the older, incompatible API, so the branch did not compile at all.
Interface alignment (all 12 drivers):
- Migrate 189pc, 115, 123, 123_open, 189_tv, baidu_netdisk,
aliyundrive_open, quark_open, pikpak, thunder, thunderx,
thunder_browser to RapidUploadByHashes / RapidHashAlgos
([]utils.HashType, no longer []*utils.HashType) / RapidHashNeedsPieces
- Add shared driver.SeedHashStream as a complete model.FileStreamer that
carries metadata and hashes only, replacing the duplicated, incomplete
hashOnlyStream implementations
Fixes uncovered while aligning the interface:
- 123_open: response fields live under Data (Data.Reuse / Data.FileID)
- quark_open: pre.Data.FID -> pre.Data.Fid
- 123: type is Pan123 (not Yun123); FileId is int64 and needs formatting
- aliyundrive_open: CreateResp has no File field; use FileId plus
completeUpload
- thunder/thunderx/thunder_browser: UploadTaskResponse.File is a Files
value type, return &resp.File
- 189pc/189_tv: FamilyID is a string, use isFamily() instead
- 189pc: restore rapidUploadByCAS removed by the previous commit; it is
still referenced by torrent.go. Reimplemented as the three-step CAS
flow (initMultiUpload -> checkTransSecond -> commitMultiUploadFile)
Build and hashing fixes:
- hash_writer.go: HashType exposes NewFunc; GCID.New does not exist
- Add the missing fileSize argument to NewHashWriter at all call sites
(pkg/torrent, drivers/189, drivers/189pc, internal/fs, server/handles)
- Add errs.ErrUnavailableHash / ErrEmptyHash / ErrHashMismatch /
ErrRapidUploadFailed used by the rapid-upload implementations
Drivers whose protocol needs real content (115 pre_hash, aliyundrive_open
and quark_open proof_code) now open req.Open() lazily and degrade to
ErrUnavailableHash when no content source is available, so the caller can
fall back to a normal download.
Note: go vet warnings for non-constant format strings in 189pc/utils.go
are pre-existing and intentionally left untouched.
- add an opt-in Local driver setting for PDF thumbnails
- render PDF first pages with macOS Quick Look
- preserve unsupported-platform behavior and cover the renderer with tests
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Co-authored-by: ILoveScratch <ilovescratch@foxmail.com>
* fix(drivers/139): improve mail login credential renewal
* fix(drivers/139): guard mail login client initialization
Fall back to base.NewRestyClient() when base.RestyClient has not been initialized, while preserving cloned global-client behavior and the login/SMS retry and redirect policies.
- Decode JSON time strings before normalizing Unicode spaces in both 189 drivers
- Exercise escaped spaces and existing date formats through JSON unmarshalling
- Cover invalid JSON input and XML time parsing
Signed-off-by: jyxjjj <16695261+jyxjjj@users.noreply.github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
multipartUploadToOSS passed the UpdateProgress callback into
stream.NewStreamSectionReader, which ignores the up argument, so the
callback was never invoked while uploading parts. As a result,
cross-storage copy tasks targeting GuangYaPan stayed at 0% and showed no
progress bar or speed in the task list.
Fix by tracking the uploaded byte count and invoking up after every
part is uploaded, keeping consistent with other drivers' upload flow.
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
The 115 and pikpak multipart uploaders checked for cancellation with a
`case <-ctx.Done()` inside a select, and a break there only leaves the
select, not the enclosing `for retry := 0; retry < 3; retry++` loop.
Cancelling an upload therefore ran all three attempts for every
remaining chunk, each allocating a chunk-sized buffer and reading it
off disk before firing a request that could not succeed, and reported
a transport error instead of the cancellation.
Move the check ahead of the select and use utils.IsCanceled, matching
the pattern the other drivers already use. Assigning ctx.Err() to err
is load-bearing: without it a cancelled chunk takes the success branch,
counts toward progress, and appends a zero-value UploadPart.
Found with staticcheck (SA4011).
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
* feat(strm): add local save permission mode
- add private and shared permission modes for local STRM files
- repair shared-mode directory and file permissions during generation
- add permission handling tests
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(strm): respect deployment umask for local directories
- remove application-level permission modes and chmod operations
- create local STRM directories with umask-controlled permissions
- preserve existing permissions and test the behavior
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
---------
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* feat(ilanzou): modernize console API session and copy
Use an isolated cookie-backed API session and preserve raw appToken syntax required by current iLanzou endpoints.
