- http.Server with ReadHeaderTimeout/IdleTimeout (no read/write timeouts: /stream/ is long-lived)
- shared outbound clients: providerHTTPClient (5m), apiHTTPClient (30s), imgcache client (30s)
- imgcache: download outside the lock, per-item helper, cache URL uses the file name not the fs path
- writeFileAtomic (temp + fsync + rename) for settings/xepg/pms/urls/authentication JSON
- one package-level logMu for WebScreenLog and notifications; ring buffer keeps the newest lines
- notifications evict the oldest instead of random map entries
- xepg XMLTV file removal rebuilt after the loop; data.go range-mutation removed
- API handler returns after error body; WS request/response fresh per command
- checked type assertions in data/backup/provider/screen
- SIGINT/SIGTERM handled in main via src.Shutdown(); fatal paths exit 1
Input handling:
- uploadLogo: client file name reduced to a safe base name with an image
extension (path traversal and arbitrary-extension writes closed).
- extractZIP: zip-slip guard; entries that resolve outside the target are
refused. Per-entry closes no longer pile up as defers.
- ffmpeg.path / vlc.path must be an existing regular file named ffmpeg,
vlc or cvlc, checked both when saved and right before exec.
- Stream URLs passed to the external buffer must use a network scheme
(http, https, rtsp, rtmp, rtp, udp, mms); file:, concat:, pipe: are
refused.
- /download/ (backups with settings.json and authentication.json) requires
the web session when web authentication is enabled.
- settings.json is written 0600; the Plex token is masked in every payload
sent to the UI and the mask round-trips as "unchanged" on save.
Authentication:
- Passwords are stored with bcrypt. Existing HMAC-SHA256 records still
verify (constant time) and are re-hashed on the first successful login.
Username lookups compare in constant time.
- URL (?username=&password=) and HTTP Basic authentication verify the
credentials per request via AuthenticateUser and no longer create a
session token, which removes the unbounded token growth under Plex
polling. Expired sessions are evicted whenever a new one is created.
- createFirstUserForAuthentication and checkAuthorizationLevel now return
real errors instead of calling no-op closures.
Tests: src/security_test.go and src/internal/authentication/
authentication_test.go cover each of the above.