Navidrome v0.62.0

v0.62.0
Added 10
  • Support for OpenSubsonic sonicSimilarity extension enabling audio-based similarity through plugins with getSonicSimilarTracks and findSonicPath endpoints
  • New OpenSubsonic playbackReport extension for playback reporting in the UI
  • ReplayGain fields in smart playlists
  • New isMissing and isPresent operators for smart playlists
  • Five new UI themes
  • EnforceNonRootUser option to exit early on startup if Navidrome is running as root
Changed 3
  • Redesigned Now Playing experience and playback reporting panel using OpenSubsonic playbackReport extension
  • Renamed EnableTranscodingCancellation to Transcoding.EnableCancellation and moved under Transcoding section
  • Renamed SimilarSongsMatchThreshold to Matcher.FuzzyThreshold and moved under Matcher section
Security 7
  • Enforce per-user ownership on share reads to fix cross-account disclosure of other users' shares and share tokens
  • Enforce ownership atomically on player and share updates to fix cross-tenant player takeover and share-update IDOR
  • Require signed state token on Last.fm link callback to fix unauthenticated scrobble session hijack
  • Validate token expiration and share existence on public share stream endpoints to fix JWT expiration bypass
  • Restrict transcoding configuration reads to admins to fix disclosure of admin-only configuration to non-admin users
  • Require admin access for Subsonic internet radio station management endpoints to fix missing authorization
  • Cap concurrent transcodes to prevent ffmpeg-based denial of service with per-server and per-user limits

This release introduces support for the OpenSubsonic sonicSimilarity extension, enabling audio-based similarity through the plugin system: when a plugin provides the capability, the new getSonicSimilarTracks and findSonicPath endpoints unlock smarter, sound-based recommendations and playlists. One plugin that implements it is AudioMuse-AI. It also brings a major overhaul to playback reporting and the Now Playing experience — the UI now uses the new OpenSubsonic playbackReport extension, replacing the old scrobble flow with a redesigned panel and configurable reporting interval. On the security front, it hardens the server with stronger ownership and authorization checks across shares, players, and transcoding endpoints, caps concurrent transcodes to prevent ffmpeg-based denial of service, and adds an option to refuse to run as root. Smart playlists gain ReplayGain fields and new isMissing/isPresent operators, and there are five new UI themes to choose from.

Security

This release fixes several reported vulnerabilities. We thank the security researchers who responsibly disclosed them.

Note: Several of the advisories linked above are still in draft/triage on GitHub at the time of writing. Their links will become publicly accessible once the advisories are published. The fixes themselves are already included in this release.

Configuration Changes
StatusOptionDescriptionDefault
NewEnforceNonRootUserExit early on startup if Navidrome is running as root (ignored on Windows). (#5373)false
NewTranscoding.MaxConcurrentMaximum number of concurrent transcodes server-wide (0 = unlimited). (#5522)0
NewTranscoding.MaxConcurrentPerUserMaximum number of concurrent transcodes per user (0 = unlimited). (#5522)0
NewMatcher.PreferStarredBias the fuzzy matcher toward starred/high-rated tracks. (#5387)true
NewUIPlaybackReportIntervalHow often the UI reports playback progress. (#5448)1m
DeprecatedEnableTranscodingCancellationTranscoding.EnableCancellationRenamed and moved under the new Transcoding section. (#5523)false
DeprecatedSimilarSongsMatchThresholdMatcher.FuzzyThresholdRenamed and moved under the new Matcher section. (#5387)85

For a complete list of all configuration options, see the Configuration Options documentation.

UI
Smart Playlists
  • Add ReplayGain fields to the criteria system. (d9dac4445 by @deluan)
  • Add isMissing and isPresent operators. (#5436 by @deluan)
  • Relax playlist visibility in inPlaylist/notInPlaylist rules. (#5411 by @deluan)
  • Optimize smart playlist performance for role and tag criteria. (#5515 by @deluan)
  • Coerce string booleans in smart playlist rules. (#5450 by @deluan)
Subsonic API
  • Implement the playbackReport OpenSubsonic extension. (#5442 by @deluan)
  • Add the sonicSimilarity extension as a plugin capability. (#5419 by @deluan)
  • Add a groupings field to the OpenSubsonic Child response. (f12e75aa1 by @deluan)
  • Use SQLite RANDOM() sorting in getRandomSongs for faster results. (cf1f190bb by @deluan)
  • Mark AlbumID3 songCount and created as required. (8897ec918 by @deluan)
  • Normalize non-NFKD Unicode letters (ø, æ, œ, ß) in search. (#5413 by @deluan)
Transcoding
  • Place -ss before -i for fast input seeking. (#5492 by @deluan)
  • Don't apply server-side override on getTranscodeDecision. (#5473 by @deluan)
  • Log a warning for invalid or stale transcode tokens. (9a2eb483e by @deluan)
Scanner
  • Respect tag-split config when multiple frames map to the same tag. (#5193 by @trek-e)
  • Fix error when importing playlists without an admin user. (5b85b2839 by @deluan)
Artwork
  • Fix stale cache and top-level album artwork for multi-disc albums. (#5457 by @deluan)
  • Prefer album-root images over disc-subfolder images for multi-disc albums. (#5451 by @deluan)
  • Return the correct timestamp when disc or album cover art changes. (#5378 by @bobo-xxx)
Server
  • Prevent artwork throttle token starvation on slow clients. (#5472 by @deluan)
  • Proxy NowPlaying even when ignoreScrobble is set. (#5559 by @deluan)
  • Make the /api/song path filter work and use startsWith. (#5566 by @deluan)
  • Preserve unchanged fields on partial REST playlist updates. (#5542 by @deluan)
  • Allow toggling playlist auto-import and avoid unnecessary artwork reloads. (#5421 by @deluan)
Matcher
  • Add Matcher.PreferStarred option to bias the fuzzy matcher toward starred/high-rated tracks. (#5387 by @deluan)
Plugins
CLI
  • Add pls export/import subcommands for bulk playlist management. (#5412 by @deluan)
  • Restore int cast for syscall.Stdin on Windows. (e75ab3b03 by @deluan)
Build & Dependencies
  • Improve Windows support: the Go test suite now runs on Windows CI, with previously-skipped Subsonic, artwork, watcher, and scheduler tests enabled and fixed. (#5380, #5427, #5416 by @deluan)
  • Upgrade Go to 1.26. (#5361 by @deluan)
  • Enable native libwebp encoding in the Docker image. (#5350 by @deluan)
  • Update TagLib to 2.3. (e55a35544 by @deluan)
Translations
New Contributors

Full Changelog: https://github.com/navidrome/navidrome/compare/v0.61.2...v0.62.0

Helping out

This release is only possible thanks to the support of some awesome people!

Want to be one of them? You can sponsor, pay me a Ko-fi, or contribute with code.

Where to go next?
View original

Upgraded? How did it go?

Discussion