65 Commits
Author SHA1 Message Date
MichaelandClaude Opus 5 9843999809 Logos des chaînes : repli par nom quand l'hébergeur de picons tombe
L'hébergeur des picons du fournisseur (51.158.145.100) répond toujours
503 sur toutes ses URL. Couper le flot de requêtes ne suffisait pas : la
grille restait sans logo. Pire, le pixel transparent servi en 200 était
pris pour une image valide par Flutter, qui n'affichait plus son icône
de repli — d'où des tuiles entièrement vides.

- Nouvelle route `/api/logo?src=…&name=…` : URL du panneau d'abord (via
  le proxy, mêmes protections anti-SSRF et même mémoire des hôtes
  morts), puis recherche par nom dans le dépôt public tv-logo/tv-logos
- Appariement par nom : préfixe pays et suffixes de qualité ignorés,
  `+` → `plus`, variante plus longue (`bein-sports-1-french`), puis
  marque sans numéro pour les canaux événementiels. Aucune approximation
  sur un mot seul
- Liste de logos en cache 24 h (API GitHub : 60 requêtes/h non
  authentifiées), 15 min de recul après échec, images en mémoire
- Image indisponible : 410 mis en cache au lieu du pixel. 410 et non
  404 : la Cascade du serveur rattrape les 404 et renvoyait celui du
  handler statique, sans cache-control
- Client (grille bureau, mobile, enregistrements) : logo toujours
  demandé au backend, nom compris, même sans stream_icon. L'onglet
  Enregistrements chargeait l'URL http brute, bloquée en HTTPS

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-19 13:39:01 +02:00
Claude 1d8717bb40 Fiabilise le système d'enregistrement de bout en bout
Fuseaux horaires :
- POST /api/recordings rejette en 400 les dates sans fuseau et normalise
  tout en UTC à l'écriture (l'interprétation des dates naïves dans le TZ
  du conteneur décalait les enregistrements de 1-2 h)
- Helper frontend unique postRecording() : les 2 points de création
  (modal, guide EPG) envoient la même convention UTC

Contrôle d'accès :
- stop/delete/logs d'un enregistrement et delete d'un season pass
  vérifient la propriété (userId ou admin), comme playlists_handler
- Suppression des replis 'dev_user_id' et 'admin' (401 sans session)

SQLite :
- PRAGMA foreign_keys/WAL/busy_timeout (les ON DELETE CASCADE déclarés
  ne s'appliquaient pas : sessions et playlists orphelines)
- Migrations de schéma versionnées (schema_version) + index user_id,
  start_time, season_passes(user_id)

Gestion disque :
- Refus explicite de capture sous MIN_FREE_DISK_MB (défaut 500 Mo)
- Rotation par quota d'octets (RECORDINGS_QUOTA_GB, opt-in) qui ne touche
  jamais un enregistrement actif et supprime fichiers + ligne ensemble ;
  l'ancienne rotation « 50 fichiers » pouvait effacer une capture en cours
- DELETE /api/recordings/<id> supprime aussi .mkv/.log/parties (SafePath)

Scheduler :
- Arrêt gracieux orchestré par server.dart : clôture des enregistrements
  (fusion des parties, statut) avant killAll des sessions de streaming ;
  l'ancien handler SIGTERM de FfmpegSessionManager faisait exit(0) direct
- Noms de fichiers uniques par fragment d'id (deux enregistrements du
  même programme s'écrasaient mutuellement avec -y)
- Requête filtrée scheduled/recording au lieu de toute la table / 10 s
- Statut cancelled pour un scheduled arrêté (completed sans fichier
  cassait la lecture)

Season passes :
- Playlist du propriétaire du pass résolue à chaque scan (l'injection
  figée du 1er utilisateur rendait les passes muets après ajout de
  playlist, et mélangeait les credentials en multi-utilisateurs)
- Correspondance exacte par défaut (match_mode, migration en 'contains'
  pour l'existant), plafond de créations par scan, réalignement des
  horaires déplacés dans l'EPG, déduplication tolérante ±2 min
- Redaction des erreurs de scan (ClientException contient l'URL amont)

