Repository navigation
Tags: seerr-team/seerr
Tags
fix(auth): sign session cookie store with sessionSecret, not clientId
cookie-parser was initialized with settings.clientId (the Plex client
UUID), but express-session signs connect.sid with settings.sessionSecret.
The secrets differ, so cookie-parser's signature check on connect.sid
fails, the cookie is dropped from req.cookies, and the OpenAPI validator
rejects every authenticated request with "cookie 'connect.sid' required"
even though the browser is sending it correctly.
This also matches the signing secret used by the OIDC code-verifier and
state cookies that are stored via res.cookie(..., {signed: true}), which
read back through req.signedCookies during the callback.
feat(watchlist): track watchlist entries so deletions stick Deleting a title that was still on someone's watchlist got it re-requested on the next sync and on every sync after that, as the only thing sync looked at was the media status. Entries are now recorded per user with the watchlistedAt timestamp Plex reportes, so an entry is acted on once. Removing a title from the watchlist and adding it back produces a new timestamp, which is a new entry, so it gets requested again. Shows track which seasons were handled, so new seasons still come through and re-adding the series resets it. fix 3222
fix(requests): skip override rules if there is no default server
fix(scanner): confirm orphan candidates against the servers before de… …clining The arr scanners snapshot the library once per run and then decline any PROCESSING request missing from the snapshot, so a request created mid-scan gets declined minutes after the *arr accepted it. The stock schedule makes it routine, as both scan jobs land on a plex-wtachlist-sync tick as well. Now they are re-checked against the live servers before anything is declined, using the library-filtered endpoints.
fix(sqlite): avoid shared transaction depth race in subscribers sqlite reuses one query runner per process, so concurrent scanner saves race on its shared transaction depth counter and wedge it, silently leaving later writes uncommitted. Related-request work now runs directly on event.manager on sqlite instead of nesting a transaction.
perf: bound tmdb cache & split scan lookups into their own tier Library scans and availavilit sync fetched the full /tv/:id payload including aggregate_credits and cached it for 12 hours in the same unbounded cache the interactive TV detail page uses, so a full scan left most of a library resident until the TTL expired. Scanners and availability sync now request only keywords and external_ids, which is everything they read, and write to a separate LRU-bounded cache with a 15 minute TTL, so scan lookups age out on their own instead of evicting traffic of manual browsing. The interactive cache gains a key-count backstop against the unbounded growth, and aggregate_credits.crew and credits.cast are stripped before caching since nothing in the codebase readss that either. fix #3307
fix(tv): prevent phantom specials from blocking season requests
PreviousNext