rays b86062b97a Keep a feed's items and files to the people who subscribe to it (#129)
Routes that take a feed or an enclosure id did not check who was asking. Anyone signed in could
read any feed's items through GET /api/feeds/{id}/entries, a paid feed's included, with the
addresses of its files, which can carry the subscriber's key: the Directory leaves such feeds
out for that reason, and this route handed them back to whoever guessed the id, a slug of the
title. In production it answered 25 items of a feed the asking account does not subscribe to.
/media/{id} served any downloaded file by its sequential id, POST /api/enclosures/{id}/download
and /api/feeds/{id}/download-latest queued any feed's downloads, and DELETE
/api/enclosures/{id}?force=true deleted any file.

Each now answers 404, "you do not subscribe to that feed", unless the person subscribes to it.
A feed inside an OPML has a subscription row of its own for everyone subscribed to the OPML, so
that holds for those feeds too. Found while adding the Directory's feed page (#128), which has
its own route that answers only for listed feeds and carries no files.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-05 16:19:38 +00:00
2026-09-09 19:34:25 +00:00

ipx

A self-hosted podcatcher for a household. It checks your feeds, downloads the episodes, and serves a web UI modelled on the 2004 Mac app iPodderX, for any number of people sharing one copy of the files. One Rust binary, ipx, is both the daemon and the command line.

It is a rewrite of ipodderx-core, the Python engine behind iPodderX (2004-2008, Ray Slakinski & August Trometer).

What it does

  • The web UI. It has a toolbar, and a feed list that opens with the Directory, Currently Listening and All Subscriptions. Items sit in a sortable table with a Files pane, and there is a player bar. It comes in Dark, Light and Classic themes, and works on a phone.
  • Several people, one copy. Each person has their own subscriptions and their own read, pinned and playback state. There is one file on disk per episode, however many people want it. People sign in with a password or through a proxy (Cloudflare Zero Trust or Authentik), and admins manage accounts and settings.
  • Scanning. Feeds are checked on a schedule, globally or per feed, and a feed's own TTL is honoured. Keyword, explicit-content and media-type filters decide what is downloaded, with a limit on how many of a feed's newest episodes are downloaded.
  • Downloads. Files come over HTTP or BitTorrent and are filed into a folder per feed. Retention deletes the oldest files to stay under a disk quota or an age limit, and never touches an item someone has pinned.
  • OPML. You can import and export your own subscriptions. You can also subscribe to an OPML URL, which keeps a whole list in step as a folder.

Run it

With Docker:

docker build -t ipx .
docker compose up -d

docker-compose.yml is set up for the author's own server. Point its image and its three volumes (/config, /data and /downloads) at yours first. The UI is on port 8099. BitTorrent uses 6881 over TCP and UDP. Files are written as PUID/PGID, 99:100 by default.

From source:

cargo build --release
./target/release/ipx daemon

The first start creates admin / ipodderx. Sign in at /login, then change it:

echo -n 'a good password' | ipx user passwd admin

The UI is plain HTTP, so put TLS in front of it if it is reachable from outside your network.

Documentation

docs/configuration.md Every config key, path and environment variable
docs/cli.md Every command, including ipx user
docs/users.md Accounts, and what several people share
docs/sso.md Signing in through Cloudflare Zero Trust or Authentik
docs/architecture.md How it works: modules, schema, control socket, HTTP API
CHANGELOG.md What changed, by release
CLAUDE.md Notes for working on the code, including how production is deployed

Tests

cargo test                # the engine: parsing, filters, retention, schedules, SQL, per-user state
node tests/page-smoke.js  # the page script loads without throwing
node tests/native-bridge.js  # the page hands playback to a native shell
npx playwright test       # a real browser against a real daemon on fixture feeds

npm install gets the test runner, and npx playwright install --with-deps chromium gets the browser.

License

MIT, see LICENSE. The icons are Font Awesome Free 7.3.1 by @fontawesome, under CC BY 4.0, embedded as SVG.

Description
No description provided
Readme MIT 16 MiB
Languages
Rust 49.6%
JavaScript 25.9%
TypeScript 14.8%
CSS 7%
Python 1.4%
Other 1.3%