Commit Graph
85 Commits
Author SHA1 Message Date
nathan 0b7a54d7da Fix Drone YAML, add regex filters and per-playlist buffer mode (backend)
continuous-integration/drone/push Build is passing
- .drone.yml: two command strings contained ": " and were parsed as maps
  by Drone's YAML loader ("cannot unmarshal !!map into string"). Quoted.
- Filters: new type "regex-filter". The rule is a Go regular expression
  tried against the channel name, the group title and the raw attribute
  line; case-insensitive unless the filter is marked case sensitive.
  Patterns are validated when the filter is saved and when rules are
  rebuilt, and compiled once (cached). The two fixed {include}/!{exclude}
  patterns are compiled at package level instead of per stream.
- Per-playlist buffer: a playlist's "buffer" parameter ("-", "xteve",
  "ffmpeg", "vlc") overrides the global setting for that playlist in
  the stream handler, the buffer start, the tuner lookup and the external
  process buffer. Anything else falls back to the global setting.
  (UI controls for both follow with the Phase 5 frontend work.)
- Tests: TestRegexFilter, TestBufferModeFor.
2026-09-26 13:24:11 +10:00
nathan 3a3ba861dc Phase 5a: persistent websocket with request ids and reconnect
continuous-integration/drone/push Build encountered an error
Client (ts/network_ts.ts): one WebSocket per page. Commands queue and go
out one at a time with a client-chosen id; the response is matched on the
echoed id (or to the in-flight request for older servers). 12 s timeout
per request, exponential-backoff reconnect (0.5 s to 10 s), the in-flight
request is retried after a reconnect, and log polls are de-duplicated so
they cannot pile up behind a stalled connection. The old global flag that
silently dropped any request made while another was in flight is gone.

Server (src/webserver.go): the /data/ handler now serves any number of
commands on one connection (it used to break out of its loop after the
first reply without closing the socket, leaving it open and deaf; the old
client papered over that by opening a new socket per request). Connection
closed on exit, request id echoed in the response.

Test: TestWSServesMultipleCommandsPerConnection.
2026-09-26 13:19:38 +10:00
nathan cbc5bc5da2 Merge branch 'worktree-agent-a93010566d356e58c' into improvements 2026-09-26 13:18:03 +10:00
nathan 3bbea8e952 Phase 2b: server/client timeouts, atomic state writes, log mutex, panic and shutdown fixes
- http.Server with ReadHeaderTimeout/IdleTimeout (no read/write timeouts: /stream/ is long-lived)
- shared outbound clients: providerHTTPClient (5m), apiHTTPClient (30s), imgcache client (30s)
- imgcache: download outside the lock, per-item helper, cache URL uses the file name not the fs path
- writeFileAtomic (temp + fsync + rename) for settings/xepg/pms/urls/authentication JSON
- one package-level logMu for WebScreenLog and notifications; ring buffer keeps the newest lines
- notifications evict the oldest instead of random map entries
- xepg XMLTV file removal rebuilt after the loop; data.go range-mutation removed
- API handler returns after error body; WS request/response fresh per command
- checked type assertions in data/backup/provider/screen
- SIGINT/SIGTERM handled in main via src.Shutdown(); fatal paths exit 1
2026-09-26 13:17:07 +10:00
nathan 320eaa1b28 Phase 2a: buffer state under one lock, atomic tuner limit, context-driven external buffer
continuous-integration/drone/push Build encountered an error
- src/buffer_state.go replaces the two sync.Maps plus a global RWMutex with
  one bufferMu guarding a map of *Playlist. Each stream has one shared
  bufferStream (URL, folder, status, client count, error, cancel hook);
  downloaders keep a private ThisStream and publish through helpers.
  Playlist.Clients / ThisClient / ClientConnection are gone: there was one
  client counter per stream in two places that could disagree.
- bufferAcquireStream does the tuner check and the registration under the
  same lock, so two clients tuning at once cannot both pass the limit.
  bufferReleaseClient removes the stream when the last client leaves,
  cancels its process and deletes its segment folder.
- bufferingStream rewritten: waits on r.Context() instead of the deprecated
  CloseNotifier, sets Content-Type before WriteHeader (the old code set
  headers after and one was literally named "Content-Length:"), flushes
  each segment to the client, no defer inside the segment loop.
- connectToStreamingServer: shared streamHTTPClient with dial, TLS and
  response-header timeouts (no overall timeout, bodies are endless); the
  deferred Body/segment closes inside the redirect and read loops are now
  explicit closes, so a multi-hour stream no longer accumulates them.
- thirdPartyBuffer rewritten around exec.CommandContext: the process is
  killed when the last client leaves or when no usable data arrives within
  20 s (time.AfterFunc watchdog, no leaked goroutine); cmd.Start error is
  checked; no panic; one file handle per segment. ffmpeg and VLC command
  lines come from buildFFmpegArgs / buildVLCArgs, which are unit tested.
- Data.Cache.StreamingURLS is guarded by streamingURLsMu and persisted
  from a snapshot.
- Tests (src/buffer_test.go, run with -race): restream shares one provider
  connection, six concurrent tunes against a tuner limit of two, 50-way
  acquire/release contention, cleanup and cancel on last release.
2026-09-26 13:14:48 +10:00
nathan 36303fecea Phase 1b/1c: server-side input handling and authentication
continuous-integration/drone/push Build encountered an error
Input handling:
- uploadLogo: client file name reduced to a safe base name with an image
  extension (path traversal and arbitrary-extension writes closed).
- extractZIP: zip-slip guard; entries that resolve outside the target are
  refused. Per-entry closes no longer pile up as defers.
- ffmpeg.path / vlc.path must be an existing regular file named ffmpeg,
  vlc or cvlc, checked both when saved and right before exec.
- Stream URLs passed to the external buffer must use a network scheme
  (http, https, rtsp, rtmp, rtp, udp, mms); file:, concat:, pipe: are
  refused.
- /download/ (backups with settings.json and authentication.json) requires
  the web session when web authentication is enabled.
- settings.json is written 0600; the Plex token is masked in every payload
  sent to the UI and the mask round-trips as "unchanged" on save.