API de suivi (polling conservé) :
- GET /api/recordings enrichi : progress_pct, file_size_bytes,
  retry_count, is_active ; barre de progression + taille dans la liste

Validé : dart analyze (0 issue) et dart test (48/48) sur bin/.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015oEu9QayWsw7hCKhenxgVa
2026-08-27 12:11:56 +00:00
MichaelandClaude Opus 5 ad3e970c8d fix(api): send session token on EPG, recordings and season-pass calls
The security hardening in 60d3f42 moved /api/epg, /api/recordings and
/api/season-passes behind authMiddleware, but the Flutter client still
called them through bare package:http. Those requests carry no
Authorization header, and on web BrowserClient sets withCredentials to
false so the session cookie is not sent either — every call came back
401. Symptoms: empty TV guide, empty recordings list, empty season
passes.

Adds AuthedHttp, a thin wrapper that injects the same token ApiClient
and XtreamService already use (localStorage['auth_token']), and routes
the 13 affected calls through it.

subtitle_service is left on plain http: it fetches third-party subtitle
URLs, not our API, and must not leak the session token.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 21:54:01 +02:00
MichaelandClaude Opus 5 1feeaae78a feat(design): Warm Cinema theme + event-driven adaptive players
Replaces the Projector Noir palette with "Warm Cinema" and rebuilds the
web players around a shared, event-driven engine.

Design
- app_colors: warm charcoal (#0B0908), cream (#F3E9DF), ember (#D9541F);
  adds posterScrim/heroScrim gradients, lift()/emberFocus() shadows,
  const cream-alpha tokens replacing Colors.whiteNN, and primaryFill,
  a deeper ember reserved for text-bearing fills so white labels clear
  the 4.5:1 AA threshold that #D9541F alone does not
- app_theme / mobile_theme: Fraunces (display serif) + Karla (body),
  tighter radii, 20+ component themes
- glass_container: opaque layered surfaces replace the blurred glass
- themed_loading_screen restyled; players and boot splash follow

Performance
- drop every BackdropFilter: backdrop blur forced a full framebuffer
  read per frame per card, the main source of scroll jank
- bundle Fraunces/Karla as assets so google_fonts stops fetching from
  fonts.gstatic.com at startup
- bound image decode size on 12 sites: a 40-poster grid drops from
  ~240 MB to a few tens of MB of GPU memory

Players (new shared engine: web/xf-player-core.js)
- start on media events instead of polling the buffer every 100-200 ms
- hls.js/mpegts.js loaded on demand, so ~213 KB of mpegts is never
  fetched for HLS streams
- liveSyncDurationCount 10 -> 2, startFragPrefetch on, testBandwidth
  off, MPEG-TS initial stash 512 KB -> 64 KB
- adaptive escalation fast -> balanced -> safe after repeated stalls in
  a 60 s window, applied live for HLS so there is no visible cut

Preserved from the recent streaming work on main: server-side quality
selection, stable player viewId, the turbo direct MPEG-TS path, vendored
library cache headers and the CI/Docker changes. Only the theme layer and
the player front-end were replaced; GlassCard stays in ui_components.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 21:42:56 +02:00
MichaelandClaude Fable 5 e332895d7d feat(design): Projector Noir theme - tungsten amber on film-black
Full visual refonte replacing the generic neon-blue glass look:

- palette: warm film-black surface ladder, tungsten amber primary,
  warm taupe secondary, verdigris teal tertiary; semantic and
  category colors retuned to match (coral live, gold movies)
- typography: Syne (display/headlines) + Instrument Sans (body/UI)
  replace Space Grotesk/Inter/Outfit across all screens
- glassmorphism tokens warmed (amber inner glow, warm-white borders)
- web player theme.css + index.html loader mirror the new tokens
- hardcoded Colors.blue* in streaming settings and recordings tabs
  now use AppColors tokens
- DESIGN_SYSTEM.md updated to v3.0 Projector Noir

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 14:52:45 +02:00
MichaelandClaude Fable 5 969d40dec5 fix(ci): exclude bin/ from root analyzer and clean remaining warnings
The frontend CI job ran `flutter analyze` from the repo root, which also
analyzed the bin/ server package without its dependencies resolved
(shelf_router, sqlite3, bcrypt, test), producing hundreds of
uri_does_not_exist errors. bin/ is a standalone package covered by the
backend job, so it is now excluded from root analysis.

