Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 2 additions & 3 deletions homepage/index.php
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,8 @@
die();
}

/* Prevent XSS input */
$_GET = filter_input_array(INPUT_GET, FILTER_SANITIZE_STRING);
$_POST = filter_input_array(INPUT_POST, FILTER_SANITIZE_STRING);
$_GET = filter_input_array(INPUT_GET, FILTER_SANITIZE_FULL_SPECIAL_CHARS) ?: [];
$_POST = filter_input_array(INPUT_POST, FILTER_SANITIZE_FULL_SPECIAL_CHARS) ?: [];
require_once 'scripts/common.php';
$config = get_config();
$site_name = get_sitename();
Expand Down
5 changes: 2 additions & 3 deletions homepage/views.php
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
<?php

/* Prevent XSS input */
$_GET = filter_input_array(INPUT_GET, FILTER_SANITIZE_STRING);
$_POST = filter_input_array(INPUT_POST, FILTER_SANITIZE_STRING);
$_GET = filter_input_array(INPUT_GET, FILTER_SANITIZE_FULL_SPECIAL_CHARS) ?: [];
$_POST = filter_input_array(INPUT_POST, FILTER_SANITIZE_FULL_SPECIAL_CHARS) ?: [];

session_start();

Expand Down
2,407 changes: 1,634 additions & 773 deletions scripts/adminer-de.php

Large diffs are not rendered by default.

2,407 changes: 1,634 additions & 773 deletions scripts/adminer-fr.php

Large diffs are not rendered by default.

2,407 changes: 1,634 additions & 773 deletions scripts/adminer.php

Large diffs are not rendered by default.

60 changes: 30 additions & 30 deletions scripts/advanced.php
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
<?php
ini_set('display_errors', 1);
ini_set('display_errors', 0);
error_reporting(E_ERROR);

require_once "scripts/common.php";
Expand All @@ -23,23 +23,23 @@
$update_caddyfile = false;

if(isset($_GET["caddy_pwd"])) {
$caddy_pwd = $_GET["caddy_pwd"];
$caddy_pwd = conf_safe_string($_GET["caddy_pwd"]);
if(strcmp($caddy_pwd,$config['CADDY_PWD']) !== 0) {
$contents = preg_replace("/CADDY_PWD=.*/", "CADDY_PWD=\"$caddy_pwd\"", $contents);
$update_caddyfile = true;
}
}

if(isset($_GET["ice_pwd"])) {
$ice_pwd = $_GET["ice_pwd"];
$ice_pwd = conf_safe_token($_GET["ice_pwd"]);
if(strcmp($ice_pwd,$config['ICE_PWD']) !== 0) {
$contents = preg_replace("/ICE_PWD=.*/", "ICE_PWD=$ice_pwd", $contents);
$restart_livestream = true;
}
}

if(isset($_GET["birdnetpi_url"])) {
$birdnetpi_url = $_GET["birdnetpi_url"];
$birdnetpi_url = conf_safe_url($_GET["birdnetpi_url"]);
// remove trailing slash to prevent conf from becoming broken
$birdnetpi_url = rtrim($birdnetpi_url, '/');
if(strcmp($birdnetpi_url,$config['BIRDNETPI_URL']) !== 0) {
Expand All @@ -49,15 +49,15 @@
}

if(isset($_GET["rtsp_stream"])) {
$rtsp_stream = str_replace("\r\n", ",", $_GET["rtsp_stream"]);
$rtsp_stream = conf_safe_string(str_replace("\r\n", ",", $_GET["rtsp_stream"]));
if(strcmp($rtsp_stream,$config['RTSP_STREAM']) !== 0) {
$contents = preg_replace("/RTSP_STREAM=.*/", "RTSP_STREAM=\"$rtsp_stream\"", $contents);
$restart_livestream = True;
}
}

if (isset($_GET["rtsp_stream_to_livestream"])) {
$rtsp_stream_selected = trim($_GET["rtsp_stream_to_livestream"]);
$rtsp_stream_selected = conf_safe_string($_GET["rtsp_stream_to_livestream"]);