Resolve CDN download responses more robustly, align upload metadata with the console protocol, and delegate copies to OpenList background tasks instead of blocking requests.
* fix(ilanzou): escape appToken query values
Escape opaque appToken values while preserving the literal colon required by iLanzou endpoints. Ignore CDN HEAD response lengths unless the response status is successful.
* fix(ilanzou): address driver review feedback
Use the ilanzou package name consistently, document upload result polling, and bound CDN size probes. Keep the appToken and CDN challenge handling covered by focused tests and comments.
* fix(ilanzou): use context timeout for HEAD probe
* feat(strm): add file size filtering for STRM generation
- add ParseSize helper function in pkg/utils to parse human-readable byte sizes
- add minFileSize setting field to STRM driver Addition struct
- filter out files below minFileSize threshold during STRM generation
* refactor(strm): use MB as default unit for minFileSize instead of ParseSize
Replace string-based ParseSize auto-conversion with a simple int64 number
field defaulting to MB, consistent with other drivers (Google Drive,
Teldrive). Remove the now-unused ParseSize function and its tests.
The Login endpoint may return an acw_sc__v2 validation page when accessed,
which previously caused login failures. This change adds the same retry
logic and cookie handling already used in request() to automatically solve
the challenge, ensuring login success even when the anti-bot mechanism is
triggered.
* fix(drivers/139): update path handling for family
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* perf(drivers/139): add retry go for family upload
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* feat(drivers/139): add FamilyCloudHost and GroupCloudHost handling
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* perf(drivers/139): add retry go for personalnew upload
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): use new batchpartinfos for remaining parts
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(driver/139): do not use path in id
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(driver/139): refactor RootPath handling
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(driver/139): remove root path stripping in Init method
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(drivers/139): reduce upload retry attempts to 3
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): add rate limiting for MetaPersonalNew upload
- Wrap stream with LimitedUploadStream before creating StreamSectionReader
- Aligns with the same pattern used in the MetaPersonal/MetaGroup/MetaFamily path
Co-authored-by: GitHub Copilot <copilot@github.com>
* fix(drivers/139): fix section reader leak and seek check in retry block
- Check rd.Seek() return value and free the section reader on error
- Call ss.FreeSectionReader(rd) on all error paths within retry.Do closure
- Prevents buffer.Block leak when retrying failed upload chunks
Co-authored-by: GitHub Copilot <copilot@github.com>
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): move GetSectionReader outside retry loop
- Move ss.GetSectionReader() before retry.Do() so the sequential
stream section reader is only called once per chunk
- Remove redundant ss.FreeSectionReader() calls from inside the
retry closure since the reader is now owned by the outer scope
- Fixes 'stream not cached' errors when retrying failed chunk
uploads during cross-storage WebDAV COPY operations
Co-authored-by: GitHub Copilot <copilot@github.com>
* feat(drivers/139): add UseOldStreamUpload option
- Add UseOldStreamUpload option
- Implement newRequest, newPost
- Support rapid upload for PersonalNew and Group/Family
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): add more param for group/family put
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): correct group params for new put
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): update personalPost to use getPersonalCloudHost
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(drivers/139): correct typo
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): pass full partInfos slice for batched upload
- Pass the global partInfos slice instead of the batch subset to
uploadPersonalParts, so that PartNumber-1 indexing does not go
out of bounds when a file has more than 100 parts.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(drivers/139): avoid double-counting progress on upload retries
- Save p.Done before each part and reset it inside the retry function
so that bytes from failed attempts are not counted toward progress.
- Each part is counted exactly once, on the successful attempt.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(drivers/139): gate route-host checks by cloud type
- Only validate GroupCloudHost and FamilyCloudHost for MetaGroup
and MetaFamily storage types, so that personal-only accounts do
not fail initialization when the route policy omits group/family.
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
* fix(drivers/139): add ProviderRoot back for groupgetfiles
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): set path to 0 when group old upload
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(drivers/139): improve error handling for family root path retrieval
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* refactor(drivers/139): update condition checks for CloudHost initialization
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: GitHub Copilot <copilot@github.com>
Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Recover temporarily missing or incomplete 115 Open path metadata from parent
and ancestor directory listings. Use 115-sdk-go v0.2.6 to normalize missing
object errors, while preserving valid zero-byte files and ensuring recursive
parent resolution progresses correctly.
