PhotoPrism CE doesn't enforce auth_users.base_path on API reads (any user can q=path:"other/*"). New /api/v1/* proxy forwards to PhotoPrism with per-session enforcement: search queries get their path filter validated/injected, single-photo reads and like are ownership-checked, hash-addressed media and session/config pass through, everything else is 403 for scoped users. Admins (empty BasePath) pass through fully. prism.hubris.network will route here instead of straight to PhotoPrism. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
5.2 KiB
5.2 KiB