Conversation
Follow-up to #1390. - The origin came from each result's infoUrl, matched by a regex that did not check the host, and the mam_id cookie had no domain. Any Prowlarr indexer returning a URL like https://evil.example?myanonamouse.net/t/1 sent the session ID to evil.example. Requests now always go to https://www.myanonamouse.net (Prowlarr's only MAM URL), with the cookie as a header and redirects off. Only results from Prowlarr's MyAnonamouse indexer are looked up, and their URLs must be on myanonamouse.net. - The lookup searched every category and read one page, so for common titles most of Prowlarr's results were missed (a "Dune" audiobook search: 56 audiobooks on the first 100 of 328 matches). It now reruns Prowlarr's exact search: the same query clean-up, the MAM main categories behind the Torznab categories searched (13/15/16 for audiobooks, 14 for e-books, all once expanded), and the MAM indexer's own search type, search-in options and languages. Further pages are read while IDs are missing, page 1 of every title first, at most 4 requests per search. - Failed requests back off for 1, 2, 4 ... up to 30 minutes. The 10th consecutive failure stops enrichment until Test MAM Session passes, the session ID changes, or Shelfmark restarts. - The detail cache prunes expired entries instead of growing for as long as Shelfmark runs.
doonga
pushed a commit
to greyrock-labs/home-ops
that referenced
this pull request
Sep 26, 2026
…v1.4.0) (#283) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/calibrain/shelfmark](https://github.com/calibrain/shelfmark) | minor | `v1.3.15` → `v1.4.0` | --- ### Release Notes <details> <summary>calibrain/shelfmark (ghcr.io/calibrain/shelfmark)</summary> ### [`v1.4.0`](https://github.com/calibrain/shelfmark/releases/tag/v1.4.0) [Compare Source](calibrain/shelfmark@v1.3.15...v1.4.0) ##### What's Changed - build(deps): bump the python-deps group with 2 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1302](calibrain/shelfmark#1302) - fix: keep polling queued Real-Debrid torrents by [@​mvanhorn](https://github.com/mvanhorn) in [#​1303](calibrain/shelfmark#1303) - fix(bypass): keep Anna's Archive's aa\_ddg\_check so clearance replays by [@​jfmlima](https://github.com/jfmlima) in [#​1305](calibrain/shelfmark#1305) - fix(postprocess): attach unmatched chaptered audio files to existing book group ([#​1176](calibrain/shelfmark#1176)) by [@​amasen02](https://github.com/amasen02) in [#​1309](calibrain/shelfmark#1309) - build(deps): bump the gh-actions group with 3 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1310](calibrain/shelfmark#1310) - build(deps): bump the npm-deps group in /src/frontend with 4 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1308](calibrain/shelfmark#1308) - build(deps): bump python from `cae66f2` to `cad9a2c` by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1307](calibrain/shelfmark#1307) - build(deps): bump the docker-base-image-digests group with 2 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1306](calibrain/shelfmark#1306) - Deep-link Search By mode via URL hash by [@​nfvelten](https://github.com/nfvelten) in [#​1311](calibrain/shelfmark#1311) - build(deps): bump the python-deps group across 1 directory with 4 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1327](calibrain/shelfmark#1327) - Keep default filters out of the URL hash by [@​nfvelten](https://github.com/nfvelten) in [#​1314](calibrain/shelfmark#1314) - feat(download): add Blackhole torrent handoff by [@​atirna](https://github.com/atirna) in [#​1312](calibrain/shelfmark#1312) - feat(naming): add {FirstAuthor} template token by [@​viniciuspx](https://github.com/viniciuspx) in [#​1322](calibrain/shelfmark#1322) - fix: share rotating log file handlers by [@​eikopf](https://github.com/eikopf) in [#​1316](calibrain/shelfmark#1316) - fix(prowlarr): skip indexers in Prowlarr failure back-off by [@​jfmlima](https://github.com/jfmlima) in [#​1324](calibrain/shelfmark#1324) - fix: prevent Anna's Archive download countdown resets by preserving browser sessions by [@​broglea](https://github.com/broglea) in [#​1325](calibrain/shelfmark#1325) - build(deps): bump the docker-base-image-digests group with 2 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1328](calibrain/shelfmark#1328) - build(deps-dev): bump the npm-deps group in /src/frontend with 4 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1329](calibrain/shelfmark#1329) - build(deps-dev): bump vitest from 4.1.11 to 5.0.0 in /src/frontend by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1330](calibrain/shelfmark#1330) - fix(irc): search by surname, and rank the answer by author ([#​1331](calibrain/shelfmark#1331)) by [@​Kukkerem](https://github.com/Kukkerem) in [#​1332](calibrain/shelfmark#1332) - fix(irc): rank a surname-only result as partial, not wrong ([#​1332](calibrain/shelfmark#1332)) by [@​calibrain](https://github.com/calibrain) in [#​1334](calibrain/shelfmark#1334) - feat(sources): add Libgen as a direct catalogue search source by [@​klaidliadon](https://github.com/klaidliadon) in [#​1326](calibrain/shelfmark#1326) - refactor: make direct download provider-driven by [@​TomJansen](https://github.com/TomJansen) in [#​1337](calibrain/shelfmark#1337) - fix(sources): restore Direct Download search errors and language matches by [@​calibrain](https://github.com/calibrain) in [#​1339](calibrain/shelfmark#1339) - fix(sources): send a Referer when fetching libgen ads.php pages by [@​klaidliadon](https://github.com/klaidliadon) in [#​1340](calibrain/shelfmark#1340) - Feature: Add Download counts to search result displays and Download sidebar by [@​RoninTech](https://github.com/RoninTech) in [#​1336](calibrain/shelfmark#1336) - Extract archives when zip/rar are enabled as supported formats by [@​funkypenguin](https://github.com/funkypenguin) in [#​1343](calibrain/shelfmark#1343) - fix(download): complete consumed Blackhole handoffs by [@​atirna](https://github.com/atirna) in [#​1345](calibrain/shelfmark#1345) - Add configurable word separator for naming templates by [@​viniciuspx](https://github.com/viniciuspx) in [#​1333](calibrain/shelfmark#1333) - build(deps): bump the python-deps group across 1 directory with 5 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1344](calibrain/shelfmark#1344) - fix: unbreak main and follow up on the Blackhole handoff review by [@​calibrain](https://github.com/calibrain) in [#​1346](calibrain/shelfmark#1346) - build(deps): bump python-socketio from 5.16.4 to 5.17.0 in the python-deps group by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1347](calibrain/shelfmark#1347) - Added the ability to sort direct search results by Most downloads by [@​RoninTech](https://github.com/RoninTech) in [#​1351](calibrain/shelfmark#1351) - feat: Add TorBox client support and settings integration by [@​marcelorodrigo](https://github.com/marcelorodrigo) in [#​1342](calibrain/shelfmark#1342) - refactor: extract the per-source release search out of /api/releases by [@​splitsec2](https://github.com/splitsec2) in [#​1355](calibrain/shelfmark#1355) - build(deps): bump the docker-base-image-digests group with 2 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1348](calibrain/shelfmark#1348) - build(deps): bump the npm-deps group in /src/frontend with 9 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1349](calibrain/shelfmark#1349) - build(deps): bump the gh-actions group with 6 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1350](calibrain/shelfmark#1350) - feat(auth): provision proxy users as non-admin once an admin exists by [@​splitsec2](https://github.com/splitsec2) in [#​1356](calibrain/shelfmark#1356) - fix(users): apply user updates only after the payload validates by [@​splitsec2](https://github.com/splitsec2) in [#​1360](calibrain/shelfmark#1360) - fix(download): default is\_admin to False in the request policy guard by [@​splitsec2](https://github.com/splitsec2) in [#​1358](calibrain/shelfmark#1358) - fix(oidc): reject backslash paths in the return\_to sanitizer by [@​splitsec2](https://github.com/splitsec2) in [#​1359](calibrain/shelfmark#1359) - fix(queue): don't stamp CANCELLED over a finished download by [@​splitsec2](https://github.com/splitsec2) in [#​1361](calibrain/shelfmark#1361) - fix(download): check task ownership before serving queued files by [@​splitsec2](https://github.com/splitsec2) in [#​1357](calibrain/shelfmark#1357) - Feature: Show the AA search result stats by [@​RoninTech](https://github.com/RoninTech) in [#​1362](calibrain/shelfmark#1362) - fix(requests): reject non-object items in the batch endpoint by [@​splitsec2](https://github.com/splitsec2) in [#​1369](calibrain/shelfmark#1369) - fix(http): keep the host of a protocol-relative download link by [@​splitsec2](https://github.com/splitsec2) in [#​1368](calibrain/shelfmark#1368) - fix(googlebooks): page by the capped size, not the raw limit by [@​splitsec2](https://github.com/splitsec2) in [#​1370](calibrain/shelfmark#1370) - fix(deluge): send seeding ratio limit under Deluge's own keys by [@​splitsec2](https://github.com/splitsec2) in [#​1367](calibrain/shelfmark#1367) - feat(auth): static API\_KEY (env) accepted as Bearer or X-Api-Key, cookie or key by [@​gavinmcfall](https://github.com/gavinmcfall) in [#​1366](calibrain/shelfmark#1366) - fix(auth): rename the API\_KEY env var to SHELFMARK\_API\_KEY by [@​calibrain](https://github.com/calibrain) in [#​1374](calibrain/shelfmark#1374) - fix: bypass recordings, welib wrong-md5 links, footer build sha ([#​1364](calibrain/shelfmark#1364)) by [@​calibrain](https://github.com/calibrain) in [#​1373](calibrain/shelfmark#1373) - build(deps): bump the python-deps group with 4 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1375](calibrain/shelfmark#1375) - ci: debounce dev image builds instead of building nightly by [@​calibrain](https://github.com/calibrain) in [#​1376](calibrain/shelfmark#1376) - fix(download): stream a completed book instead of buffering it in RAM - lowering memory needs significantly by [@​splitsec2](https://github.com/splitsec2) in [#​1378](calibrain/shelfmark#1378) - perf(docker): keep the heavy build layers cacheable across builds - save 11minutes per build by [@​splitsec2](https://github.com/splitsec2) in [#​1379](calibrain/shelfmark#1379) - test(auth): stop proxy provisioning tests depending on run order by [@​splitsec2](https://github.com/splitsec2) in [#​1381](calibrain/shelfmark#1381) - feat(search): add a configurable default content type by [@​splitsec2](https://github.com/splitsec2) in [#​1371](calibrain/shelfmark#1371) - feat(library): mark search results already in a Calibre library by [@​splitsec2](https://github.com/splitsec2) in [#​1377](calibrain/shelfmark#1377) - Default to english when no lang is slected by [@​calibrain](https://github.com/calibrain) in [#​1396](calibrain/shelfmark#1396) - fix(auth): fail closed when auth prerequisites are missing ([#​1387](calibrain/shelfmark#1387)) by [@​calibrain](https://github.com/calibrain) in [#​1397](calibrain/shelfmark#1397) - build(deps): bump the gh-actions group with 4 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1395](calibrain/shelfmark#1395) - fix(audiobookbay): reuse the resolved magnet when retrying ([#​1388](calibrain/shelfmark#1388)) by [@​calibrain](https://github.com/calibrain) in [#​1398](calibrain/shelfmark#1398) - build(deps): bump the npm-deps group in /src/frontend with 7 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1394](calibrain/shelfmark#1394) - build(deps): bump seleniumbase from 4.54.9 to 4.54.10 in the python-deps group by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1382](calibrain/shelfmark#1382) - feat: narrator, series and bitrate columns for MyAnonamouse results by [@​adman234](https://github.com/adman234) in [#​1390](calibrain/shelfmark#1390) - build(deps): bump astral-sh/uv from 0.12.16 to 0.12.19 in the docker-base-image-digests group across 1 directory by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1392](calibrain/shelfmark#1392) - fix(mam): keep the session ID on MAM and rerun Prowlarr's exact search by [@​calibrain](https://github.com/calibrain) in [#​1399](calibrain/shelfmark#1399) - fix(ui): contain the result count added in [#​1362](calibrain/shelfmark#1362) by [@​calibrain](https://github.com/calibrain) in [#​1363](calibrain/shelfmark#1363) ##### New Contributors - [@​amasen02](https://github.com/amasen02) made their first contribution in [#​1309](calibrain/shelfmark#1309) - [@​atirna](https://github.com/atirna) made their first contribution in [#​1312](calibrain/shelfmark#1312) - [@​viniciuspx](https://github.com/viniciuspx) made their first contribution in [#​1322](calibrain/shelfmark#1322) - [@​eikopf](https://github.com/eikopf) made their first contribution in [#​1316](calibrain/shelfmark#1316) - [@​broglea](https://github.com/broglea) made their first contribution in [#​1325](calibrain/shelfmark#1325) - [@​klaidliadon](https://github.com/klaidliadon) made their first contribution in [#​1326](calibrain/shelfmark#1326) - [@​TomJansen](https://github.com/TomJansen) made their first contribution in [#​1337](calibrain/shelfmark#1337) - [@​RoninTech](https://github.com/RoninTech) made their first contribution in [#​1336](calibrain/shelfmark#1336) - [@​marcelorodrigo](https://github.com/marcelorodrigo) made their first contribution in [#​1342](calibrain/shelfmark#1342) - [@​splitsec2](https://github.com/splitsec2) made their first contribution in [#​1355](calibrain/shelfmark#1355) - [@​gavinmcfall](https://github.com/gavinmcfall) made their first contribution in [#​1366](calibrain/shelfmark#1366) **Full Changelog**: <calibrain/shelfmark@v1.3.15...v1.4.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone America/New_York) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDUuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEwNS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19--> Reviewed-on: https://git.greyrock.io/todd/home-ops/pulls/283
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #1390.
not check the host, and the mam_id cookie had no domain. Any Prowlarr
indexer returning a URL like https://evil.example?myanonamouse.net/t/1
sent the session ID to evil.example. Requests now always go to
https://www.myanonamouse.net (Prowlarr's only MAM URL), with the cookie
as a header and redirects off. Only results from Prowlarr's
MyAnonamouse indexer are looked up, and their URLs must be on
myanonamouse.net.
titles most of Prowlarr's results were missed (a "Dune" audiobook
search: 56 audiobooks on the first 100 of 328 matches). It now reruns
Prowlarr's exact search: the same query clean-up, the MAM main
categories behind the Torznab categories searched (13/15/16 for
audiobooks, 14 for e-books, all once expanded), and the MAM indexer's
own search type, search-in options and languages. Further pages are
read while IDs are missing, page 1 of every title first, at most 4
requests per search.
consecutive failure stops enrichment until Test MAM Session passes,
the session ID changes, or Shelfmark restarts.
as Shelfmark runs.