Authentication:
- Passwords are stored with bcrypt. Existing HMAC-SHA256 records still
  verify (constant time) and are re-hashed on the first successful login.
  Username lookups compare in constant time.
- URL (?username=&password=) and HTTP Basic authentication verify the
  credentials per request via AuthenticateUser and no longer create a
  session token, which removes the unbounded token growth under Plex
  polling. Expired sessions are evicted whenever a new one is created.
- createFirstUserForAuthentication and checkAuthorizationLevel now return
  real errors instead of calling no-op closures.

Tests: src/security_test.go and src/internal/authentication/
authentication_test.go cover each of the above.
2026-09-26 13:04:54 +10:00
nathan 4976219857 Phase 1a: browser-side security
continuous-integration/drone/push Build encountered an error
- Provider-controlled strings (channel names, groups, file names, log
  lines, in-place mapping edits, client info) are rendered with
  textContent instead of innerHTML. PopupContent.description() takes an
  explicit isHTML flag that only the static help texts pass.
- Websocket: drop the always-true CheckOrigin so gorilla's same-origin
  check applies; read the session token from the HttpOnly cookie sent with
  the handshake (the ?Token= query parameter is still accepted for older
  clients); the client no longer puts the token in the URL, rewrites the
  cookie, or console-logs request/response payloads.
- Session cookie is HttpOnly, SameSite=Strict, Path=/, session-scoped
  (expiry stays server side) and is cleared on logout.
- Serving the first-run wizard no longer sets Settings.AuthenticationWEB
  to false; the wizard page simply bypasses login while it is active.
- Upgrade failures no longer write a second error response.
- Tests: src/websocket_test.go covers cross-origin refusal, same-origin
  and no-Origin clients, missing/unknown/legacy tokens, and cookie flags.
2026-09-26 12:59:47 +10:00
nathan 504ea3f9f4 Phase 3: Go hygiene pass, runtime PUID/PGID, fork README
continuous-integration/drone/push Build encountered an error
Go:
- staticcheck 399 -> 0 with staticcheck.conf (style checks ST1000/1003/
  1005/1016/1020/1021/1022 excluded; error strings are shown in the UI).
- io/ioutil and rand.Seed removed; CloseNotifier kept with a lint-ignore
  until the Phase 2 context rewrite.
- Dead code deleted: Auto handler, getStreamByChannelID, updateXEPG,
  indexOfInt, jsonToMapInt64, removeOldSystemData, randomTime, and the
  commented-out blocks in struct-buffer.go and internal/authentication.
- Duplicates folded: cacheImagesInBackground(), one addErrorToStream().
- Bugs found by SA4006/SA5001: os.Create handle leaked per ffmpeg segment
  (buffer.go), http.NewRequest error unchecked (buffer.go), xepg.json
  migration wrote null on read error (migrate.go), WriteUserData errors
  silently dropped (authentication.go), defer Close before error check
  (buffer.go, toolchain.go). checkFilePermission results were discarded;
  an unwritable config or temp dir is now fatal at start-up.
- gofmt applied repo-wide; Drone runs gofmt check and staticcheck.

