94 Commits

Author SHA1 Message Date
Claudio Ortolina 8391cf275a ML-180: remove backup download feature
Delete ArchiveController, its routes, the maintenance UI backup
button, and the test file. Management scripts and Litestream
supersede this functionality.
2026-05-15 07:13:33 +01:00
Claudio Ortolina ba62d54cc5 ML-177: implementation 2026-05-10 20:39:18 +01:00
Claudio Ortolina cccd28a9f9 ML-165: implementation 2026-05-05 13:43:18 +01:00
Claudio Ortolina 51bd24d5b4 ML-162: enable /api/v1/errors endpoint 2026-05-04 13:14:40 +01:00
Claudio Ortolina c489fde1cc ML-152: add /api/v1/ version prefix to all API routes 2026-04-30 11:57:43 +01:00
Claudio Ortolina 90db113845 ML-5: document Last.fm OAuth callback trust boundary
Closes GitHub issue #178.
2026-04-24 08:05:07 +01:00
Claudio Ortolina 0dcd6eab83 Replace /scrobble/:release_id with nested route 2026-04-23 14:39:26 +01:00
Claudio Ortolina d8041dc0dd Add /scrobble/:rg_id release-group page 2026-04-23 14:35:58 +01:00
Claudio Ortolina 4194fb8b6d Update dependencies
oban_web 2.12.2 => 2.12.3
2026-04-15 13:50:52 +01:00
Claudio Ortolina 1cf9446063 Update oban_web to 2.12
- Had to disable nonces for style-src directives (seems like they're not
  propagated everywhere in oban_web's templates)
- Doesn't seem to support crons or workflows when backed by SQLite
2026-03-26 10:09:22 +00:00
Claudio Ortolina 1ee4d3465a Move /dev/maintenance to /maintenance 2026-03-18 07:44:22 +00:00
Claudio Ortolina 69ff926aba Allow WASM evaluation on prod 2026-03-14 18:02:27 +00:00
Claudio Ortolina 2dd6f10a7f Fix CSP error for barcode detection 2026-03-14 17:38:04 +00:00
Claudio Ortolina 854a6e1816 Allow worker blob URLs in CSP directives
canvas-confetti creates web workers from blob URLs,
which requires an explicit worker-src directive.
2026-03-13 15:01:28 +00:00
Claudio Ortolina 145c5c288c Allow loading img blobs in csp directives 2026-03-13 14:47:35 +00:00
Claudio Ortolina 3ddb287187 Fix csp directives for online store template logos 2026-03-09 18:30:29 +00:00
Claudio Ortolina f9845e8b7c Dry up CSP policies 2026-03-08 19:56:05 +00:00
Claudio Ortolina 77c45bddc6 Update CSP policies for musicbrainz covers + fallbacks 2026-03-08 19:54:00 +00:00
Claudio Ortolina 27519fca29 Fix CSP for images from brave 2026-03-08 19:47:43 +00:00
Claudio Ortolina 59616e58b5 Allow LiveDebugger origins in dev 2026-03-08 19:44:41 +00:00
Claudio Ortolina 1bfe501b3d Split strings for readability 2026-03-07 23:44:00 +00:00
Claudio Ortolina 05354b9f78 Explain the CSP policies 2026-03-07 23:40:40 +00:00
Claudio Ortolina 46da8eea38 EXP: fix CSP issues for /dev routes 2026-03-07 21:07:24 +00:00
Claudio Ortolina 41480316c2 Fix CSP settings
⏺ Here's a breakdown of each directive:

  ┌─────────────────┬────────────────────────────────────────────────┬─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
  │    Directive    │                     Value                      │                                                         Purpose                                                         │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ default-src     │ 'self'                                         │ Fallback for any resource type not explicitly listed — only allow from the app's own origin                             │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ script-src      │ 'self'                                         │ JavaScript can only be loaded from the app's origin (no external scripts, no inline)                                    │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ style-src       │ 'self' 'unsafe-inline' https://rsms.me         │ Stylesheets from the app's origin, inline styles (needed by LiveView), and the https://rsms.me/inter/ hosted on rsms.me │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ font-src        │ 'self' https://rsms.me                         │ Font files from the app's origin and rsms.me (Inter font)                                                               │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ img-src         │ 'self' data: https://lastfm.freetls.fastly.net │ Images from the app's origin, data: URIs (inline base64 images), and Last.fm's CDN for album/artist artwork             │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ connect-src     │ 'self'                                         │ XHR/fetch/WebSocket connections only to the app's origin (covers LiveView's WebSocket)                                  │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ frame-ancestors │ 'self'                                         │ The app can only be embedded in iframes by itself (clickjacking protection)                                             │
  ├─────────────────┼────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
  │ base-uri        │ 'self'                                         │ Restricts <base> tag to the app's origin (prevents base tag injection attacks)                                          │
  └─────────────────┴────────────────────────────────────────────────┴─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘

