Files
xTeVe/tasks/todo.md
T
nathan 51c7830067
continuous-integration/drone/push Build encountered an error
Phase 0: remove auto-updater, pin Go 1.27.1, fix vet warnings, tidy ignores
- Delete BinaryUpdate, internal/up2date, GitHub/Update structs and the
  xteveAutoUpdate / update.url settings (UI rows, en.json, defaults).
  Settings-schema migrations kept and moved to src/migrate.go.
- Drop kardianos/osext dependency.
- xteve.go version 0200 -> 0201 to match changelog; Drone now fails on drift.
- go.mod go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1.
- Fix four go vet unreachable-code warnings.
- .gitignore: .gocache/, agent.md, skill.md. .dockerignore: build context
  no longer includes caches, ts/, tasks/ or markdown except the changelog.
- Drone: publish :latest only from master; other branches publish a
  branch-named tag so a feature push cannot replace the deployed image.
- Add tasks/improvement-plan.md and tasks/todo.md.
- Regenerate src/webUI.go.
2026-09-26 12:38:02 +10:00

5.0 KiB

xTeVe improvement checklist

Detailed rationale, file references and effort estimates: tasks/improvement-plan.md. Status: Phase 0 committed on branch improvements 2026-09-26.

Phase 0: Hygiene

  • .gitignore (.gocache/), deleted .gocache/, extended .dockerignore
  • agent.md / skill.md git-ignored and docker-ignored (left in place)
  • Version drift fixed (xteve.go now 0201) and Drone drift check added
  • Auto-updater deleted (BinaryUpdate, internal/up2date, GitHub/Update structs, xteveAutoUpdate + update.url settings, UI rows, en.json); migrations kept in migrate.go; kardianos/osext gone
  • go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1
  • Four go vet unreachable-code warnings fixed (vet clean)
  • staticcheck baseline via go run honnef.co/go/tools/cmd/staticcheck@latest ./...: 408 findings (S1002 113, SA5008 79, S1039 67, S1038 40, S1023 35, ST1005 20, SA1019 14, SA4006 9, misc 11). Mostly style; SA5008/SA4006/SA1019 worth a pass in Phase 3 cleanup

Phase 1: Security

  • Replace innerHTML with textContent for provider-controlled strings
  • Enforce websocket Origin check; move token from query string to cookie; stop console-logging tokens
  • Cookie HttpOnly + SameSite
  • Wizard GET must not set AuthenticationWEB = false
  • Sanitise uploadLogo filename
  • Zip-slip guard in backup restore
  • Restrict ffmpeg.path / vlc.path and reject non-http(s) stream URLs
  • Put /download/ behind auth
  • Configured base URL instead of Host-header-derived domain
  • bcrypt with migrate-on-login; constant-time compare
  • Token expiry and eviction
  • Only admins may edit other users
  • Settings file mode 0600; redact Plex token in UI payload
  • Decide default for web auth on fresh installs (keep off; LAN only, decided 2026-09-25)

Phase 2: Streaming stability

  • Race tests: two concurrent tuners against a fake TS server, run with -race
  • *Playlist with own mutex; remove stale store-backs
  • Atomic tuner reservation; clean BufferClients on force kill
  • RWMutex around StreamingURLS
  • Remove defer inside read loops (buffer, compression, imgcache)
  • Single external-process buffer (exec.CommandContext + request context) with ffmpeg and VLC argument builders; drop CloseNotifier
  • Real mutex for screen log
  • http.Server with timeouts; timeouts on all outbound clients
  • imgcache: download outside the lock
  • Atomic write helper (temp + fsync + rename)
  • Fix listed concrete bugs (xepg append, range mutation, log overflow, headers after WriteHeader, random notification eviction, unchecked assertions, API double write, WS struct reuse)
  • Error hygiene: no-op closures, os.Exit/panic outside main, ignored results

Phase 3: Build, embed, CI, Docker

  • //go:embed html, delete webUI.go, html-build.go, cmd/webui-gen; cache headers
  • Drop i18n: inline English strings into TS, delete en.json, template only HTML pages
  • package.json + tsconfig.json + esbuild bundle (committed, CI-verified); delete 10 dead JS files
  • CI: vet, lint, gofmt, test -race, tsc --noEmit, generated-output check
  • Version-tagged images (amd64 only)
  • PUID/PGID via su-exec; pin static-ffmpeg; VOLUME; fix LEGACY_CONFIG_DIRS
  • /healthz endpoint
  • README-DEV.md and fork section in README.md
  • Deduplicate and delete dead code; drop ioutil, osext, rand.Seed (after go:embed)
  • Resolve missing docs/design-system/ referenced by agent.md

Phase 4: Data model and performance

Not planned (lineup is ~170 channels, decided 2026-09-25). See plan for the reference list.

Phase 5: Frontend architecture

  • Persistent websocket with request IDs, queue, backoff reconnect
  • Section-level re-render instead of full createLayout()
  • Virtualised mapping table
  • Split menu_ts.ts; addEventListener; data-driven settings rows
  • Accessibility follow-ups; light theme via prefers-color-scheme
  • Consolidate CSS layers

Phase 6: Optional features

  • Regex filters
  • Per-playlist tuner limit and buffer choice
  • Bulk channel edit
  • Versioned backup/restore
  • Dummy EPG durations

Review

Phase 0 (2026-09-26, branch improvements)

  • go build, go vet, go test ./... all clean. src/webUI.go regenerated.
  • Smoke run against an empty config dir on port 34499: /web/, /lineup_status.json, /discover.json all 200, no errors logged.
  • Not verified locally: Docker image build (no daemon on this machine); Drone will cover it.
  • Compiled JS in html/js/ was hand-edited to mirror the TS change because a current tsc does not reproduce the committed output (different shim, 5 type errors in menu_ts.ts). Phase 3 replaces this with a pinned toolchain.
  • html/js/menu.js still mentions xteveAutoUpdate; it is one of the ten dead legacy files scheduled for deletion in Phase 3.
  • Settings.Branch (git.branch) was kept: it still drives whether the build number is shown in the UI and XMLTV header.