//Setting exists already, see if the value changed
if (strcmp($rtsp_stream_selected, $config['RTSP_STREAM_TO_LIVESTREAM']) !== 0) {
Expand All @@ -67,7 +67,7 @@
}

if (isset($_GET["activate_freqshift_in_livestream"])) {
$activate_freqshift_in_livestream = trim($_GET["activate_freqshift_in_livestream"]);
$activate_freqshift_in_livestream = conf_safe_string($_GET["activate_freqshift_in_livestream"]);

//Setting exists already, see if the value changed
if (strcmp($activate_freqshift_in_livestream, $config['ACTIVATE_FREQSHIFT_IN_LIVESTREAM']) !== 0) {
Expand All @@ -77,119 +77,119 @@
}

if(isset($_GET["overlap"])) {
$overlap = $_GET["overlap"];
$overlap = conf_safe_number($_GET["overlap"], $config['OVERLAP'] ?? '0');
if(strcmp($overlap,$config['OVERLAP']) !== 0) {
$contents = preg_replace("/OVERLAP=.*/", "OVERLAP=$overlap", $contents);
}
}

if(isset($_GET["confidence"])) {
$confidence = $_GET["confidence"];
$confidence = conf_safe_number($_GET["confidence"], $config['CONFIDENCE'] ?? '0');
if(strcmp($confidence,$config['CONFIDENCE']) !== 0) {
$contents = preg_replace("/CONFIDENCE=.*/", "CONFIDENCE=$confidence", $contents);
}
}

if(isset($_GET["sensitivity"])) {
$sensitivity = $_GET["sensitivity"];
$sensitivity = conf_safe_number($_GET["sensitivity"], $config['SENSITIVITY'] ?? '0');
if(strcmp($sensitivity,$config['SENSITIVITY']) !== 0) {
$contents = preg_replace("/SENSITIVITY=.*/", "SENSITIVITY=$sensitivity", $contents);
}
}

if(isset($_GET["freqshift_hi"]) && is_numeric($_GET['freqshift_hi'])) {
$freqshift_hi = $_GET["freqshift_hi"];
$freqshift_hi = conf_safe_number($_GET["freqshift_hi"], $config['FREQSHIFT_HI'] ?? '0');
if(strcmp($freqshift_hi,$config['FREQSHIFT_HI']) !== 0) {
$contents = preg_replace("/FREQSHIFT_HI=.*/", "FREQSHIFT_HI=$freqshift_hi", $contents);
}
}

if(isset($_GET["freqshift_lo"]) && is_numeric($_GET['freqshift_lo'])) {
$freqshift_lo = $_GET["freqshift_lo"];
$freqshift_lo = conf_safe_number($_GET["freqshift_lo"], $config['FREQSHIFT_LO'] ?? '0');
if(strcmp($freqshift_lo,$config['FREQSHIFT_LO']) !== 0) {
$contents = preg_replace("/FREQSHIFT_LO=.*/", "FREQSHIFT_LO=$freqshift_lo", $contents);
}
}

if(isset($_GET["freqshift_pitch"]) && is_numeric($_GET['freqshift_pitch'])) {
$freqshift_pitch = $_GET["freqshift_pitch"];
$freqshift_pitch = conf_safe_number($_GET["freqshift_pitch"], $config['FREQSHIFT_PITCH'] ?? '0');
if(strcmp($freqshift_pitch,$config['FREQSHIFT_PITCH']) !== 0) {
$contents = preg_replace("/FREQSHIFT_PITCH=.*/", "FREQSHIFT_PITCH=$freqshift_pitch", $contents);
}
}

