fixes #789 - Security Issue: API allows access to any folder of the PC running MediaBrowser
This commit is contained in:
@@ -1386,8 +1386,6 @@ namespace MediaBrowser.Api.Playback
|
||||
ParseParams(request);
|
||||
}
|
||||
|
||||
var user = AuthorizationRequestFilterAttribute.GetCurrentUser(Request, UserManager);
|
||||
|
||||
var url = Request.PathInfo;
|
||||
|
||||
if (string.IsNullOrEmpty(request.AudioCodec))
|
||||
@@ -1409,11 +1407,6 @@ namespace MediaBrowser.Api.Playback
|
||||
|
||||
var item = LibraryManager.GetItemById(request.Id);
|
||||
|
||||
if (user != null && item.GetPlayAccess(user) != PlayAccess.Full)
|
||||
{
|
||||
throw new ArgumentException(string.Format("{0} is not allowed to play media.", user.Name));
|
||||
}
|
||||
|
||||
List<MediaStream> mediaStreams = null;
|
||||
|
||||
state.ItemType = item.GetType().Name;
|
||||
|
||||
Reference in New Issue
Block a user