aboutsummaryrefslogtreecommitdiff
path: root/Jellyfin.Api/Middleware/LanFilteringMiddleware.cs
diff options
context:
space:
mode:
Diffstat (limited to 'Jellyfin.Api/Middleware/LanFilteringMiddleware.cs')
-rw-r--r--Jellyfin.Api/Middleware/LanFilteringMiddleware.cs49
1 files changed, 49 insertions, 0 deletions
diff --git a/Jellyfin.Api/Middleware/LanFilteringMiddleware.cs b/Jellyfin.Api/Middleware/LanFilteringMiddleware.cs
new file mode 100644
index 000000000..9c2194faf
--- /dev/null
+++ b/Jellyfin.Api/Middleware/LanFilteringMiddleware.cs
@@ -0,0 +1,49 @@
+using System.Threading.Tasks;
+using Jellyfin.Networking.Configuration;
+using MediaBrowser.Common.Extensions;
+using MediaBrowser.Common.Net;
+using MediaBrowser.Controller.Configuration;
+using Microsoft.AspNetCore.Http;
+
+namespace Jellyfin.Api.Middleware;
+
+/// <summary>
+/// Validates the LAN host IP based on application configuration.
+/// </summary>
+public class LanFilteringMiddleware
+{
+ private readonly RequestDelegate _next;
+
+ /// <summary>
+ /// Initializes a new instance of the <see cref="LanFilteringMiddleware"/> class.
+ /// </summary>
+ /// <param name="next">The next delegate in the pipeline.</param>
+ public LanFilteringMiddleware(RequestDelegate next)
+ {
+ _next = next;
+ }
+
+ /// <summary>
+ /// Executes the middleware action.
+ /// </summary>
+ /// <param name="httpContext">The current HTTP context.</param>
+ /// <param name="networkManager">The network manager.</param>
+ /// <param name="serverConfigurationManager">The server configuration manager.</param>
+ /// <returns>The async task.</returns>
+ public async Task Invoke(HttpContext httpContext, INetworkManager networkManager, IServerConfigurationManager serverConfigurationManager)
+ {
+ if (serverConfigurationManager.GetNetworkConfiguration().EnableRemoteAccess)
+ {
+ await _next(httpContext).ConfigureAwait(false);
+ return;
+ }
+
+ var host = httpContext.GetNormalizedRemoteIp();
+ if (!networkManager.IsInLocalNetwork(host))
+ {
+ return;
+ }
+
+ await _next(httpContext).ConfigureAwait(false);
+ }
+}