if(isset($_GET["freqshift_tool"])) {
$freqshift_tool = $_GET["freqshift_tool"];
$freqshift_tool = conf_safe_token($_GET["freqshift_tool"]);
if(strcmp($freqshift_tool,$config['FREQSHIFT_TOOL']) !== 0) {
$contents = preg_replace("/FREQSHIFT_TOOL=.*/", "FREQSHIFT_TOOL=$freqshift_tool", $contents);
}
}

if(isset($_GET["freqshift_reconnect_delay"]) && is_numeric($_GET['freqshift_reconnect_delay'])) {
$freqshift_reconnect_delay = $_GET["freqshift_reconnect_delay"];
if(strcmp($freqshift_hi,$config['FREQSHIFT_RECONNECT_DELAY']) !== 0) {
$freqshift_reconnect_delay = conf_safe_number($_GET["freqshift_reconnect_delay"], $config['FREQSHIFT_RECONNECT_DELAY'] ?? '0');
if(strcmp($freqshift_reconnect_delay,$config['FREQSHIFT_RECONNECT_DELAY']) !== 0) {
$contents = preg_replace("/FREQSHIFT_RECONNECT_DELAY=.*/", "FREQSHIFT_RECONNECT_DELAY=$freqshift_reconnect_delay", $contents);
}
}

if(isset($_GET["full_disk"])) {
$full_disk = $_GET["full_disk"];
$full_disk = conf_safe_token($_GET["full_disk"]);
if(strcmp($full_disk,$config['FULL_DISK']) !== 0) {
$contents = preg_replace("/FULL_DISK=.*/", "FULL_DISK=$full_disk", $contents);
}
}

if (isset($_GET["purge_threshold"])) {
$purge_threshold = $_GET["purge_threshold"];
$purge_threshold = conf_safe_number($_GET["purge_threshold"], $config['PURGE_THRESHOLD'] ?? '0');
if (strcmp($purge_threshold, $config['PURGE_THRESHOLD']) !== 0) {
$contents = preg_replace("/PURGE_THRESHOLD=.*/", "PURGE_THRESHOLD=$purge_threshold", $contents);
}
}

if (isset($_GET["max_files_species"])) {
$max_files_species = $_GET["max_files_species"];
$max_files_species = conf_safe_number($_GET["max_files_species"], $config['MAX_FILES_SPECIES'] ?? '0');
if (strcmp($max_files_species, $config['MAX_FILES_SPECIES']) !== 0) {
$contents = preg_replace("/MAX_FILES_SPECIES=.*/", "MAX_FILES_SPECIES=$max_files_species", $contents);
}
}

if(isset($_GET["privacy_threshold"])) {
$privacy_threshold = $_GET["privacy_threshold"];
$privacy_threshold = conf_safe_number($_GET["privacy_threshold"], $config['PRIVACY_THRESHOLD'] ?? '0');
if(strcmp($privacy_threshold,$config['PRIVACY_THRESHOLD']) !== 0) {
$contents = preg_replace("/PRIVACY_THRESHOLD=.*/", "PRIVACY_THRESHOLD=$privacy_threshold", $contents);
}
}

if(isset($_GET["rec_card"])) {
$rec_card = $_GET["rec_card"];
$rec_card = conf_safe_device($_GET["rec_card"]);
if(strcmp($rec_card,$config['REC_CARD']) !== 0) {
$contents = preg_replace("/REC_CARD=.*/", "REC_CARD=\"$rec_card\"", $contents);
}
}

if(isset($_GET["channels"])) {
$channels = $_GET["channels"];
$channels = conf_safe_number($_GET["channels"], $config['CHANNELS'] ?? '0');
if(strcmp($channels,$config['CHANNELS']) !== 0) {
$contents = preg_replace("/CHANNELS=.*/", "CHANNELS=$channels", $contents);
}
}

