ChordFlask is a local-first trusted-user application. It is designed for a
single user on a trusted machine. The server binds to loopback (127.0.0.1) by
default.
- ChordFlask has no authentication, no TLS, and no CSRF protection.
- ChordFlask must not be exposed to untrusted networks, the public internet, or multi-user environments without explicit hardening.
- LAN exposure is opt-in only and remains restricted to configured media roots on a trusted network. Even then, ChordFlask provides no authentication.
Only the latest main revision or latest published release is supported.
If you discover a security issue, please report it privately to the maintainer
at git@isarlab.de.
Do not open a public issue.
- Describe the issue, affected components, and reproduction steps.
- The maintainer will acknowledge within 5 business days.
- A fix will be prepared and released before public disclosure.
- Non-loopback operation requires explicitly configured media roots, and the app rejects traversal outside them. Loopback-only trusted-user operation may browse other locally readable directories for compatibility.
- The web directory browser starts at the local user's home directory on loopback. On non-loopback listeners it exposes only configured media roots and hides parent navigation at each boundary.
- Flask debug mode is disabled by default and is rejected on non-loopback listeners even when explicitly requested.
- File-system operations resolve paths with
Path.resolve()and validate containment. - The queue persists to the user's home directory (
~/.chordflask/) with file locking and atomic writes. - No credentials, secrets, or authentication tokens are stored or transmitted.
chordflask-genlyricsis an explicitly invoked external-runtime CLI that makes HTTPS requests to LRCLIB, sending the song lookup metadata or search terms required for matching. It does not upload media files or ChordFlask analysis data. Normal playback and analysis do not use LRCLIB. A desktop source or standalone Prepare action can invoke the helper only when that external Lyrics runtime is installed.
Non-loopback listening requires at least one allowed media root:
chordflask --listen 0.0.0.0 --roots "/home/user/Music"Separate multiple roots with the platform path separator (: on Linux/macOS,
; on Windows):
chordflask --listen 0.0.0.0 \
--roots "/home/user/Music:/mnt/media/videos"Scripts and services may set CHORDFLASK_MEDIA_ROOTS; the legacy
CHORDIFIER_MEDIA_ROOTS name remains accepted for compatibility. The
command-line --roots option takes precedence over both. Only media below the
resolved roots is served on a non-loopback listener; the home directory or
whole filesystem is not added automatically.
Vamp plugins and FFmpeg are external runtimes with their own security postures.
See THIRD_PARTY_NOTICES.md for provenance and licensing.