continuous-integration/drone/push Build encountered an error
- Delete BinaryUpdate, internal/up2date, GitHub/Update structs and the xteveAutoUpdate / update.url settings (UI rows, en.json, defaults). Settings-schema migrations kept and moved to src/migrate.go. - Drop kardianos/osext dependency. - xteve.go version 0200 -> 0201 to match changelog; Drone now fails on drift. - go.mod go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1. - Fix four go vet unreachable-code warnings. - .gitignore: .gocache/, agent.md, skill.md. .dockerignore: build context no longer includes caches, ts/, tasks/ or markdown except the changelog. - Drone: publish :latest only from master; other branches publish a branch-named tag so a feature push cannot replace the deployed image. - Add tasks/improvement-plan.md and tasks/todo.md. - Regenerate src/webUI.go.
5.0 KiB
5.0 KiB
xTeVe improvement checklist
Detailed rationale, file references and effort estimates: tasks/improvement-plan.md.
Status: Phase 0 committed on branch improvements 2026-09-26.
Phase 0: Hygiene
.gitignore(.gocache/), deleted.gocache/, extended.dockerignoreagent.md/skill.mdgit-ignored and docker-ignored (left in place)- Version drift fixed (
xteve.gonow 0201) and Drone drift check added - Auto-updater deleted (
BinaryUpdate,internal/up2date,GitHub/Updatestructs,xteveAutoUpdate+update.urlsettings, UI rows,en.json); migrations kept inmigrate.go;kardianos/osextgone go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1- Four
go vetunreachable-code warnings fixed (vet clean) - staticcheck baseline via
go run honnef.co/go/tools/cmd/staticcheck@latest ./...: 408 findings (S1002 113, SA5008 79, S1039 67, S1038 40, S1023 35, ST1005 20, SA1019 14, SA4006 9, misc 11). Mostly style; SA5008/SA4006/SA1019 worth a pass in Phase 3 cleanup
Phase 1: Security
- Replace
innerHTMLwithtextContentfor provider-controlled strings - Enforce websocket Origin check; move token from query string to cookie; stop console-logging tokens
- Cookie
HttpOnly+SameSite - Wizard GET must not set
AuthenticationWEB = false - Sanitise
uploadLogofilename - Zip-slip guard in backup restore
- Restrict
ffmpeg.path/vlc.pathand reject non-http(s) stream URLs - Put
/download/behind auth - Configured base URL instead of Host-header-derived domain
- bcrypt with migrate-on-login; constant-time compare
- Token expiry and eviction
- Only admins may edit other users
- Settings file mode 0600; redact Plex token in UI payload
- Decide default for web auth on fresh installs (keep off; LAN only, decided 2026-09-25)
Phase 2: Streaming stability
- Race tests: two concurrent tuners against a fake TS server, run with
-race *Playlistwith own mutex; remove stale store-backs- Atomic tuner reservation; clean
BufferClientson force kill - RWMutex around
StreamingURLS - Remove
deferinside read loops (buffer, compression, imgcache) - Single external-process buffer (
exec.CommandContext+ request context) with ffmpeg and VLC argument builders; dropCloseNotifier - Real mutex for screen log
http.Serverwith timeouts; timeouts on all outbound clients- imgcache: download outside the lock
- Atomic write helper (temp + fsync + rename)
- Fix listed concrete bugs (xepg append, range mutation, log overflow, headers after WriteHeader, random notification eviction, unchecked assertions, API double write, WS struct reuse)
- Error hygiene: no-op closures,
os.Exit/panicoutside main, ignored results
Phase 3: Build, embed, CI, Docker
//go:embed html, deletewebUI.go,html-build.go,cmd/webui-gen; cache headers- Drop i18n: inline English strings into TS, delete
en.json, template only HTML pages package.json+tsconfig.json+ esbuild bundle (committed, CI-verified); delete 10 dead JS files- CI: vet, lint, gofmt,
test -race,tsc --noEmit, generated-output check - Version-tagged images (amd64 only)
- PUID/PGID via su-exec; pin static-ffmpeg;
VOLUME; fixLEGACY_CONFIG_DIRS /healthzendpointREADME-DEV.mdand fork section inREADME.md- Deduplicate and delete dead code; drop
ioutil,osext,rand.Seed(after go:embed) - Resolve missing
docs/design-system/referenced byagent.md
Phase 4: Data model and performance
Not planned (lineup is ~170 channels, decided 2026-09-25). See plan for the reference list.
Phase 5: Frontend architecture
- Persistent websocket with request IDs, queue, backoff reconnect
- Section-level re-render instead of full
createLayout() - Virtualised mapping table
- Split
menu_ts.ts;addEventListener; data-driven settings rows - Accessibility follow-ups; light theme via
prefers-color-scheme - Consolidate CSS layers
Phase 6: Optional features
- Regex filters
- Per-playlist tuner limit and buffer choice
- Bulk channel edit
- Versioned backup/restore
- Dummy EPG durations
Review
Phase 0 (2026-09-26, branch improvements)
go build,go vet,go test ./...all clean.src/webUI.goregenerated.- Smoke run against an empty config dir on port 34499:
/web/,/lineup_status.json,/discover.jsonall 200, no errors logged. - Not verified locally: Docker image build (no daemon on this machine); Drone will cover it.
- Compiled JS in
html/js/was hand-edited to mirror the TS change because a currenttscdoes not reproduce the committed output (different shim, 5 type errors inmenu_ts.ts). Phase 3 replaces this with a pinned toolchain. html/js/menu.jsstill mentionsxteveAutoUpdate; it is one of the ten dead legacy files scheduled for deletion in Phase 3.Settings.Branch(git.branch) was kept: it still drives whether the build number is shown in the UI and XMLTV header.