41 couleurs Material brutes traînaient encore dans l'interface, hors palette :
rouge, vert, orange et surtout un violet omniprésent sur les Season Pass, qui
n'appartient à aucune famille du thème.
Correspondances retenues :
- Colors.red / redAccent -> AppColors.live (#E5484D) pour les badges LIVE et
les indicateurs d'enregistrement, AppColors.error pour les messages d'erreur
- Colors.green / greenAccent -> AppColors.success
- Colors.orangeAccent -> AppColors.warning
- Colors.amber -> AppColors.ratingGold, pour aligner les étoiles de notation
du mobile sur celles du bureau
- Colors.purpleAccent -> famille secondary (terre cuite)
- fonds de boutons passés sur les variantes *Container avec leur couleur de
premier plan, le remplissage clair ne portant pas de texte lisible
Le titre du programme EPG dans la grille Live TV utilisait ratingGold, un jeton
réservé aux notes : il passe sur primary, l'accent ember du thème.
Les fonds de SnackBar vert/rouge deviennent surfaceContainerHigh, le succès et
l'échec restant portés par le pictogramme du message.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
EPG — les trois chemins (backend /api/epg, XtreamService.getShortEpg et
getShortEPG) n'utilisaient que get_epg et get_short_epg. Beaucoup de
panneaux Xtream ne connaissent pas get_epg : ils répondent 200 avec le
bloc d'authentification, sans epg_listings, ce qui produisait un guide
vide indiscernable d'une chaîne sans programme. get_short_epg y renvoie
epg_listings vide en permanence.
- backend : get_simple_data_table en premier, get_short_epg en repli
- client : bascule automatique et mémorisée vers le tableau complet dès
qu'un panneau est muet sur l'action légère, pour ne pas doubler les
requêtes sur chaque tuile de grille
- dates dérivées des *_timestamp epoch et émises en ISO-8601 UTC : les
champs texte sont dans le fuseau du panneau, sans indicateur de zone,
et étaient relus comme de l'heure locale — le guide était décalé et
les enregistrements planifiés depuis le guide l'étaient aussi
- cache backend : la clé incluait seulement le channelId, deux playlists
partageant un stream_id se servaient mutuellement leur guide
UI — les deux halos d'ambiance du dashboard étaient restés de l'ancien
thème : primary (#FFB68C) à 40 % posé sur le coin haut-gauche, donc pile
derrière la sidebar, et info (#A3B8C4, bleu-gris) à 35 % dans une palette
entièrement chaude. Ramenés à des braises ember à 8 % / 6 %.
- fond via AppColors.backgroundGradient
- onglet actif rempli en primaryContainer (surface) et non primary
(teinte claire réservée au texte/icônes)
- sidebar en niveau flottant : en niveau 1 son fond #181310 se confondait
avec le haut du dégradé #1A1310
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Full visual refonte replacing the generic neon-blue glass look:
- palette: warm film-black surface ladder, tungsten amber primary,
warm taupe secondary, verdigris teal tertiary; semantic and
category colors retuned to match (coral live, gold movies)
- typography: Syne (display/headlines) + Instrument Sans (body/UI)
replace Space Grotesk/Inter/Outfit across all screens
- glassmorphism tokens warmed (amber inner glow, warm-white borders)
- web player theme.css + index.html loader mirror the new tokens
- hardcoded Colors.blue* in streaming settings and recordings tabs
now use AppColors tokens
- DESIGN_SYSTEM.md updated to v3.0 Projector Noir
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- reaper no longer kills exited sessions immediately: a finished VOD
transcode was reaped (segments deleted) while still being watched
- reuse completed VOD/recording sessions instead of re-transcoding
- live input: add -rw_timeout 30s and -reconnect_at_eof so a stalled
upstream triggers reconnect instead of wedging ffmpeg forever
- reaper watchdog restarts live sessions whose playlist stopped updating
- waitForPlaylist fails fast on clean ffmpeg exit without output
- direct .ts proxy: close http.Client on stream end/error (socket leak)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Stop sending no-store on vendored player libraries: hls.min.js and
mpegts.min.js (~750 KB) were re-downloaded on every player open
- hls.js: start with 1 live segment instead of 3, lower buffer-first
threshold 1.5s -> 0.8s, poll buffer every 100ms
- mpegts.js: initial stash 512KB -> 128KB, start at 0.5s buffered
- Live FFmpeg: -hls_init_time 1 closes the first segment after ~1s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
.dockerignore excluded entrypoint.sh while the Dockerfile COPYs it into
the runtime stage; buildx (docker-container driver) fails hard on this
where the legacy builder only warned.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
streamAuthMiddleware wrapped the whole streaming router inside the
Cascade, so any unmatched path without a session (e.g. GET / through the
reverse proxy) returned 401 before reaching the static file handler.
Now only /api/live, /api/vod and /api/recordings/stream are guarded;
other paths fall through to the router's 404 and the Cascade continues.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Builds and pushes ghcr.io/r0m1k3/xtremflow:latest (+ sha tag) so update
managers (Unraid/Watchtower/Portainer) can detect new images instead of
relying on a local build context.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The frontend CI job ran `flutter analyze` from the repo root, which also
analyzed the bin/ server package without its dependencies resolved
(shelf_router, sqlite3, bcrypt, test), producing hundreds of
uri_does_not_exist errors. bin/ is a standalone package covered by the
backend job, so it is now excluded from root analysis.
