diff --git a/calibre_web/CHANGELOG.md b/calibre_web/CHANGELOG.md index 5eaf9b129a..bd07964f26 100644 --- a/calibre_web/CHANGELOG.md +++ b/calibre_web/CHANGELOG.md @@ -1,4 +1,7 @@ +## 0.6.27.2 (2026-08-23) +- Fix: trust the whole supervisor network range for the ingress auth header instead of the addon's own address, which changes across restarts. The list is only written when that range is missing, so an entry added in the calibre-web admin page is no longer erased on every start (https://github.com/alexbelgium/hassio-addons/pull/3010) + ## 0.6.27.1 (2026-08-23) - Fix: Ingress login was rejected since 0.6.27, which only accepts the reverse proxy auth header from trusted source addresses. The addon now adds its own ip to that list (https://github.com/alexbelgium/hassio-addons/issues/3003) diff --git a/calibre_web/config.yaml b/calibre_web/config.yaml index ad72563d8e..fdce14d9db 100644 --- a/calibre_web/config.yaml +++ b/calibre_web/config.yaml @@ -116,5 +116,5 @@ schema: slug: calibre-web udev: true url: https://github.com/alexbelgium/hassio-addons/tree/master/calibre_web -version: "0.6.27.1" +version: "0.6.27.2" video: true diff --git a/calibre_web/rootfs/etc/cont-init.d/80-configuration.sh b/calibre_web/rootfs/etc/cont-init.d/80-configuration.sh index 4ae133e43b..16a99a5f33 100755 --- a/calibre_web/rootfs/etc/cont-init.d/80-configuration.sh +++ b/calibre_web/rootfs/etc/cont-init.d/80-configuration.sh @@ -19,25 +19,19 @@ if [ ! -f /config/app.db ]; then else sqlite3 /config/app.db 'update settings set config_reverse_proxy_login_header_name="X-WebAuth-User",config_allow_reverse_proxy_header_login=1' - # Calibre-web 0.6.27 only accepts the ingress auth header from a trusted source address, and - # defaults that list to "127.0.0.1,::1". Nginx binds its upstream socket to the addon ip - # (proxy_bind $server_addr in ingress.conf) and calibre-web listens dual-stack, so it sees - # ::ffff: and drops the header. Both the plain and the ipv4-mapped forms are listed - # because an ipv4 entry never matches an ipv6-mapped address on the calibre-web side. - # The column only exists once calibre-web 0.6.27+ has migrated app.db, so a failure here is - # not fatal : the next start applies it. - addon_ip=$(bashio::addon.ip_address) - trusted_ips="127.0.0.1,::1,::ffff:127.0.0.1" - if bashio::var.has_value "${addon_ip}"; then - trusted_ips="${trusted_ips},${addon_ip},::ffff:${addon_ip}" - fi - trusted_ips_error=$(sqlite3 /config/app.db "update settings set config_reverse_proxy_trusted_ips='${trusted_ips}'" 2>&1) || { - if echo "${trusted_ips_error}" | grep -q "no such column"; then - bashio::log.warning "Could not set the ingress trusted ip list, it will be applied at next start" - else - bashio::log.warning "Could not set the ingress trusted ip list: ${trusted_ips_error}" - fi - } + # Calibre-web 0.6.27 only accepts that header from a trusted source address, and defaults the + # list to "127.0.0.1,::1". Ingress reaches calibre-web from the addon's own address on the + # supervisor network (proxy_bind $server_addr in ingress.conf) and calibre-web listens + # dual-stack, so it sees ::ffff: and drops the header. The supervisor range is + # listed in both forms because an ipv4 entry never matches an ipv4-mapped address. + # Prepended to whatever is already there, and only when the mapped form is missing : that form + # is the one ingress needs and the one nobody types by hand, so it doubles as the marker that + # this already ran. Anything the user added is kept, the statement runs at most once, and the + # duplicates it can leave behind are entries calibre-web skips or already trusts. + # The column only exists once calibre-web 0.6.27+ has migrated app.db and cont-init runs + # before calibre-web, so a failure here is not fatal : the next start applies it. + trusted_ips_error=$(sqlite3 /config/app.db "update settings set config_reverse_proxy_trusted_ips='127.0.0.1,::1,::ffff:127.0.0.1,172.30.32.0/23,::ffff:172.30.32.0/119,'||coalesce(config_reverse_proxy_trusted_ips,'') where coalesce(config_reverse_proxy_trusted_ips,'') not like '%::ffff:172.30.32.0/119%'" 2>&1) || + bashio::log.warning "Could not set the ingress trusted ip list, it will be applied at next start (${trusted_ips_error})" fi bashio::log.info "Default username:password is admin:admin123"