jagrosh / jagrosh/MusicBot

[Feature Request] Config option to disallow external url sources

Open
#808 4 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
5.8k
Forks
2.8k
PR merge metrics
No merged PRs in 30d

Description

**Is your feature request related to a problem? Please describe.**
LavaPlayer allows playing of any arbitrary URLs, which some are considering as a security issue.

**Describe the solution you'd like**
A config entry should be added, which allows bot owners to not load tracks from external URL's. YouTube, SoundCloud etc. can still load regardless of this setting

**Describe the basic flow/steps of using this feature**
1. - The bot owner disables the capability of playing from external url sources
- No one will be able to queue any music outside of YouTube, SoundCloud etc.

2. - The bot owner disables the capability of playing from external url sources
- Everyone will be able to queue any music outside of YouTube, SoundCloud etc.

**Additional context**
Discussed in https://github.com/jagrosh/MusicBot/discussions/744

Originally posted by **hermitoff** August 29, 2021
Hello,

Do not use your IP to host the bot!
Because anyone can find it.

You just have to send to the bot a request (with the command play) to an ip logger to get it.

Here is an example to show you:
![unknown](https://user-images.githubusercontent.com/82811865/131243025-01dec083-03d0-4876-b9ba-0669b103bf59.png)

I'm sorry to show this to everybody.
And don't worry about the IP on the image, I don't care.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. First clarify which URL sources remain allowed and resolve the contradictory usage steps; done means the configuration reliably prevents disallowed external URLs while preserving the explicitly allowed sources.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.