mirror of
https://github.com/navidrome/navidrome.git
synced 2026-08-01 07:21:17 +00:00
fix(participants): add separator to dedup key to avoid prefix collisions
Per Gemini review on PR #5527: the dedup key was 'ID+SubRole' with no separator, so (ID='12', SubRole='3') and (ID='1', SubRole='23') would collide. Real-world risk is negligible (artist IDs are fixed-length MD5 hashes), but the fix is trivial — use a NUL byte that cannot appear in either field.
This commit is contained in:
parent
627d6161cc
commit
2ff6d91057
@ -156,12 +156,15 @@ func (p Participants) Merge(other Participants) {
|
||||
}
|
||||
|
||||
func (p Participants) add(role Role, participants ...Participant) {
|
||||
// Use a separator that can't appear in either field so e.g.
|
||||
// (ID="12", SubRole="3") doesn't collide with (ID="1", SubRole="23").
|
||||
const sep = "\x00"
|
||||
seen := make(map[string]int, len(p[role]))
|
||||
for i, artist := range p[role] {
|
||||
seen[artist.ID+artist.SubRole] = i
|
||||
seen[artist.ID+sep+artist.SubRole] = i
|
||||
}
|
||||
for _, participant := range participants {
|
||||
key := participant.ID + participant.SubRole
|
||||
key := participant.ID + sep + participant.SubRole
|
||||
if idx, ok := seen[key]; ok {
|
||||
// Same artist/sub-role seen before. The merge (e.g. building
|
||||
// album.Participants from per-track participants) is inherently
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user