Docker:
- Entrypoint starts as root, applies PUID/PGID (falls back to XTEVE_UID/
  XTEVE_GID, then image defaults), fixes config ownership only when it
  differs, then drops to xteve via su-exec. --user starts skip all of it.
- /xteve removed from LEGACY_CONFIG_DIRS (it is the parent of the default).
- mwader/static-ffmpeg pinned to 7.1.1; VOLUME /xteve/config.
- Compose files pull registry.coadcorp.com/nathan/xteve:latest, use
  PUID/PGID/TZ, and explain that SSDP needs host networking.
- .dockerignore excludes the npm toolchain (bundle stays in html/js).

Docs: README rewritten for the fork (about, registry, compose, env vars,
security notes); README-DEV gains a container section.
2026-09-26 12:57:43 +10:00
nathan ddc70e170a Phase 3: embed web UI with go:embed, pinned TypeScript toolchain, drop i18n, add /healthz
continuous-integration/drone/push Build encountered an error
- html/embed.go embeds html/ (pages, css, img, js, video); src/assets.go
  serves it, with os.DirFS("html") under -dev. Static assets get an ETag
  and Cache-Control: no-cache; HTML pages are still templated (only the
  login error message is substituted now).
- Delete the generated src/webUI.go (783 KB base64), src/html-build.go and
  cmd/webui-gen; Dockerfile no longer runs a generator.
- Language layer removed: 254 {{.x}} placeholders inlined as English
  strings in ts/*.ts and the two auth pages; html/lang/en.json, the
  LanguageUI struct and the 'language' setting are gone.
- ts/tsconfig.json + package.json pin typescript 5.9.3; the seven sources
  compile (ES2020, global scripts) into one committed html/js/app.js.
  Ten unreferenced legacy scripts under html/js/ deleted; all pages load
  js/app.js.
- Fix the six type errors that blocked a clean compile, including a real
  bug: a missing semicolon in the search shortcut handler made the code
  call the result of preventDefault(), so the shortcut threw instead of
  focusing the search box.
- /healthz liveness endpoint; Dockerfile healthcheck and README use it.
- Drone: go vet, and a webui-check step that rebuilds the bundle and fails
  if the committed app.js is stale.
- README-DEV.md documents build, UI toolchain, -dev, versioning, CI.
2026-09-26 12:46:45 +10:00
nathan 51c7830067 Phase 0: remove auto-updater, pin Go 1.27.1, fix vet warnings, tidy ignores
continuous-integration/drone/push Build encountered an error
- Delete BinaryUpdate, internal/up2date, GitHub/Update structs and the
  xteveAutoUpdate / update.url settings (UI rows, en.json, defaults).
  Settings-schema migrations kept and moved to src/migrate.go.
- Drop kardianos/osext dependency.
- xteve.go version 0200 -> 0201 to match changelog; Drone now fails on drift.
- go.mod go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1.
- Fix four go vet unreachable-code warnings.
- .gitignore: .gocache/, agent.md, skill.md. .dockerignore: build context
  no longer includes caches, ts/, tasks/ or markdown except the changelog.
- Drone: publish :latest only from master; other branches publish a
  branch-named tag so a feature push cannot replace the deployed image.
- Add tasks/improvement-plan.md and tasks/todo.md.
- Regenerate src/webUI.go.
2026-09-26 12:38:02 +10:00
nathan f558a855ae go fix
continuous-integration/drone/push Build is passing
2026-02-18 15:12:33 +11:00
nathan 125b0bb35f Enhance XEPG channel mapping and settings management
continuous-integration/drone/push Build is passing
2026-02-13 16:09:00 +11:00
nathan 32c3d779c0 add edit button to mapping table and refactor cell creation
continuous-integration/drone/push Build is passing
2026-02-12 13:22:51 +11:00
nathan c577d354e7 Enhance configuration handling and implement wizard completion logic