Also:
- Remove all unused fields/variables flagged as analyzer warnings
  (api_client, cache_service, player_screen, subtitle_service,
  live_tv_tab, mobile screens)
- Run `flutter analyze --no-fatal-infos` in CI: pre-existing deprecation
  infos (withOpacity, dart:html) stay non-fatal while errors and warnings
  still fail the build

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:17:40 +02:00
MichaelandClaude Fable 5 60d3f42901 feat: security hardening, streaming overhaul, design polish, tests
Security:
- Replace unsalted SHA-256 password hashing with bcrypt (lazy rehash on login)
- Add authenticated /api/xtream-api gateway: Xtream credentials are injected
  server-side and never sent to the frontend; /api/playlists no longer
  returns passwords
- Redact credentials from all logs (login body, proxy/FFmpeg/scheduler URLs)
- Add auth to recordings, EPG, season-passes and streaming routes
  (HttpOnly session cookie for hls.js; loopback bypass for local FFmpeg)
- Lock player postMessage to same-origin in both directions
- Vendor and pin hls.js 1.6.7 / mpegts.js 1.7.3 (drop CDN @latest)
- Fix rate limiter (client IP was never resolved), add login rate limit,
  restrict CORS, add CSP Report-Only, block private-IP SSRF targets,
  fix path traversal in recording log retrieval, chmod 777 -> 770
- Remove dead HiveService (seeded admin/admin into IndexedDB with SHA-256)
- Fix authMiddleware not populating 'user' context (getPlaylist ignored the
  logged-in user; admin purge always returned 403)

Streaming:
- New FfmpegSessionManager: process registry, idle reaper (4 min live /
  15 min VOD), orphan cleanup at startup, clean SIGTERM shutdown,
  fast-fail with stderr instead of 30 s timeout
- Quality selection (source/high/medium/low) for live and VOD; source mode
  streams with -c:v copy (zero transcoding); selector wired into the player
- Concurrent recordings (MAX_CONCURRENT_RECORDINGS, default 2); conflicts
  retry on the next tick instead of silently failing
- Lower live latency (HLS window 20 -> 10 segments, liveSync 10 -> 3)
- Fix recording log lookup (.mp4 vs .mkv mismatch)

Design:
- Replace hardcoded colors with AppColors tokens (12 files)
- web/theme.css syncs HTML players with the Flutter palette
- DPAD/keyboard navigation (arrow-key focus, player shortcuts)
- Tooltips on player icon buttons, Semantics on content cards
- Remove 7 dead widgets broken since the Stitch merge

Quality:
- bin/test/: 21 unit tests (bcrypt, redaction, traversal, SSRF, recording
  conflicts) plus a quality-selector widget test
- GitHub Actions CI (analyze + test + build web)
- Archive stale status docs into docs/archive/

