No description
Find a file
Deluan Quintão 652c27690b
feat(plugins): add HTTP host service (#5095)
* feat(httpclient): implement HttpClient service for outbound HTTP requests in plugins

Signed-off-by: Deluan <deluan@navidrome.org>

* feat(httpclient): enhance SSRF protection by validating host requests against private IPs

Signed-off-by: Deluan <deluan@navidrome.org>

* feat(httpclient): support DELETE requests with body in HttpClient service

Signed-off-by: Deluan <deluan@navidrome.org>

* feat(httpclient): refactor HTTP client initialization and enhance redirect handling

Signed-off-by: Deluan <deluan@navidrome.org>

* refactor(http): standardize naming conventions for HTTP types and methods

Signed-off-by: Deluan <deluan@navidrome.org>

* refactor example plugin to use host.HTTPSend for improved error management

Signed-off-by: Deluan <deluan@navidrome.org>

* fix(plugins): fix IPv6 SSRF bypass and wildcard host matching

Fix two bugs in the plugin HTTP/WebSocket host validation:

1. extractHostname now strips IPv6 brackets when no port is present
(e.g. "[::1]" → "::1"). Previously, net.SplitHostPort failed for
bracketed IPv6 without a port, leaving brackets intact. This caused
net.ParseIP to return nil, bypassing the private/loopback SSRF guard.

2. matchHostPattern now treats "*" as an allow-all pattern. Previously,
a bare "*" only matched via exact equality, so plugins declaring
requiredHosts: ["*"] (like webhook-rs) had all requests rejected.

---------

Signed-off-by: Deluan <deluan@navidrome.org>
2026-02-24 14:28:36 -05:00
.devcontainer feat(scanner): upgrade TagLib to 2.2, with MKA/Matroska support (#5071) 2026-02-21 16:52:48 -05:00
.github chore(deps): bump goreleaser/goreleaser-action in /.github/workflows (#5089) 2026-02-23 19:06:45 -05:00
adapters feat(scanner): upgrade TagLib to 2.2, with MKA/Matroska support (#5071) 2026-02-21 16:52:48 -05:00
cmd refactor: move playlist business logic from repositories to service layer (#5027) 2026-02-21 19:57:13 -05:00
conf feat(server): add ExtAuth logout URL configuration (#5074) 2026-02-23 20:28:38 -05:00
consts feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
contrib build: add packages for deb and rpm to release (#3202) 2024-10-26 13:31:45 -04:00
core refactor: move playlist business logic from repositories to service layer (#5027) 2026-02-21 19:57:13 -05:00
db feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
git feat(plugins): experimental support for plugins (#3998) 2025-06-22 20:45:38 -04:00
log refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
model feat(subsonic): sort search3 results by relevance (#5086) 2026-02-23 08:51:54 -05:00
persistence feat(subsonic): sort search3 results by relevance (#5086) 2026-02-23 08:51:54 -05:00
plugins feat(plugins): add HTTP host service (#5095) 2026-02-24 14:28:36 -05:00
release fix: linux service should restart when upgrading (#5001) 2026-02-09 17:11:45 -05:00
resources fix(ui): update Danish, Portuguese (BR) translations from POEditor (#5039) 2026-02-12 16:38:57 -05:00
scanner refactor: move playlist business logic from repositories to service layer (#5027) 2026-02-21 19:57:13 -05:00
scheduler refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
server feat(server): add ExtAuth logout URL configuration (#5074) 2026-02-23 20:28:38 -05:00
tests feat(subsonic): sort search3 results by relevance (#5086) 2026-02-23 08:51:54 -05:00
ui feat(server): add ExtAuth logout URL configuration (#5074) 2026-02-23 20:28:38 -05:00
utils refactor: run Go modernize (#5002) 2026-02-08 09:57:30 -05:00
.dockerignore fix: add music.old to .dockerignore and .gitignore 2026-02-06 07:40:05 -05:00
.git-blame-ignore-revs Move project to Navidrome GitHub organization 2021-02-06 21:47:19 -05:00
.gitignore fix: add music.old to .dockerignore and .gitignore 2026-02-06 07:40:05 -05:00
.golangci.yml feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
.nvmrc chore(deps): update all dependencies (#4618) 2025-10-25 17:05:16 -04:00
CODE_OF_CONDUCT.md Use Contributor Covenant v2.0 2020-07-21 14:40:21 -04:00
CONTRIBUTING.md docs: update commit message format in CONTRIBUTING.md 2026-02-20 11:00:34 -05:00
Dockerfile feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
go.mod chore(deps): update go-taglib to v0.0.0-20260221220301-2fab4903f48e 2026-02-21 17:04:59 -05:00
go.sum chore(deps): update go-taglib to v0.0.0-20260221220301-2fab4903f48e 2026-02-21 17:04:59 -05:00
LICENSE Change license to GPLv3 2020-01-22 14:48:38 -05:00
main.go feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
Makefile feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
Procfile.dev chore(deps): upgrade to Go 1.24.1 (#3851) 2025-03-17 21:08:10 -04:00
README.md feat: add Navidrome Guru on Gurubase.io (#3491) 2024-11-23 17:29:00 -05:00
reflex.conf feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00

Navidrome logo

Navidrome Music Server  Tweet

Last Release Build Downloads Docker Pulls Dev Chat Subreddit Contributor Covenant Gurubase

Navidrome is an open source web-based music collection server and streamer. It gives you freedom to listen to your music collection from any browser or mobile device. It's like your personal Spotify!

Note: The master branch may be in an unstable or even broken state during development. Please use releases instead of the master branch in order to get a stable set of binaries.

Check out our Live Demo!

Any feedback is welcome! If you need/want a new feature, find a bug or think of any way to improve Navidrome, please file a GitHub issue or join the discussion in our Subreddit. If you want to contribute to the project in any other way (ui/backend dev, translations, themes), please join the chat in our Discord server.

Installation

See instructions on the project's website

Cloud Hosting

PikaPods has partnered with us to offer you an officially supported, cloud-hosted solution. A share of the revenue helps fund the development of Navidrome at no additional cost for you.

PikaPods

Features

  • Handles very large music collections
  • Streams virtually any audio format available
  • Reads and uses all your beautifully curated metadata
  • Great support for compilations (Various Artists albums) and box sets (multi-disc albums)
  • Multi-user, each user has their own play counts, playlists, favourites, etc...
  • Very low resource usage
  • Multi-platform, runs on macOS, Linux and Windows. Docker images are also provided
  • Ready to use binaries for all major platforms, including Raspberry Pi
  • Automatically monitors your library for changes, importing new files and reloading new metadata
  • Themeable, modern and responsive Web interface based on Material UI
  • Compatible with all Subsonic/Madsonic/Airsonic clients
  • Transcoding on the fly. Can be set per user/player. Opus encoding is supported
  • Translated to various languages

Translations

Navidrome uses POEditor for translations, and we are always looking for more contributors

Documentation

All documentation can be found in the project's website: https://www.navidrome.org/docs. Here are some useful direct links:

Screenshots