if(isset($_GET["recording_length"])) {
$recording_length = $_GET["recording_length"];
$recording_length = conf_safe_number($_GET["recording_length"], $config['RECORDING_LENGTH'] ?? '0');
if(strcmp($recording_length,$config['RECORDING_LENGTH']) !== 0) {
$contents = preg_replace("/RECORDING_LENGTH=.*/", "RECORDING_LENGTH=$recording_length", $contents);
}
}

if(isset($_GET["extraction_length"])) {
$extraction_length = $_GET["extraction_length"];
$extraction_length = conf_safe_number($_GET["extraction_length"], $config['EXTRACTION_LENGTH'] ?? '0');
if(strcmp($extraction_length,$config['EXTRACTION_LENGTH']) !== 0) {
$contents = preg_replace("/EXTRACTION_LENGTH=.*/", "EXTRACTION_LENGTH=$extraction_length", $contents);
}
}

if(isset($_GET["audiofmt"])) {
$audiofmt = $_GET["audiofmt"];
$audiofmt = conf_safe_token($_GET["audiofmt"]);
if(strcmp($audiofmt,$config['AUDIOFMT']) !== 0) {
$contents = preg_replace("/AUDIOFMT=.*/", "AUDIOFMT=$audiofmt", $contents);
}
Expand All @@ -214,15 +214,15 @@

if(isset($_GET["raw_spectrogram"])) {
$raw_spectrogram = 1;
if(strcmp($RAW_SPECTROGRAM,$config['RAW_SPECTROGRAM']) !== 0) {
if(strcmp($raw_spectrogram,$config['RAW_SPECTROGRAM']) !== 0) {
$contents = preg_replace("/RAW_SPECTROGRAM=.*/", "RAW_SPECTROGRAM=$raw_spectrogram", $contents);
}
} else {
$contents = preg_replace("/RAW_SPECTROGRAM=.*/", "RAW_SPECTROGRAM=0", $contents);
}

if(isset($_GET["rare_species_threshold"])) {
$rare_species_threshold = $_GET["rare_species_threshold"];
$rare_species_threshold = conf_safe_number($_GET["rare_species_threshold"], $config['RARE_SPECIES_THRESHOLD'] ?? '0');
if(strcmp($rare_species_threshold, $config['RARE_SPECIES_THRESHOLD']) !== 0) {
$contents = preg_replace("/RARE_SPECIES_THRESHOLD=.*/", "RARE_SPECIES_THRESHOLD=$rare_species_threshold", $contents);
}
Expand All @@ -231,14 +231,14 @@
}

if(isset($_GET["custom_image"])) {
$custom_image = $_GET["custom_image"];
$custom_image = conf_safe_string($_GET["custom_image"]);
if(strcmp($custom_image,$config['CUSTOM_IMAGE']) !== 0) {
$contents = preg_replace("/CUSTOM_IMAGE=.*/", "CUSTOM_IMAGE=$custom_image", $contents);
$contents = preg_replace("/CUSTOM_IMAGE=.*/", "CUSTOM_IMAGE=\"$custom_image\"", $contents);
}
}

if(isset($_GET["custom_image_label"])) {
$custom_image_label = $_GET["custom_image_label"];
$custom_image_label = conf_safe_string($_GET["custom_image_label"]);
if(strcmp($custom_image_label,$config['CUSTOM_IMAGE_TITLE']) !== 0) {
$contents = preg_replace("/CUSTOM_IMAGE_TITLE=.*/", "CUSTOM_IMAGE_TITLE=\"$custom_image_label\"", $contents);
}
Expand Down
23 changes: 22 additions & 1 deletion scripts/api.php
Original file line number Diff line number Diff line change
Expand Up @@ -11,13 +11,34 @@
sendResponse405();
}

function api_is_local() {
$ip = $_SERVER['REMOTE_ADDR'] ?? '';
return $ip === '127.0.0.1' || $ip === '::1' || $ip === '::ffff:127.0.0.1';
}

