Input handling:
- uploadLogo: client file name reduced to a safe base name with an image
extension (path traversal and arbitrary-extension writes closed).
- extractZIP: zip-slip guard; entries that resolve outside the target are
refused. Per-entry closes no longer pile up as defers.
- ffmpeg.path / vlc.path must be an existing regular file named ffmpeg,
vlc or cvlc, checked both when saved and right before exec.
- Stream URLs passed to the external buffer must use a network scheme
(http, https, rtsp, rtmp, rtp, udp, mms); file:, concat:, pipe: are
refused.
- /download/ (backups with settings.json and authentication.json) requires
the web session when web authentication is enabled.
- settings.json is written 0600; the Plex token is masked in every payload
sent to the UI and the mask round-trips as "unchanged" on save.
Authentication:
- Passwords are stored with bcrypt. Existing HMAC-SHA256 records still
verify (constant time) and are re-hashed on the first successful login.
Username lookups compare in constant time.
- URL (?username=&password=) and HTTP Basic authentication verify the
credentials per request via AuthenticateUser and no longer create a
session token, which removes the unbounded token growth under Plex
polling. Expired sessions are evicted whenever a new one is created.
- createFirstUserForAuthentication and checkAuthorizationLevel now return
real errors instead of calling no-op closures.
Tests: src/security_test.go and src/internal/authentication/
authentication_test.go cover each of the above.
Go:
- staticcheck 399 -> 0 with staticcheck.conf (style checks ST1000/1003/
1005/1016/1020/1021/1022 excluded; error strings are shown in the UI).
- io/ioutil and rand.Seed removed; CloseNotifier kept with a lint-ignore
until the Phase 2 context rewrite.
- Dead code deleted: Auto handler, getStreamByChannelID, updateXEPG,
indexOfInt, jsonToMapInt64, removeOldSystemData, randomTime, and the
commented-out blocks in struct-buffer.go and internal/authentication.
- Duplicates folded: cacheImagesInBackground(), one addErrorToStream().
- Bugs found by SA4006/SA5001: os.Create handle leaked per ffmpeg segment
(buffer.go), http.NewRequest error unchecked (buffer.go), xepg.json
migration wrote null on read error (migrate.go), WriteUserData errors
silently dropped (authentication.go), defer Close before error check
(buffer.go, toolchain.go). checkFilePermission results were discarded;
an unwritable config or temp dir is now fatal at start-up.
- gofmt applied repo-wide; Drone runs gofmt check and staticcheck.
Docker:
- Entrypoint starts as root, applies PUID/PGID (falls back to XTEVE_UID/
XTEVE_GID, then image defaults), fixes config ownership only when it
differs, then drops to xteve via su-exec. --user starts skip all of it.
- /xteve removed from LEGACY_CONFIG_DIRS (it is the parent of the default).
- mwader/static-ffmpeg pinned to 7.1.1; VOLUME /xteve/config.
- Compose files pull registry.coadcorp.com/nathan/xteve:latest, use
PUID/PGID/TZ, and explain that SSDP needs host networking.
- .dockerignore excludes the npm toolchain (bundle stays in html/js).
Docs: README rewritten for the fork (about, registry, compose, env vars,
security notes); README-DEV gains a container section.