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:07:18 +02:00
MichaelandClaude Opus 4.7 b985f11704 fix: resolve all compile errors from Stitch theme merge
- Add missing AppTheme animation constants (durationSm/Md/Lg/Xl, curveSmooth)
  to satisfy remote widget references.
- Replace deprecated GlassContainer(opacity:) with .glass()/.floating()/.base()
  in login_screen, live_tv_tab, mobile_live_tv_tab, player_screen,
  dashboard_screen.
- Fix const-eval errors by removing const from BorderSide/Text/BoxDecoration
  using AppColors.focusColor and AppColors.border (runtime getters).
- Fix subtitle_service.dart: padEnd → padRight (Dart String API).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-28 07:37:37 +02:00
MichaelandClaude Opus 4.7 60228f5576 fix: resolve GlassContainer API mismatch and broken remote files
- Replace deprecated GlassContainer(opacity:/hasBorder:) calls in
  dashboard_screen.dart and player_screen.dart with .glass() constructor.
- Fix epg_grid_screen.dart missing provider import and Playlist type mismatch.
- Delete broken/unreferenced files: network_service.dart, epg_grid_screen.dart.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-28 07:24:41 +02:00
MichaelandClaude Opus 4.7 2ba16caf55 Merge remote-tracking branch 'origin/main' into main
Resolved conflicts by keeping remote functional features (RecordingScheduler,
FFmpeg HLS transcoding, mobile player, channel cards) and restoring local
Stitch theme foundation (app_colors, app_theme, glass_container, mobile_theme).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-27 22:17:52 +02:00
MichaelandClaude Opus 4.7 f7eaa724e2 feat(theme): complete redesign to Cyber-Cinematic Glass (Stitch)
Replace the legacy Apple TV-style purple/cyan theme with the full
Google Stitch Cyber-Cinematic Glass design system across the
entire app (desktop + mobile).

- New Material 3 dark ColorScheme: background #121317, primary
  #adc6ff, primaryContainer #4b8eff, surface containers, etc.
- Typography: Space Grotesk (headlines) + Inter (body/labels)
- 3-level glassmorphism via GlassContainer: base, glass, floating
- Primary gradient: #007AFF → #00C6FF with blue glow effects
- Removed old compatibility aliases (focusColor, border, textPrimary,
  textSecondary); all code now uses semantic Stitch tokens
- Systematically replaced all Colors.white/black/red/grey and
  GoogleFonts.roboto/outfit with Stitch equivalents
- All 36 lib/ files updated, zero compilation errors

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-27 22:06:29 +02:00
Michael 6a4a642611 feat: implement IPTV player screen with iframe-based stream support and recordings tab widget 2026-04-01 20:19:40 +02:00
Michael ddb8110c40 feat: add mobile scaffold layout and dedicated mobile video player implementation 2026-03-29 12:07:14 +02:00
Michael fa6ae90d8d feat: add mobile-optimized IPTV player with HLS and MpegTS support 2026-03-29 10:19:36 +02:00
Michael 9755f51af5 fix(ui): prevent NaN division crash in TvChannelGrid and fix playlist silent failure
- tv_channel_grid.dart: guard screenWidth <= 0 / NaN / Infinite on first
  Flutter Web layout pass (previously caused NaN ~/ 225.03 crash cascade).
  Also use .clamp(1.0, infinity) on item width for belt-and-suspenders safety.
  Fix invalid 'padding.vertical as double?' cast in TvHorizontalList by using
  padding.resolve(TextDirection.ltr).top instead.

- playlist_api_service.dart: remove silent catch-and-return-empty in
  getPlaylists(). Exceptions now propagate to the Riverpod FutureProvider
  so the UI shows the real error state (with Retry button) instead of
  a misleading 'No playlists available' when the API call actually failed
  (e.g., 401 Unauthorized or network error).
2026-03-26 16:24:18 +01:00
GitHub CopilotandClaude Haiku 4.5 288bf9e6ee fix(api): auto-restore authentication token on app startup
Fixed playlist loading failure by ensuring the auth token is automatically
restored from localStorage when ApiClient initializes. Previously, the token
was stored but never restored, causing 401 Unauthorized errors on API calls.

Added _restoreTokenFromStorage() method to ApiClient constructor to load
and apply stored token immediately on app startup. This ensures all API
calls (including playlist fetching) have proper authentication.

Fixes: "I still don't have a playlist" issue where playlists were not loading

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-03-26 15:44:38 +01:00
GitHub CopilotandClaude Haiku 4.5 dc711b2380 fix(ui): resolve NaN division error in tv channel grid width calculation
Fixed NaN error in TvChannelGrid width calculation by properly resolving
EdgeInsetsGeometry to concrete values before arithmetic operations.
EdgeInsetsGeometry.horizontal can return NaN/infinity, causing invalid
width calculations.

