rays c1187a7926 Verify Cloudflare Access's signed token before trusting the proxy
The proxy sign-in believed Cf-Access-Authenticated-User-Email from any
address in trusted_proxies. On Tower that address is the Docker gateway,
so any container there could name itself anyone (docs/sso.md said as
much, and CLAUDE.md listed it as a known gap).

With [web] access_team and access_aud set, a proxied request must also
carry a Cf-Access-Jwt-Assertion that verifies against Cloudflare's keys
(RS256 only, this application's audience, the team's issuer, not
expired), and the name comes from its email claim. The keys are fetched
at start and again when a token names an unseen key, at most once a
minute, so made-up key ids cannot make every request a request to
Cloudflare. While the keys cannot be had, proxied sign-in is refused;
password and token sign-in are unaffected. Both settings empty, nothing
changes.

jsonwebtoken does the checking, on the aws-lc-rs backend already in the
tree through rustls. Tests sign with throwaway keys in tests/data: a
valid token, another app's audience, expired, a forged signature, HS256,
alg none, the refetch limit, and keys that cannot be fetched. Checked
live on a scratch daemon: the header alone and a forged token got 401,
the admin token still signed in.

vouched_name takes the peer and headers rather than the request: a
&Request held across the new await made the auth middleware's future
unsendable, as a body is not Sync.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-19 14:38:25 +00:00
2026-09-19 02:33:40 +00:00
2026-09-09 19:34:25 +00:00
2026-09-18 16:47:21 +00:00

ipodderx-rs

A self-hosted podcatcher for a household. It checks your feeds, downloads the episodes, and serves a web UI modelled on the 2004 Mac app iPodderX, for any number of people sharing one copy of the files. One Rust binary, ipx, is both the daemon and the command line.

It is a rewrite of ipodderx-core, the Python engine behind iPodderX (2004-2008, Ray Slakinski & August Trometer).

What it does

  • The web UI. It has a toolbar, and a feed list that opens with Directory, Popular and All Subscriptions. Items sit in a sortable table with a Files pane, and there is a player bar. It comes in Dark, Light and Classic themes, and works on a phone.
  • Several people, one copy. Each person has their own subscriptions and their own read, pinned and playback state. There is one file on disk per episode, however many people want it. People sign in with a password or through a proxy (Cloudflare Zero Trust or Authentik), and admins manage accounts and settings.
  • Scanning. Feeds are checked on a schedule, globally or per feed, and a feed's own TTL is honoured. Keyword, explicit-content and media-type filters decide what is downloaded, with a cap on new downloads per scan.
  • Downloads. Files come over HTTP or BitTorrent and are filed into a folder per feed. Retention deletes the oldest files to stay under a disk quota or an age limit, and never touches an item someone has pinned.
  • OPML. You can import and export your own subscriptions. You can also subscribe to an OPML URL, which keeps a whole list in step as a folder.

Run it

With Docker:

docker build -t ipodderx .
docker compose up -d

docker-compose.yml is set up for the author's own server. Point its image and its three volumes (/config, /data and /downloads) at yours first. The UI is on port 8099. BitTorrent uses 6881 over TCP and UDP. Files are written as PUID/PGID, 99:100 by default.

From source:

cargo build --release
./target/release/ipx daemon

The first start creates admin / ipodderx. Sign in at /login, then change it:

echo -n 'a good password' | ipx user passwd admin

The UI is plain HTTP, so put TLS in front of it if it is reachable from outside your network.

Documentation

docs/configuration.md Every config key, path and environment variable
docs/cli.md Every command, including ipx user
docs/users.md Accounts, and what several people share
docs/sso.md Signing in through Cloudflare Zero Trust or Authentik
docs/architecture.md How it works: modules, schema, control socket, HTTP API
CHANGELOG.md What changed, by release
CLAUDE.md Notes for working on the code, including how production is deployed

Tests

cargo test                # the engine: parsing, filters, retention, schedules, SQL, per-user state
node tests/page-smoke.js  # the page script loads without throwing
npx playwright test       # a real browser against a real daemon on fixture feeds

npm install gets the test runner, and npx playwright install --with-deps chromium gets the browser.

License

MIT, see LICENSE. The icons are Font Awesome Free 7.3.1 by @fontawesome, under CC BY 4.0, embedded as SVG.

Description
No description provided
Readme MIT 9.5 MiB
Languages
Rust 49%
JavaScript 27.3%
TypeScript 15.4%
CSS 6.8%
HTML 1.1%
Other 0.4%