github vavallee/bindery v1.40.2

4 hours ago

Per user libraries stay separate when adding books, settings stay with admins, and import and metadata fixes

This release closes the remaining ways a book or author add could touch another user's library with multi user tenancy turned on, and stops non admin accounts from reading server settings such as library paths and integration addresses. Adding a book now takes the file that matches its title best instead of the first one that roughly fits, a library folder that is a symlink is scanned, more metadata refreshes keep edits you save while they run, and a few import rough edges from v1.40.1 are smoothed out. No database migrations and no upgrade steps, except for third party clients that read settings while signed in as a regular user (see below).

Security

  • Per user libraries stay separate when adding books and authors (#3029). With multi user tenancy turned on, adding a book another user already has is now refused straight away, without touching their copy. Adding a book under an author two users share no longer merges it into a book only the other user owns, and the new book belongs to you instead of showing up in everyone's library. Adding an author by a name that is an alias of another user's author no longer finds or changes that author. Adding a recommendation no longer files the book under another user's author, and refreshing an author no longer moves a book into a different user's library. Admins and installs without tenancy behave as before.
  • Settings stay with admins (#2361). A non admin account reading the settings API now gets only the few settings its own screens use: whether Discover recommendations are on, the primary metadata provider, and the defaults for adding an author. Everything else, including library paths, integration addresses and usernames for Audiobookshelf, Grimmory and the Calibre plugin, the telemetry install id and the remaining operator settings, is admin only, and so is the Grimmory connection settings endpoint. Admins see Settings exactly as before, and scripts using the API key still read every setting except secrets. A third party client signed in as a regular user that read other settings should switch to the API key. In the disabled and local-only auth modes every admitted request already counts as admin, so nothing changes there.

Fixed

  • A new book no longer takes a file that belongs to another book (#2941). When Bindery adds a book, whether from adding an author, adding a single book, filling a series or taking a recommendation, it looks for a copy already in your library. It used to take the first file that roughly matched, so "Harry Potter" could claim "Harry Potter en het vervloekte kind.epub" and leave the real match without its file. Bindery now compares every matching file, prefers the exact title, leaves a file alone when it is named exactly as another of the author's books, and keeps the book Wanted and searchable when two files are too close to call. Thanks to foobarbigtime for the original report.
  • Library Scan finds books in a library folder that is a symlink (#3026). A library or audiobook folder configured as a link (say /books pointing at /mnt/storage/books, or a container volume path that is a link) was never entered, so a scan found nothing in it. The scan now follows the folder itself and records books under the path you configured. Adding an author now recognises the books you already own in such a folder too. Linked author folders inside the library are still not followed by a scan.
  • More metadata refreshes keep edits made while they run (#2926). Four more places fetched from a metadata provider and then wrote back the book or author as it was before the lookup, so a change you saved in the meantime (unmonitoring it, a narrator fix, a different quality or root folder profile) could be silently undone. Audiobookshelf imports now merge the upstream book or author record on top of your edit, or leave it for the next import if it keeps changing; fields the import takes from upstream, such as the description and cover, still follow the usual metadata conflict rules. Refresh Metadata on an author rereads each book it matched by title right before updating it. The scheduled author metadata refresh skips an author you edited during the lookup and picks it up on its next run.
  • Adopting a file left behind by a deleted book now works (#2937). Import, In your library refused such a file with "already belongs to a book in your library" although no book had it, and adding an author skipped binding it and searched instead. Both now take the file over, the way a download or manual import already did.
  • More credits that name nobody are ignored when reading an audiobook's author (#2942). Import, In your library treated tags such as "Various Artists.", "Unknown Author(s)", "Author Unknown", "Anon." or a publisher credit like "Brilliance Audio", "Recorded Books", "Tantor Audio" or "HarperAudio" as the author, so the row reported a conflict with its folder and offered to add that "author". These are now recognised however they are punctuated. Thanks to foobarbigtime for the report.
  • EPUBs tagged with the old language codes iw, in or ji are now read as Hebrew, Indonesian and Yiddish (#2998). They slipped past the import language check and relabelled the book to the raw code.
  • Search interval hint gave the wrong advice (#3027). It told you to reduce the wanted search interval when indexers rate limit you, which makes Bindery search more often. It now says to pick a longer interval. Translations that carried the old English text now show the corrected English until they are translated.
  • Series, Calendar and Push all to Calibre can now be translated (#3027). The Series page heading, buttons and card labels, the Calendar month and weekday names, and the Push all to Calibre button and progress window were always shown in English. Calendar dates now follow your chosen language, and book status badges on the Series page are now capitalised to match the rest of the app.
  • Consistent ellipses (#3027). Loading and busy labels use the same ellipsis character in English and in the German, Spanish, French, Dutch, Tagalog, Indonesian and Korean translations. Leftover English text in those translations now falls back to English properly instead.

Changed

  • Much faster test suite (#2983). Every database test used to run all hundred migrations on a fresh in memory database, which pushed the race detector run past its CI time limit. Tests now migrate once and copy the result, about sixteen times faster under the race detector. Test only, no runtime change. Thanks francisrath.
  • Broader test coverage (#3028, #3032, #3034, #3035, #3039). New tests for the database layer, the API handlers (including the per user and admin checks), the download clients, the scheduler, OIDC sign in, telemetry, covers, the Audiobookshelf and Calibre integrations, OPDS and the least covered web pages. Test only, no runtime change.
  • Updated source-map-js in the web build tooling (#3036) to clear GHSA-68fv-2mgg-jv7q, a denial of service bug in source map parsing. It is only used by the build tools, not shipped in the app.

Don't miss a new bindery release

NewReleases is sending notifications on new releases.