Changed from: padding.horizontal
To: padding.resolve(TextDirection.ltr).left + padding.resolve(TextDirection.ltr).right

This ensures we get concrete padding values before division operations.

Fixes: Unsupported operation: Result of truncating division is NaN: NaN ~/ 225.0357142857143

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-03-26 15:36:28 +01:00
GitHub Copilot 031602f023 refactor(theme): replace hardcoded colors with AppColors for improved maintainability 2026-03-26 15:27:15 +01:00
GitHub CopilotandClaude Haiku 4.5 29888c9b2a fix(adaptive-bitrate): correct operator precedence in bitrate calculations
Fixed NaN errors in FFmpeg bitrate argument generation by ensuring integer
conversion happens before integer division. The double multiplication (1.5, 2.0)
was happening before the ~/ operator, causing NaN values. Now properly converts
to int first, then divides.

- maxRateArg: ((bitrateBps * 1.5).toInt() ~/ 1000)
- bufferSizeArg: ((bitrateBps * 2).toInt() ~/ 1000)

Fixes: Unsupported operation: Result of truncating division is NaN

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-03-26 15:26:50 +01:00
GitHub Copilot 1bc9223665 refactor(ui): update theme colors for improved consistency and remove unused gradient background 2026-03-26 15:03:07 +01:00
GitHub Copilot a60bc6e8bd refactor(ui): enhance ambient glow effects with improved visibility and size adjustments 2026-03-26 14:50:30 +01:00
GitHub Copilot 0c9d0e50ec refactor(theme): update color references to use AppColors for consistency across components 2026-03-26 11:46:41 +01:00
GitHub Copilot 1b39aed8a5 refactor(theme): update border colors and rename elevation to shadow for clarity 2026-03-26 11:38:54 +01:00
GitHub Copilot 611fc41c76 feat: Add Apple TV Design System Visual Reference and Component Guide
- Introduced a comprehensive visual reference for the Apple TV design system, including color palette, component specifications, typography, shadow elevation system, and animation timing guide.
- Detailed button states, card components, text styles, and navigation focus flow for improved user experience.
- Included accessibility considerations and a testing checklist to ensure compliance with design standards.

