From a149bf266c88028663c4064ba3c736c4995a5932 Mon Sep 17 00:00:00 2001 From: Michael SCHAL Date: Wed, 7 Jan 2026 10:39:06 +0100 Subject: [PATCH] chore: add detailed login logging and update startup message --- bin/api/auth_handler.dart | 15 +++++++++++++-- bin/server.dart | 2 +- 2 files changed, 14 insertions(+), 3 deletions(-) diff --git a/bin/api/auth_handler.dart b/bin/api/auth_handler.dart index cd2da5f..f581784 100644 --- a/bin/api/auth_handler.dart +++ b/bin/api/auth_handler.dart @@ -21,35 +21,46 @@ class AuthHandler { /// POST /api/auth/login Future _login(Request request) async { try { - final payload = jsonDecode(await request.readAsString()) as Map; + print('[Auth] Login attempt received'); + final bodyStr = await request.readAsString(); + print('[Auth] Request body: $bodyStr'); + + final payload = jsonDecode(bodyStr) as Map; final username = payload['username'] as String?; final password = payload['password'] as String?; if (username == null || password == null) { + print('[Auth] Missing username or password'); return Response(400, body: jsonEncode({ 'success': false, 'error': 'Username and password are required', }), headers: {'Content-Type': 'application/json'},); } + print('[Auth] Verifying credentials for user: $username'); // Verify credentials final user = db.verifyCredentials(username, password); if (user == null) { + print('[Auth] Invalid credentials for user: $username'); return Response(401, body: jsonEncode({ 'success': false, 'error': 'Invalid credentials', }), headers: {'Content-Type': 'application/json'},); } + print('[Auth] User verified, creating session for userId: ${user.id}'); // Create session final session = db.createSession(user.id); + print('[Auth] Session created with token: ${session.token.substring(0, 8)}...'); return Response.ok(jsonEncode({ 'success': true, 'user': user.toJson(), 'token': session.token, }), headers: {'Content-Type': 'application/json'},); - } catch (e) { + } catch (e, stackTrace) { + print('[Auth] ERROR during login: $e'); + print('[Auth] Stack trace: $stackTrace'); return Response.internalServerError( body: jsonEncode({'success': false, 'error': e.toString()}), headers: {'Content-Type': 'application/json'}, diff --git a/bin/server.dart b/bin/server.dart index 7b9a1e1..b7061fd 100644 --- a/bin/server.dart +++ b/bin/server.dart @@ -278,7 +278,7 @@ void main(List args) async { print('Server started on port ${server.port}'); print('Serving static files from: $webPath'); print('REST API available at: /api/auth/* and /api/playlists/*'); - print('Xtream proxy available at: /api/xtream/* (Authenticated)'); + print('Xtream proxy available at: /api/xtream/* (SSRF Protected)'); // Clean expired sessions periodically (every hour) Timer.periodic(const Duration(hours: 1), (_) {