  Notable things not allowed by this policy:
  - No inline <script> tags or eval()
  - No external JavaScript from CDNs
  - No embedding in third-party iframes
  - No connections to external APIs from the browser (all external API calls go through the server)
2026-03-07 19:13:48 +00:00
Claudio Ortolina 3812b6c402 Add Content-Security-Policy header
Closes #100
2026-03-07 18:53:52 +00:00
Claudio Ortolina 23c478fe4c Mount telemetry repo in live dashboard stats 2026-03-05 13:52:55 +00:00
Claudio Ortolina 73a943bc63 Server records on this day email assets from a public endpoint 2026-03-05 10:50:35 +00:00
Claudio Ortolina 478832249b Send record of the day email 2026-03-05 10:37:04 +00:00
Claudio Ortolina 1b934537ea Remove Sentry and Honeybadger 2026-02-26 21:52:57 +00:00
Claudio Ortolina 18ac442b2c Install ErrorTracker 2026-02-26 21:31:37 +00:00
Claudio Ortolina 77c5453fa8 Report all errors to Honeybadger 2026-02-26 20:47:16 +00:00
Claudio Ortolina 68956978e1 Add show route for record sets 2026-02-07 16:09:26 +00:00
Claudio Ortolina 419b093101 First pass at record sets 2026-02-05 11:46:52 +00:00
Claudio Ortolina 6f4fe163df Handle toast messages from inside Release component 2026-01-27 16:16:28 +00:00
Claudio Ortolina 11acec56b2 Remove lotus
Unstable - and it messes with the repo connection, creating other
errors.
2025-11-03 17:29:37 +00:00
Claudio Ortolina 299dee4b85 Add maintenance page
Some actions are missing
2025-11-02 21:02:34 +00:00
Claudio Ortolina f02564fa30 Add /api/collection/on_this_day endpoint 2025-10-24 20:06:23 +01:00
Claudio Ortolina a30e1b32d7 Mount data analysis via Lotus packages 2025-10-22 16:33:07 +01:00
Claudio Ortolina 57dfd3d33d Remove ErrorTracker
Doesn't work with recent LiveView releases, and seems to be maintained
very slowly despite incoming PRs to fix the issues.
2025-10-03 10:15:23 +03:00
Claudio Ortolina 67341f3ceb Revert "Add Orion for production perf measurement"
This reverts commit ec40f357d5.
2025-09-30 20:11:19 +03:00
Claudio Ortolina ec40f357d5 Add Orion for production perf measurement 2025-09-30 09:44:05 +03:00
Claudio Ortolina e9e4752bce EXP - scrobble anything 2025-09-24 08:55:42 +03:00
Claudio Ortolina 455c3a8b53 Serve artist images via assets 2025-09-18 21:26:20 +03:00
Claudio Ortolina e158345674 Change /covers to /assets 2025-09-18 21:26:16 +03:00
Claudio Ortolina b0f4e18ef7 Fix API collection record cover URLs 2025-09-17 11:24:14 +03:00
Claudio Ortolina 0996b78c7b Use Transforms to serve covers at the right size 2025-09-17 10:26:38 +03:00
Claudio Ortolina dae334b1b7 Scrobbled tracks CRUD
- Failing tests
- Warnings
2025-09-16 12:45:36 +03:00
Claudio Ortolina 21783f5dbf Resolve timezone from user browser 2025-09-11 22:14:15 +03:00
Claudio Ortolina bd12454884 Serve covers from assets 2025-09-01 14:44:17 +03:00
Claudio Ortolina 65de5fc833 Add first version of online stores for wishlisted records (claude)
See docs/plans/online_stores.md
2025-07-15 09:42:59 +01:00