continuous-integration/drone/push Build is passing
2026-02-11 17:15:54 +11:00
nathan e48a061ca0 Enhance WebSocket handling and log polling logic
continuous-integration/drone/push Build is passing
2026-02-11 16:25:48 +11:00
nathan ffd43d5217 Enhance log display behavior and menu state management
continuous-integration/drone/push Build is passing
2026-02-11 14:37:02 +11:00
nathan 9bd2b32003 Enhance WebSocket connection handling with improved timeout and error states
continuous-integration/drone/push Build is passing
2026-02-11 14:20:24 +11:00
nathan c5545cbf08 go fix for 1.26
continuous-integration/drone/push Build is passing
2026-02-11 12:53:35 +11:00
nathan 339d2d0aa5 include ffmpeg
continuous-integration/drone/push Build is passing
2026-02-11 12:42:01 +11:00
nathan a04b0ede50 fix tmp dir permissions crash
continuous-integration/drone/push Build is passing
2026-02-11 12:29:49 +11:00
nathan 6a8b4bed28 try again
continuous-integration/drone/push Build is failing
2026-02-11 11:56:30 +11:00
nathan 43a9cf5a7e bugfix
continuous-integration/drone/push Build encountered an error
2026-02-11 11:52:34 +11:00
nathan b069d5bee8 many updates 2026-02-11 11:38:26 +11:00
nathan 8cb9e43a72 Redesign UI and add first-party Docker runtime support 2026-02-11 11:04:39 +11:00
xteve-project e44eff0645 Add go.mod and go.sum. Require go v1.16 2021-03-29 19:47:56 +02:00
xteve-project 25bad13800 compile js 2021-01-21 19:50:35 +01:00
xteve-project 014f5b7218 Dummy new times
Fixed searching for XMLTV file (Mapping)
2020-11-20 22:13:52 +01:00
xteve-project 6d890cfd33 Fixed: undefined playlist 2020-10-16 16:43:56 +02:00
marmei 410cc3648f v2.1.2.0128 2020-10-09 13:00:28 +02:00
marmei f43ce0f7c5 Bug fix: Image caching (#172) 2020-10-03 11:56:50 +02:00
marmei db59f7ef37 Add XML tag: rating, credits 2020-09-26 18:35:16 +02:00
marmei d8fc1aea97 Schedule can be deactivated 2020-06-03 23:11:25 +02:00
marmei 38333d65cb Add content type (BUffer): video/x-matroska 2020-05-16 09:21:34 +02:00
marmei a6a9b90937 Merge branch 'pr/136' into beta 2020-05-16 09:19:04 +02:00
Raf a09eca59a7 cleanup channel hash map logic 2020-05-15 11:53:42 -04:00
marmei 0df3b4d755 Merge branch 'pr/136' into beta 2020-05-15 00:20:21 +02:00
marmei 5552514a1f Merge branch 'pr/134' into beta 2020-05-14 23:44:30 +02:00
Raf fb5d0a3904 freenumbergen-start at settings.firstchannel
if free
2020-05-14 09:39:28 -04:00
Raf 28fe4dcf1c Speedup db update for large files 2020-05-14 09:39:28 -04:00
5Ub-Z3r0 67b7ba6df9 Add support for proxying multicast streams through a UDPxy server.
This commit adds support for proxying multicast streams through a UDPxy
server. If the stream is multicast, and a udpxy server is set in the
configuration, then the channel URL is rewritten to use the UDPxy
service configured.

The stream URL rewriting is done regardless of the buffer option set.

Signed-off-by: 5Ub-Z3r0 <1673590+5Ub-Z3r0@users.noreply.github.com>
2020-05-13 21:26:24 +02:00
marmei 534510a4ec Websocket error 2020-03-02 17:03:56 +01:00
marmei dd911d6e5d M3U error message changed 2020-02-19 19:35:41 +01:00
marmei 4fc4330a94 FFmpeg changed: user-agent to user_agent 2020-02-08 11:10:14 +01:00
marmei 4b9f5826cf If no user agent is specified, the default FFmpeg or VLC user agent is used. 2020-01-24 19:48:29 +01:00
marmei 87b36c283b URL format removed from the settings 2020-01-04 17:17:28 +01:00
marmei 6da26ff4fb Merge branch 'pr/76' into beta 2020-01-04 17:01:32 +01:00
marmei cd08985e79 Set global domain for /web 2020-01-04 17:00:58 +01:00
marmei 1cefbf022d Workaround for IPTVX content-type bug 2019-12-28 12:28:33 +01:00
marmei 91b80bc8bb Add xteve.xml GZIP 2019-12-16 20:23:05 +01:00
marmei aa763726a3 Fixed broken merge 2019-12-14 10:17:42 +01:00