Also:
- Remove all unused fields/variables flagged as analyzer warnings
(api_client, cache_service, player_screen, subtitle_service,
live_tv_tab, mobile screens)
- Run `flutter analyze --no-fatal-infos` in CI: pre-existing deprecation
infos (withOpacity, dart:html) stay non-fatal while errors and warnings
still fail the build
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Security:
- Replace unsalted SHA-256 password hashing with bcrypt (lazy rehash on login)
- Add authenticated /api/xtream-api gateway: Xtream credentials are injected
server-side and never sent to the frontend; /api/playlists no longer
returns passwords
- Redact credentials from all logs (login body, proxy/FFmpeg/scheduler URLs)
- Add auth to recordings, EPG, season-passes and streaming routes
(HttpOnly session cookie for hls.js; loopback bypass for local FFmpeg)
- Lock player postMessage to same-origin in both directions
- Vendor and pin hls.js 1.6.7 / mpegts.js 1.7.3 (drop CDN @latest)
- Fix rate limiter (client IP was never resolved), add login rate limit,
restrict CORS, add CSP Report-Only, block private-IP SSRF targets,
fix path traversal in recording log retrieval, chmod 777 -> 770
- Remove dead HiveService (seeded admin/admin into IndexedDB with SHA-256)
- Fix authMiddleware not populating 'user' context (getPlaylist ignored the
logged-in user; admin purge always returned 403)
Streaming:
- New FfmpegSessionManager: process registry, idle reaper (4 min live /
15 min VOD), orphan cleanup at startup, clean SIGTERM shutdown,
fast-fail with stderr instead of 30 s timeout
- Quality selection (source/high/medium/low) for live and VOD; source mode
streams with -c:v copy (zero transcoding); selector wired into the player
- Concurrent recordings (MAX_CONCURRENT_RECORDINGS, default 2); conflicts
retry on the next tick instead of silently failing
- Lower live latency (HLS window 20 -> 10 segments, liveSync 10 -> 3)
- Fix recording log lookup (.mp4 vs .mkv mismatch)
Design:
- Replace hardcoded colors with AppColors tokens (12 files)
- web/theme.css syncs HTML players with the Flutter palette
- DPAD/keyboard navigation (arrow-key focus, player shortcuts)
- Tooltips on player icon buttons, Semantics on content cards
- Remove 7 dead widgets broken since the Stitch merge
Quality:
- bin/test/: 21 unit tests (bcrypt, redaction, traversal, SSRF, recording
conflicts) plus a quality-selector widget test
- GitHub Actions CI (analyze + test + build web)
- Archive stale status docs into docs/archive/
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Replace deprecated GlassContainer(opacity:/hasBorder:) calls in
dashboard_screen.dart and player_screen.dart with .glass() constructor.
- Fix epg_grid_screen.dart missing provider import and Playlist type mismatch.
- Delete broken/unreferenced files: network_service.dart, epg_grid_screen.dart.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Resolved conflicts by keeping remote functional features (RecordingScheduler,
FFmpeg HLS transcoding, mobile player, channel cards) and restoring local
Stitch theme foundation (app_colors, app_theme, glass_container, mobile_theme).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Replace the legacy Apple TV-style purple/cyan theme with the full
Google Stitch Cyber-Cinematic Glass design system across the
entire app (desktop + mobile).
- New Material 3 dark ColorScheme: background #121317, primary
#adc6ff, primaryContainer #4b8eff, surface containers, etc.
- Typography: Space Grotesk (headlines) + Inter (body/labels)
- 3-level glassmorphism via GlassContainer: base, glass, floating
- Primary gradient: #007AFF → #00C6FF with blue glow effects
- Removed old compatibility aliases (focusColor, border, textPrimary,
textSecondary); all code now uses semantic Stitch tokens
- Systematically replaced all Colors.white/black/red/grey and
GoogleFonts.roboto/outfit with Stitch equivalents
- All 36 lib/ files updated, zero compilation errors
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- tv_channel_grid.dart: guard screenWidth <= 0 / NaN / Infinite on first
Flutter Web layout pass (previously caused NaN ~/ 225.03 crash cascade).
Also use .clamp(1.0, infinity) on item width for belt-and-suspenders safety.
Fix invalid 'padding.vertical as double?' cast in TvHorizontalList by using
padding.resolve(TextDirection.ltr).top instead.
- playlist_api_service.dart: remove silent catch-and-return-empty in
getPlaylists(). Exceptions now propagate to the Riverpod FutureProvider
so the UI shows the real error state (with Retry button) instead of
a misleading 'No playlists available' when the API call actually failed
(e.g., 401 Unauthorized or network error).
- Increased FFmpeg video quality to 8Mbps and audio to 192kbps.
- Added audio resync filters and better presets.
- Optimized HLS buffer settings for mobile players to reduce interruptions.
- Reduced API cache duration to 15m and added refresh support for faster content updates.
- Add -fflags +nobuffer+fastseek+genpts for instant stream start
- Keep probesize at 5MB for reliable audio detection
- Set analyzeduration to 3s for balanced speed/reliability