if (preg_match('#^/api/v1/image/(\S+)$#', $requestUri, $matches)) {
if (!api_is_local() && !is_authenticated()) {
http_response_code(401);
header('WWW-Authenticate: Basic realm="BirdNET-Pi"');
echo json_encode(["message" => "Unauthorized"]);
exit;
}
if (empty($config["IMAGE_PROVIDER"])) {
http_response_code(404);
echo "Error 404! Image provider disabled.";
exit;
}
$sci_name = urldecode($matches[1]);
if (!preg_match('/^[A-Za-z .\'-]{1,64}$/', $sci_name)) {
http_response_code(400);
echo "Error 400! Invalid species name.";
exit;
}
if ($config["IMAGE_PROVIDER"] === 'FLICKR') {
$image_provider = new Flickr();
} else {
$image_provider = new Wikipedia();
}
$sci_name = urldecode($matches[1]);
$result = $image_provider->get_image($sci_name);

if ($result == false) {
Expand Down
50 changes: 31 additions & 19 deletions scripts/birdnet_analysis.py
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
from inotify.constants import IN_CLOSE_WRITE

from utils.analysis import load_global_model, run_analysis
from utils.helpers import get_settings, get_wav_files, ANALYZING_NOW
from utils.helpers import get_settings, get_wav_files, get_analyzing_now_path
from utils.classes import ParseFileName
from utils.reporting import extract_detection, summary, write_to_file, write_to_db, apprise, bird_weather, heartbeat, \
update_json_file
Expand All @@ -36,7 +36,7 @@ def main():

backlog = get_wav_files()

report_queue = Queue()
report_queue = Queue(maxsize=1)
thread = threading.Thread(target=handle_reporting_queue, args=(report_queue, ))
thread.start()

Expand Down Expand Up @@ -81,23 +81,26 @@ def main():


def process_file(file_name, report_queue):
enqueued = False
try:
if os.path.getsize(file_name) == 0:
os.remove(file_name)
return
log.info('Analyzing %s', file_name)
with open(ANALYZING_NOW, 'w') as analyzing:
with open(get_analyzing_now_path(), 'w') as analyzing:
analyzing.write(file_name)
file = ParseFileName(file_name)
detections = run_analysis(file)
# we join() to make sure te reporting queue does not get behind
if not report_queue.empty():
log.warning('reporting queue not yet empty')
report_queue.join()
report_queue.put((file, detections))
except BaseException as e:
enqueued = True
except Exception as e:
stderr = e.stderr.decode('utf-8') if isinstance(e, CalledProcessError) else ""
log.exception(f'Unexpected error: {stderr}', exc_info=e)
finally:
if not enqueued:
try:
os.remove(file_name)
except OSError:
pass


def handle_reporting_queue(queue):
Expand All @@ -110,20 +113,29 @@ def handle_reporting_queue(queue):
file, detections = msg
try:
update_json_file(file, detections)
reported = []
for detection in detections:
detection.file_name_extr = extract_detection(file, detection)
log.info('%s;%s', summary(file, detection), os.path.basename(detection.file_name_extr))
write_to_file(file, detection)
write_to_db(file, detection)
apprise(file, detections)
bird_weather(file, detections)
try:
detection.file_name_extr = extract_detection(file, detection)
log.info('%s;%s', summary(file, detection), os.path.basename(detection.file_name_extr))
write_to_file(file, detection)
write_to_db(file, detection)
reported.append(detection)
except Exception as e:
log.exception('dropping detection %s', detection.common_name, exc_info=e)
if reported:
apprise(file, reported)
bird_weather(file, reported)
heartbeat()
os.remove(file.file_name)
except BaseException as e:
except Exception as e:
stderr = e.stderr.decode('utf-8') if isinstance(e, CalledProcessError) else ""
log.exception(f'Unexpected error: {stderr}', exc_info=e)

queue.task_done()
finally:
try:
os.remove(file.file_name)
except OSError:
pass
queue.task_done()

# mark the 'None' signal as processed
queue.task_done()
Expand Down
Loading