Co-authored-by: Claude <noreply@anthropic.com>
* refactor(github_releases): remove internal caching, use global cache instead
- Remove Release/Releases/OtherFile cache fields from MountPoint struct
- Convert instance methods to pure functions (releaseToFiles, releasesToVersionDirs, etc.)
- Make List() fetch fresh data from GitHub API on every call
- Add githubGet helper to centralize GitHub API requests
- Remove unused GetRequest method and IsAncestorDir function
Co-authored-by: GitHub Copilot <copilot@github.com>
* feat(github_releases): add pagination and max page limit for all versions
- Add PerPage config to control releases per page (default 30, max 100)
- Add MaxPage config to limit max pages fetched (0 = unlimited)
- Rewrite getAllReleases to support automatic pagination
Co-authored-by: GitHub Copilot <copilot@github.com>
* chore(github_releases): move utils from driver.go to util.go
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(github_releases): revert changes to GetRequest
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* chore(github_releases): use more common format for github proxy url
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(github_releases): show_readme in empty releases case
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
* fix(github_releases): preserve README and LICENSE name variants
Co-authored-by: Copilot <copilot@github.com>
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
---------
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: GitHub Copilot <copilot@github.com>
* feat(driver): add Cloudflare Image Bed support
* fix: restore accidentally deleted file and name
* refactor: rename driver to cloudflare_imgbed and fix module structure
- Rename driver identifier and directory to 'cloudflare_imgbed' for consistency.
- Remove invalid 'replace' directive in go.mod.
- Restore accidentally modified/deleted files in public/dist.
- Update driver registration in drivers/all.go.
Co-authored-by: Copilot <copilot@github.com>
* fix: use base.NewRestyClient() and use e.g
Co-authored-by: Copilot <copilot@github.com>
* fix:go fmt
* feat(driver/cloudflare-imgbed): enhance cloudflare_imgbed API integration with improved error handling and pagination
* refactor
* feat(cloudflare_imgbed): implement upload functionality and optimize performance
- Added support for standard multipart form upload with zero-copy streaming.
- Implemented HuggingFace LFS direct upload for large files (>20MB).
- Integrated with OpenList global rate limiter and progress tracking.
- Optimized memory usage using io.MultiReader for request body construction.
- Added configurable upload threads for chunked HF uploads.
- Support auto mkdir dir when in upload
* refactor: simplify path handling logic
* refactor(cloudflare_imgbed): streamline API endpoint constants and improve initialization logic
* refactor(cloudflare_imgbed): clean up upload logic and remove unused functions
* docs: update help descriptions to English in cloudflare_imgbed
* feat(cloudflare_imgbed): add virtual directory support
* refactor(weak_cache): iImprove weak pointer cleanup handling
Store a cleanup handle alongside weak pointers and stop previous cleanups when overwriting entries to avoid stale removals and leaked cleanup handlers.
Ensure Delete signals success and stops associated cleanup. Add Clear to stop all active cleanups. Use entry identity in the cleanup callback to avoid removing newly inserted values.
* fix bug
* Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
* Adds uploadFolder param and streams base64 sample
Adds an uploadFolder query parameter to forward the destination path to the backend. Replaces the fixed-size sample read with a streaming base64 encoder to avoid truncation and reduce allocations
Co-authored-by: Copilot <copilot@github.com>
* refactor: add context parameter to doRequest and related calls
* fix: update List method to check args.Refresh before virtual directory mask
* refactor: optimize List method and improve error handling in doRequest
* feat: add public URL support and multi-channel chunked upload
- Support multi-channel chunk size configurations (e.g., Telegram, CFR2, S3, Discord).
- Fix 401 unauthorized error when merging chunks in HuggingFace channel.
---------
Signed-off-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: Copilot <copilot@github.com>
Co-authored-by: j2rong4cn <j2rong@qq.com>
Co-authored-by: j2rong4cn <36783515+j2rong4cn@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Pikachu Ren <40362270+PIKACHUIM@users.noreply.github.com>
Rename function passed RenameResp by value instead of pointer, causing
the API response to be discarded and producing a zero-value file entry
with empty name, zero size, and zero timestamps after rename.