Commit Graph
17 Commits
Author SHA1 Message Date
nathan 4976219857 Phase 1a: browser-side security
continuous-integration/drone/push Build encountered an error
- Provider-controlled strings (channel names, groups, file names, log
  lines, in-place mapping edits, client info) are rendered with
  textContent instead of innerHTML. PopupContent.description() takes an
  explicit isHTML flag that only the static help texts pass.
- Websocket: drop the always-true CheckOrigin so gorilla's same-origin
  check applies; read the session token from the HttpOnly cookie sent with
  the handshake (the ?Token= query parameter is still accepted for older
  clients); the client no longer puts the token in the URL, rewrites the
  cookie, or console-logs request/response payloads.
- Session cookie is HttpOnly, SameSite=Strict, Path=/, session-scoped
  (expiry stays server side) and is cleared on logout.
- Serving the first-run wizard no longer sets Settings.AuthenticationWEB
  to false; the wizard page simply bypasses login while it is active.
- Upgrade failures no longer write a second error response.
- Tests: src/websocket_test.go covers cross-origin refusal, same-origin
  and no-Origin clients, missing/unknown/legacy tokens, and cookie flags.
2026-09-26 12:59:47 +10:00
nathan ddc70e170a Phase 3: embed web UI with go:embed, pinned TypeScript toolchain, drop i18n, add /healthz
continuous-integration/drone/push Build encountered an error
- html/embed.go embeds html/ (pages, css, img, js, video); src/assets.go
  serves it, with os.DirFS("html") under -dev. Static assets get an ETag
  and Cache-Control: no-cache; HTML pages are still templated (only the
  login error message is substituted now).
- Delete the generated src/webUI.go (783 KB base64), src/html-build.go and
  cmd/webui-gen; Dockerfile no longer runs a generator.
- Language layer removed: 254 {{.x}} placeholders inlined as English
  strings in ts/*.ts and the two auth pages; html/lang/en.json, the
  LanguageUI struct and the 'language' setting are gone.
- ts/tsconfig.json + package.json pin typescript 5.9.3; the seven sources
  compile (ES2020, global scripts) into one committed html/js/app.js.
  Ten unreferenced legacy scripts under html/js/ deleted; all pages load
  js/app.js.
- Fix the six type errors that blocked a clean compile, including a real
  bug: a missing semicolon in the search shortcut handler made the code
  call the result of preventDefault(), so the shortcut threw instead of
  focusing the search box.
- /healthz liveness endpoint; Dockerfile healthcheck and README use it.
- Drone: go vet, and a webui-check step that rebuilds the bundle and fails
  if the committed app.js is stale.
- README-DEV.md documents build, UI toolchain, -dev, versioning, CI.
2026-09-26 12:46:45 +10:00
nathan 125b0bb35f Enhance XEPG channel mapping and settings management
continuous-integration/drone/push Build is passing
2026-02-13 16:09:00 +11:00
nathan 32c3d779c0 add edit button to mapping table and refactor cell creation
continuous-integration/drone/push Build is passing
2026-02-12 13:22:51 +11:00
nathan e48a061ca0 Enhance WebSocket handling and log polling logic
continuous-integration/drone/push Build is passing
2026-02-11 16:25:48 +11:00
nathan ffd43d5217 Enhance log display behavior and menu state management
continuous-integration/drone/push Build is passing
2026-02-11 14:37:02 +11:00
nathan 60af423335 update UI js
continuous-integration/drone/push Build is passing
2026-02-11 13:09:41 +11:00
nathan 57b6be74e2 improve ui checkbox functionality
continuous-integration/drone/push Build is passing
2026-02-11 13:03:12 +11:00
nathan 8cb9e43a72 Redesign UI and add first-party Docker runtime support 2026-02-11 11:04:39 +11:00
beardypig 19b9a259b1 Correctly unset the category for a channel in XEPG
Stores `""` to `x-category` when the category is unset, previosuly `"-"` was stored which would append a `<category>` to each `<programme>` for the channel.

fixes #209
2021-01-21 11:59:50 +01:00
marmei 469581e280 Add mapping desc. function 2019-12-13 19:01:18 +01:00
marmei 20e5e1b545 Buffer RTSP performance 2019-10-04 19:39:20 +02:00
marmei ad992eb615 Add FFmpeg and VLC support 2019-09-27 19:24:31 +02:00
marmei f9d1a45bbd Add original group-title to mapping editor 2019-08-17 08:57:06 +02:00
marmei 1769b1e6db v2.0.0.0009-beta 2019-08-09 17:58:34 +02:00
marmei 2a06bf6b01 Add HLS VOD support 2019-08-05 12:28:47 +02:00
marmei e001b06b62 v2.0.0.0000 2019-08-02 20:12:09 +02:00