Files
tpbproxy/routes/authtoken.js
wmantly fd5ef14999 Harden auth, add AI smart-search and post-download organization
Security & correctness hardening:
- Gate /__api/token/auth behind auth and self-scope every handler to the
  caller (was fully unauthenticated — account-takeover hole).
- Escape LDAP filter values (injection) and reject empty-password binds.
- Enforce per-torrent ownership so private torrents aren't exposed via IDOR.
- Assorted cleanup: fix 'use static' typos, drop dead Torrent.migrate + the
  getTorrentData noUpdate flag, Buffer.alloc, __dirname-relative reads,
  res.statusCode in the error handler, const-scope pubsub.

Login-gated proxy + anti-indexing:
- Block all proxying for logged-out users via an auth-token cookie the front
  end mirrors from its token; serve a local login page instead of hitting TPB.
- robots.txt disallow-all + X-Robots-Tag noindex.

Torrent category:
- Store a normalized category (TV/Movie/Music/Adult/App/Game/Other) mapped
  from the TPB category id; captured at add time (migration).

Smart Search (movies/TV):
- New /__api/search: TMDB title confirm -> scrape piratebay.party HTML ->
  Ollama ranks releases against quality prefs (x265/1080p/~1.5GB/subs,
  prefer uncut) returning a recommended pick, optional warned 4K, and other
  editions. Front-end Smart Search box + dialog feeding the existing add flow.

Post-download organization -> Emby (public Movie/TV only):
- Completion watcher files finished torrents: Ollama parses the release name,
  TMDB canonicalizes title/year, files main video (+subs) into the library
  with edition/quality-aware names (movies + TV SxxExx), stops seeding, and
  triggers an Emby library scan. Low-confidence matches are flagged, not
  mis-filed; correctable via "Fix match". Adds organizedAt/metadata columns.

Shared helpers: controller/tmdb.js, controller/ollama.js. Config blocks for
tmdb/ollama/search/emby/library/organize (secrets stay in gitignored secrets.js).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-01 14:19:13 -04:00

88 lines
1.9 KiB
JavaScript

'use strict';
const router = require('express').Router();
const {AuthToken} = require('>/models');
function ownToken(token, req){
if(!token || token.username !== req.user.username){
let error = new Error('AuthTokenNotFound');
error.name = 'AuthTokenNotFound';
error.message = 'Token not found';
error.status = 404;
throw error;
}
return token;
}
router.get('/', async function(req, res, next){
try{
return res.json(await AuthToken.findAll({where:{
username: req.user.username
}}));
}catch(error){
next(error);
}
});
router.post('/', async function(req, res, next){
try{
return res.json(await AuthToken.create({...req.body, username: req.user.username}));
}catch(error){
console.error(error)
next(error);
}
});
router.get('/user/:username', async function(req, res, next){
try{
if(req.params.username !== req.user.username){
let error = new Error('AuthTokenNotFound');
error.name = 'AuthTokenNotFound';
error.message = 'Token not found';
error.status = 404;
throw error;
}
return res.json(await AuthToken.findAll({where:{
username: req.params.username
}}));
}catch(error){
next(error);
}
});
router.get('/:token', async function(req, res, next){
try{
let token = ownToken(await AuthToken.findByPk(req.params.token), req);
token.dataValues.user = await token.getUser()
return res.json(token);
}catch(error){
next(error);
}
});
router.put('/:token', async function(req, res, next){
try{
let token = ownToken(await AuthToken.findByPk(req.params.token), req);
await token.update(req.body);
return res.json(token);
}catch(error){
next(error);
}
});
router.delete('/:token', async function(req, res, next){
try{
let token = ownToken(await AuthToken.findByPk(req.params.token), req);
await token.destroy();
return res.json({'deleted': true});
}catch(error){
next(error);
}
});
module.exports = router;