Commit Graph
26 Commits
Author SHA1 Message Date
nathan 4976219857 Phase 1a: browser-side security
continuous-integration/drone/push Build encountered an error
- Provider-controlled strings (channel names, groups, file names, log
  lines, in-place mapping edits, client info) are rendered with
  textContent instead of innerHTML. PopupContent.description() takes an
  explicit isHTML flag that only the static help texts pass.
- Websocket: drop the always-true CheckOrigin so gorilla's same-origin
  check applies; read the session token from the HttpOnly cookie sent with
  the handshake (the ?Token= query parameter is still accepted for older
  clients); the client no longer puts the token in the URL, rewrites the
  cookie, or console-logs request/response payloads.
- Session cookie is HttpOnly, SameSite=Strict, Path=/, session-scoped
  (expiry stays server side) and is cleared on logout.
- Serving the first-run wizard no longer sets Settings.AuthenticationWEB
  to false; the wizard page simply bypasses login while it is active.
- Upgrade failures no longer write a second error response.
- Tests: src/websocket_test.go covers cross-origin refusal, same-origin
  and no-Origin clients, missing/unknown/legacy tokens, and cookie flags.
2026-09-26 12:59:47 +10:00
nathan ddc70e170a Phase 3: embed web UI with go:embed, pinned TypeScript toolchain, drop i18n, add /healthz
continuous-integration/drone/push Build encountered an error
- html/embed.go embeds html/ (pages, css, img, js, video); src/assets.go
  serves it, with os.DirFS("html") under -dev. Static assets get an ETag
  and Cache-Control: no-cache; HTML pages are still templated (only the
  login error message is substituted now).
- Delete the generated src/webUI.go (783 KB base64), src/html-build.go and
  cmd/webui-gen; Dockerfile no longer runs a generator.
- Language layer removed: 254 {{.x}} placeholders inlined as English
  strings in ts/*.ts and the two auth pages; html/lang/en.json, the
  LanguageUI struct and the 'language' setting are gone.
- ts/tsconfig.json + package.json pin typescript 5.9.3; the seven sources
  compile (ES2020, global scripts) into one committed html/js/app.js.
  Ten unreferenced legacy scripts under html/js/ deleted; all pages load
  js/app.js.
- Fix the six type errors that blocked a clean compile, including a real
  bug: a missing semicolon in the search shortcut handler made the code
  call the result of preventDefault(), so the shortcut threw instead of
  focusing the search box.
- /healthz liveness endpoint; Dockerfile healthcheck and README use it.
- Drone: go vet, and a webui-check step that rebuilds the bundle and fails
  if the committed app.js is stale.
- README-DEV.md documents build, UI toolchain, -dev, versioning, CI.
2026-09-26 12:46:45 +10:00
nathan 51c7830067 Phase 0: remove auto-updater, pin Go 1.27.1, fix vet warnings, tidy ignores
continuous-integration/drone/push Build encountered an error
- Delete BinaryUpdate, internal/up2date, GitHub/Update structs and the
  xteveAutoUpdate / update.url settings (UI rows, en.json, defaults).
  Settings-schema migrations kept and moved to src/migrate.go.
- Drop kardianos/osext dependency.
- xteve.go version 0200 -> 0201 to match changelog; Drone now fails on drift.
- go.mod go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1.
- Fix four go vet unreachable-code warnings.
- .gitignore: .gocache/, agent.md, skill.md. .dockerignore: build context
  no longer includes caches, ts/, tasks/ or markdown except the changelog.
- Drone: publish :latest only from master; other branches publish a
  branch-named tag so a feature push cannot replace the deployed image.
- Add tasks/improvement-plan.md and tasks/todo.md.
- Regenerate src/webUI.go.
2026-09-26 12:38:02 +10:00
nathan 125b0bb35f Enhance XEPG channel mapping and settings management
continuous-integration/drone/push Build is passing
2026-02-13 16:09:00 +11:00
nathan 32c3d779c0 add edit button to mapping table and refactor cell creation
continuous-integration/drone/push Build is passing
2026-02-12 13:22:51 +11:00
nathan e48a061ca0 Enhance WebSocket handling and log polling logic
continuous-integration/drone/push Build is passing
2026-02-11 16:25:48 +11:00
nathan ffd43d5217 Enhance log display behavior and menu state management
continuous-integration/drone/push Build is passing
2026-02-11 14:37:02 +11:00
nathan 9bd2b32003 Enhance WebSocket connection handling with improved timeout and error states
continuous-integration/drone/push Build is passing
2026-02-11 14:20:24 +11:00
nathan 60af423335 update UI js
continuous-integration/drone/push Build is passing
2026-02-11 13:09:41 +11:00
nathan 57b6be74e2 improve ui checkbox functionality
continuous-integration/drone/push Build is passing
2026-02-11 13:03:12 +11:00
nathan b069d5bee8 many updates 2026-02-11 11:38:26 +11:00
nathan 8cb9e43a72 Redesign UI and add first-party Docker runtime support 2026-02-11 11:04:39 +11:00
xteve-project 25bad13800 compile js 2021-01-21 19:50:35 +01:00
xteve-project 014f5b7218 Dummy new times
Fixed searching for XMLTV file (Mapping)
2020-11-20 22:13:52 +01:00
5Ub-Z3r0 67b7ba6df9 Add support for proxying multicast streams through a UDPxy server.
This commit adds support for proxying multicast streams through a UDPxy
server. If the stream is multicast, and a udpxy server is set in the
configuration, then the channel URL is rewritten to use the UDPxy
service configured.

The stream URL rewriting is done regardless of the buffer option set.

Signed-off-by: 5Ub-Z3r0 <1673590+5Ub-Z3r0@users.noreply.github.com>
2020-05-13 21:26:24 +02:00
marmei 87b36c283b URL format removed from the settings 2020-01-04 17:17:28 +01:00
marmei 469581e280 Add mapping desc. function 2019-12-13 19:01:18 +01:00
marmei 1a1e37fe15 v2.1.0.0105: Settings for URI scheme 2019-12-06 20:48:59 +01:00
marmei 20e5e1b545 Buffer RTSP performance 2019-10-04 19:39:20 +02:00
marmei ad992eb615 Add FFmpeg and VLC support 2019-09-27 19:24:31 +02:00
marmei f9d1a45bbd Add original group-title to mapping editor 2019-08-17 08:57:06 +02:00
marmei 1769b1e6db v2.0.0.0009-beta 2019-08-09 17:58:34 +02:00
marmei 67fe80b4fd v2.0.0.0008-beta
Pull request: Error in http/https detection. (#6)
2019-08-09 09:31:31 +02:00
marmei 2a06bf6b01 Add HLS VOD support 2019-08-05 12:28:47 +02:00
marmei 4dc9dfabf2 Wizard: Add input placeholder (M3U, XMLTV)
Wizard: Alert by empty value (M3U, XMLTV)
2019-08-03 14:52:17 +02:00
marmei e001b06b62 v2.0.0.0000 2019-08-02 20:12:09 +02:00