TypeScript:
- menu_ts.ts split into menu.ts, content.ts, popup.ts and xmltv.ts; the
other files drop their _ts suffix. Bundle order fixed in ts/tsconfig.json.
- All 94 string event handlers (setAttribute("onclick", "javascript: ..."))
replaced with addEventListener closures. changeButtonAction, which
rewrote an onclick attribute from select values, is gone.
- Settings rows are generated from one SETTINGS_FIELDS table instead of
~20 copy-pasted blocks; rendered HTML is byte-identical to before.
saveSettings now serialises password inputs, so a changed Plex token is
actually sent (the server treats the mask as unchanged).
- createLayout rebuilds the menu list only when the set of visible items
changes, so focus in the menu survives a refresh.
- announce()/alertUser(): alerts are mirrored into an aria-live region.
- Filter popup offers a third type, Regular Expression (regex-filter), and
the filter table labels it. Playlist popups get a Buffer select
(default / none / xTeVe / FFmpeg / VLC) saved as the playlist's
"buffer" parameter; the tuner field stays editable when the
playlist's own buffer is active.
Tests: tests/ holds 27 jsdom tests (Node's built-in runner, jsdom pinned)
that load the built bundle with a fixture server payload: menu visibility
rules, mapping table renders names as text, settings panel fields, popup
flows, sorting, bulk select, layout refresh keeps nodes, live region,
regex option, buffer select. npm test runs in the Drone webui-check step.
README-DEV documents the layout and the test workflow.
- html/css split into tokens.css (custom properties), base.css (reset,
typography, focus, skip link), components.css (buttons, inputs, tables,
status cards, popups, menu, log lines) and layout.css (shell, sidebar,
header, breakpoints); screen.css removed. Selectors and declarations
moved as-is; three pairs of conflicting rules resolved in favour of the
one that already won the cascade, two empty rules dropped.
- Every literal colour outside tokens.css is now a token (category badge
borders excepted). color-scheme set so native controls follow.
- Light theme under prefers-color-scheme: light, with explicit
data-theme="light"/"dark" overrides on :root for a future toggle.
Body text 13.6:1, muted text 5.4:1, accent 5.1:1 on the light background.
- HTML: lang="en" everywhere, one h1 per page, maintenance page uses
<main>, an id typo fixed.
- .drone.yml: two command strings contained ": " and were parsed as maps
by Drone's YAML loader ("cannot unmarshal !!map into string"). Quoted.
- Filters: new type "regex-filter". The rule is a Go regular expression
tried against the channel name, the group title and the raw attribute
line; case-insensitive unless the filter is marked case sensitive.
Patterns are validated when the filter is saved and when rules are
rebuilt, and compiled once (cached). The two fixed {include}/!{exclude}
patterns are compiled at package level instead of per stream.
- Per-playlist buffer: a playlist's "buffer" parameter ("-", "xteve",
"ffmpeg", "vlc") overrides the global setting for that playlist in
the stream handler, the buffer start, the tuner lookup and the external
process buffer. Anything else falls back to the global setting.
(UI controls for both follow with the Phase 5 frontend work.)
- Tests: TestRegexFilter, TestBufferModeFor.
Client (ts/network_ts.ts): one WebSocket per page. Commands queue and go
out one at a time with a client-chosen id; the response is matched on the
echoed id (or to the in-flight request for older servers). 12 s timeout
per request, exponential-backoff reconnect (0.5 s to 10 s), the in-flight
request is retried after a reconnect, and log polls are de-duplicated so
they cannot pile up behind a stalled connection. The old global flag that
silently dropped any request made while another was in flight is gone.
Server (src/webserver.go): the /data/ handler now serves any number of
commands on one connection (it used to break out of its loop after the
first reply without closing the socket, leaving it open and deaf; the old
client papered over that by opening a new socket per request). Connection
closed on exit, request id echoed in the response.
Test: TestWSServesMultipleCommandsPerConnection.