chore: Complete redesign of XtremFlow Apple TV theme

- Updated color palette to align with Apple TV aesthetics, enhancing sophistication and premium feel.
- Optimized typography for better readability at 10ft viewing distance.
- Improved focus states for remote navigation clarity.
- Implemented a new 5-level shadow system for cinematic depth.
- Refined glass effects for a premium appearance.
- Ensured all components are accessible and comfortable for remote use.
2026-03-26 11:34:47 +01:00
GitHub Copilot 863e5ddad4 refactor(theme): update card and dialog themes to use CardThemeData and DialogThemeData
refactor(ui_components): adjust animation durations for smoother transitions
fix(dashboard): rename border property to hasBorder for clarity
fix(player): rename border property to hasBorder for consistency
2026-03-26 11:20:31 +01:00
GitHub Copilot 5b16029038 refactor(channel_card): simplify ChannelCard structure and enhance hover effects 2026-03-26 11:15:30 +01:00
GitHub Copilot 2ca0c8bf1a feat: Enhance Apple TV UI components with modern design elements
- Updated ChannelCard widget to include live indicator, favorite button, and EPG information with smooth animations and skeleton loading for images.
- Introduced MobileTheme for touch-optimized layouts, adapting Apple TV design principles for mobile screens.
- Added TvChannelGrid for responsive channel layouts with flexible column counts and smooth animations.
- Created TvModernCard for displaying content with interactive hover states, progress indicators, and context menu support.
- Implemented TvTopNavBar and TvSideNav for improved navigation with glassmorphism effects and user-friendly interactions.
- Developed TvFloatingMenu for context-aware actions with smooth reveal animations.
2026-03-26 11:09:40 +01:00
GitHub Copilot 74b06196e4 refactor(cache): move CacheEntry class outside CacheService and enhance its functionality 2026-03-26 10:47:16 +01:00
GitHub Copilot db849599b7 fix(dependencies): remove unused http_client_adapter from pubspec.yaml 2026-03-26 10:38:39 +01:00
GitHub Copilot 91eb1ce5a0 Add download and subtitle services, enhance UI with continue watching and quality selector widgets
- Implemented DownloadService for managing download tasks, including start, pause, resume, and cancel functionalities.
- Created SubtitleService for handling subtitle tracks, parsing SRT and WebVTT formats, and downloading subtitles.
- Added ContinueWatchingWidget to display user's watch history with progress indicators.
- Developed QualitySelectorWidget for selecting video quality during playback, including auto quality adjustment.
- Introduced TrendingWidget and RecentlyAddedWidget to showcase trending and recently added content.
2026-03-26 10:34:18 +01:00
Michael 9f3c29f6dd feat: implement Xtream API service for managing live channels, VOD, and series with caching and dynamic backend URL handling. 2026-03-10 14:57:44 +01:00
Michael e4f8ebcf8f fix(mobile): stabilize router and add loading timeout/retry on playlists screen 2026-03-09 17:35:09 +01:00
Michael 180b57e1b7 fix(router): add missing import for MobileLoginScreen 2026-03-09 17:09:07 +01:00
Michael 33c6385d7e feat: introduce mobile player screen and lite player view with channel zapping functionality 2026-03-09 14:52:41 +01:00
Michael fa88746db6 feat: introduce IPTV data models and initial Live TV UI, including EPG overlay. 2026-03-09 10:12:55 +01:00
Michael 71630d75e8 feat: Install FFmpeg with NVIDIA NVENC/NVDEC support via apt-get instead of a static build. 2026-01-03 10:26:17 +01:00
Michael 30218cb1d0 feat: add TvFocusableCard widget for interactive focus and hover effects. 2026-01-01 18:37:42 +01:00
Michael 79ad1243fa feat: Add a themed loading screen widget and a web-based HLS/MPEG-TS video player. 2026-01-01 18:21:54 +01:00
Michael a1a8810ddc feat: introduce streaming handlers for live TV proxy and VOD HLS transcoding using FFmpeg. 2026-01-01 18:12:45 +01:00
Michael 57b7acbead feat: Implement streaming handlers for live MPEG-TS proxy and VOD HLS transcoding via FFmpeg, and add a release build script. 2025-12-16 07:39:33 +01:00
Michael 916709cf27 feat: implement login and dashboard screens, introducing GlassContainer and TvFocusableCard widgets. 2025-12-13 08:42:30 +01:00
Michael 20f8904e78 feat: add HeroCarousel widget for displaying interactive, auto-playing content. 2025-12-08 23:13:12 +01:00
Michael e0cdf69674 feat: add settings API service and IPTV settings provider with configurable options. 2025-12-08 22:58:43 +01:00
Michael 63846c090a feat: implement IPTV settings management with streaming and display preferences 2025-12-08 21:40:46 +01:00
Michael e95fdb534a feat: add new UI tabs for movies and series, including mobile-specific versions with search and pagination. 2025-12-08 20:43:41 +01:00
Michael 38f3f9c96b feat: Add initial IPTV player with HLS/MPEG-TS support, query parameter parsing, and parent window communication. 2025-12-07 14:57:32 +01:00
Michael 9fd8fe62e5 feat: Add IPTV player screen with live stream FFmpeg transcoding, playback position tracking, and new dashboard and digital clock widgets. 2025-12-07 10:02:54 +01:00
Michael fb2412e03a feat: introduce IPTV player, GoRouter setup, themed loading screen, and content tabs 2025-12-07 09:54:50 +01:00
Michael 12f5ddcf97 feat: implement ChannelCard widget with EPG display, interactive hover effects, and live indicator. 2025-12-07 00:16:43 +01:00
Michael 29b070b964 chore: update project dependencies to their latest versions. 2025-12-07 00:04:52 +01:00