Commit Graph
12 Commits
Author SHA1 Message Date
shamoonandBen Phelps b3cf985d4a Merge pull request from GHSA-24m5-7vjx-9x37
* Restrict emby endpoints and proxy segments

* Dont allow path traversal in segments

* Restrict qbittorrent proxy endpoints

* Restrict npm proxy endpoints

* Restrict flood proxy endpoints

* Restrict tdarr proxy endpoints

* Restrict xteve proxy endpoints

* Restrict transmission proxy endpoints

* disallow non-mapped endpoints

this change drops all requests that have un-mapped endpoint queries

allowedEndpoints is added as a method to pass proxy requests via a regex on the endpoint

most widgets with custom proxies use either no endpoint, or a static one

Co-Authored-By: Ben Phelps <ben@phelps.io>
2024-06-02 21:13:29 -07:00
shamoonandBen Phelps 19c25713c4 Run pre-commit hooks over existing codebase
Co-Authored-By: Ben Phelps <ben@phelps.io>
2023-10-18 09:49:33 -07:00
Georges-Antoine Assi bd1c2b1881 Add setting to hide widgets on failure 2023-04-30 19:09:37 -04:00
shamoon f2b3a12569 Fix nzbget download rate units 2023-01-28 21:17:39 -08:00
Jason Fischer 7266390491 Add Deluge widget
- Create semi-generic jsonrpc proxy handler
- Refactor NZBGet to use jsonrpc proxy handler

closes #190
2022-11-23 11:51:53 -08:00
Michael Shamoon 8a783ba9f6 Simplify error catching 2022-11-18 15:24:07 -08:00
Michael Shamoon 21017e4716 Add detailed Error component for service widgets 2022-11-18 15:24:07 -08:00
Jason Fischer 9b7d6b196f Allow widget field visibility to be configurable 2022-09-29 21:15:25 -07:00
Ben Phelps 0a58f259ff wrapped proxy calls via useWidgetAPI 2022-09-27 22:59:14 +03:00
Ben Phelps 4386999c38 further restructuring 2022-09-26 15:25:10 +03:00
Ben Phelps e1a3a82f75 utils cleanup, initial static generation 2022-09-26 12:04:37 +03:00
Ben Phelps 47bc073fb4 widget refactoring and cleanup 2022-09-26 02:23:02 +03:00