- http.Server with ReadHeaderTimeout/IdleTimeout (no read/write timeouts: /stream/ is long-lived)
- shared outbound clients: providerHTTPClient (5m), apiHTTPClient (30s), imgcache client (30s)
- imgcache: download outside the lock, per-item helper, cache URL uses the file name not the fs path
- writeFileAtomic (temp + fsync + rename) for settings/xepg/pms/urls/authentication JSON
- one package-level logMu for WebScreenLog and notifications; ring buffer keeps the newest lines
- notifications evict the oldest instead of random map entries
- xepg XMLTV file removal rebuilt after the loop; data.go range-mutation removed
- API handler returns after error body; WS request/response fresh per command
- checked type assertions in data/backup/provider/screen
- SIGINT/SIGTERM handled in main via src.Shutdown(); fatal paths exit 1
- src/buffer_state.go replaces the two sync.Maps plus a global RWMutex with
one bufferMu guarding a map of *Playlist. Each stream has one shared
bufferStream (URL, folder, status, client count, error, cancel hook);
downloaders keep a private ThisStream and publish through helpers.
Playlist.Clients / ThisClient / ClientConnection are gone: there was one
client counter per stream in two places that could disagree.
- bufferAcquireStream does the tuner check and the registration under the
same lock, so two clients tuning at once cannot both pass the limit.
bufferReleaseClient removes the stream when the last client leaves,
cancels its process and deletes its segment folder.
- bufferingStream rewritten: waits on r.Context() instead of the deprecated
CloseNotifier, sets Content-Type before WriteHeader (the old code set
headers after and one was literally named "Content-Length:"), flushes
each segment to the client, no defer inside the segment loop.
- connectToStreamingServer: shared streamHTTPClient with dial, TLS and
response-header timeouts (no overall timeout, bodies are endless); the
deferred Body/segment closes inside the redirect and read loops are now
explicit closes, so a multi-hour stream no longer accumulates them.
- thirdPartyBuffer rewritten around exec.CommandContext: the process is
killed when the last client leaves or when no usable data arrives within
20 s (time.AfterFunc watchdog, no leaked goroutine); cmd.Start error is
checked; no panic; one file handle per segment. ffmpeg and VLC command
lines come from buildFFmpegArgs / buildVLCArgs, which are unit tested.
- Data.Cache.StreamingURLS is guarded by streamingURLsMu and persisted
from a snapshot.
- Tests (src/buffer_test.go, run with -race): restream shares one provider
connection, six concurrent tunes against a tuner limit of two, 50-way
acquire/release contention, cleanup and cancel on last release.
Input handling:
- uploadLogo: client file name reduced to a safe base name with an image
extension (path traversal and arbitrary-extension writes closed).
- extractZIP: zip-slip guard; entries that resolve outside the target are
refused. Per-entry closes no longer pile up as defers.
- ffmpeg.path / vlc.path must be an existing regular file named ffmpeg,
vlc or cvlc, checked both when saved and right before exec.
- Stream URLs passed to the external buffer must use a network scheme
(http, https, rtsp, rtmp, rtp, udp, mms); file:, concat:, pipe: are
refused.
- /download/ (backups with settings.json and authentication.json) requires
the web session when web authentication is enabled.
- settings.json is written 0600; the Plex token is masked in every payload
sent to the UI and the mask round-trips as "unchanged" on save.
Authentication:
- Passwords are stored with bcrypt. Existing HMAC-SHA256 records still
verify (constant time) and are re-hashed on the first successful login.
Username lookups compare in constant time.
- URL (?username=&password=) and HTTP Basic authentication verify the
credentials per request via AuthenticateUser and no longer create a
session token, which removes the unbounded token growth under Plex
polling. Expired sessions are evicted whenever a new one is created.
- createFirstUserForAuthentication and checkAuthorizationLevel now return
real errors instead of calling no-op closures.
Tests: src/security_test.go and src/internal/authentication/
authentication_test.go cover each of the above.
- Provider-controlled strings (channel names, groups, file names, log
lines, in-place mapping edits, client info) are rendered with
textContent instead of innerHTML. PopupContent.description() takes an
explicit isHTML flag that only the static help texts pass.
- Websocket: drop the always-true CheckOrigin so gorilla's same-origin
check applies; read the session token from the HttpOnly cookie sent with
the handshake (the ?Token= query parameter is still accepted for older
clients); the client no longer puts the token in the URL, rewrites the
cookie, or console-logs request/response payloads.
- Session cookie is HttpOnly, SameSite=Strict, Path=/, session-scoped
(expiry stays server side) and is cleared on logout.
- Serving the first-run wizard no longer sets Settings.AuthenticationWEB
to false; the wizard page simply bypasses login while it is active.
- Upgrade failures no longer write a second error response.
- Tests: src/websocket_test.go covers cross-origin refusal, same-origin
and no-Origin clients, missing/unknown/legacy tokens, and cookie flags.
Go:
- staticcheck 399 -> 0 with staticcheck.conf (style checks ST1000/1003/
1005/1016/1020/1021/1022 excluded; error strings are shown in the UI).
- io/ioutil and rand.Seed removed; CloseNotifier kept with a lint-ignore
until the Phase 2 context rewrite.
- Dead code deleted: Auto handler, getStreamByChannelID, updateXEPG,
indexOfInt, jsonToMapInt64, removeOldSystemData, randomTime, and the
commented-out blocks in struct-buffer.go and internal/authentication.
- Duplicates folded: cacheImagesInBackground(), one addErrorToStream().
- Bugs found by SA4006/SA5001: os.Create handle leaked per ffmpeg segment
(buffer.go), http.NewRequest error unchecked (buffer.go), xepg.json
migration wrote null on read error (migrate.go), WriteUserData errors
silently dropped (authentication.go), defer Close before error check
(buffer.go, toolchain.go). checkFilePermission results were discarded;
an unwritable config or temp dir is now fatal at start-up.
- gofmt applied repo-wide; Drone runs gofmt check and staticcheck.
Docker:
- Entrypoint starts as root, applies PUID/PGID (falls back to XTEVE_UID/
XTEVE_GID, then image defaults), fixes config ownership only when it
differs, then drops to xteve via su-exec. --user starts skip all of it.
- /xteve removed from LEGACY_CONFIG_DIRS (it is the parent of the default).
- mwader/static-ffmpeg pinned to 7.1.1; VOLUME /xteve/config.
- Compose files pull registry.coadcorp.com/nathan/xteve:latest, use
PUID/PGID/TZ, and explain that SSDP needs host networking.
- .dockerignore excludes the npm toolchain (bundle stays in html/js).
Docs: README rewritten for the fork (about, registry, compose, env vars,
security notes); README-DEV gains a container section.
- html/embed.go embeds html/ (pages, css, img, js, video); src/assets.go
serves it, with os.DirFS("html") under -dev. Static assets get an ETag
and Cache-Control: no-cache; HTML pages are still templated (only the
login error message is substituted now).
- Delete the generated src/webUI.go (783 KB base64), src/html-build.go and
cmd/webui-gen; Dockerfile no longer runs a generator.
- Language layer removed: 254 {{.x}} placeholders inlined as English
strings in ts/*.ts and the two auth pages; html/lang/en.json, the
LanguageUI struct and the 'language' setting are gone.
- ts/tsconfig.json + package.json pin typescript 5.9.3; the seven sources
compile (ES2020, global scripts) into one committed html/js/app.js.
Ten unreferenced legacy scripts under html/js/ deleted; all pages load
js/app.js.
- Fix the six type errors that blocked a clean compile, including a real
bug: a missing semicolon in the search shortcut handler made the code
call the result of preventDefault(), so the shortcut threw instead of
focusing the search box.
- /healthz liveness endpoint; Dockerfile healthcheck and README use it.
- Drone: go vet, and a webui-check step that rebuilds the bundle and fails
if the committed app.js is stale.
- README-DEV.md documents build, UI toolchain, -dev, versioning, CI.
- Delete BinaryUpdate, internal/up2date, GitHub/Update structs and the
xteveAutoUpdate / update.url settings (UI rows, en.json, defaults).
Settings-schema migrations kept and moved to src/migrate.go.
- Drop kardianos/osext dependency.
- xteve.go version 0200 -> 0201 to match changelog; Drone now fails on drift.
- go.mod go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1.
- Fix four go vet unreachable-code warnings.
- .gitignore: .gocache/, agent.md, skill.md. .dockerignore: build context
no longer includes caches, ts/, tasks/ or markdown except the changelog.
- Drone: publish :latest only from master; other branches publish a
branch-named tag so a feature push cannot replace the deployed image.
- Add tasks/improvement-plan.md and tasks/todo.md.
- Regenerate src/webUI.go.