.dockerignore excluded entrypoint.sh while the Dockerfile COPYs it into
the runtime stage; buildx (docker-container driver) fails hard on this
where the legacy builder only warned.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
streamAuthMiddleware wrapped the whole streaming router inside the
Cascade, so any unmatched path without a session (e.g. GET / through the
reverse proxy) returned 401 before reaching the static file handler.
Now only /api/live, /api/vod and /api/recordings/stream are guarded;
other paths fall through to the router's 404 and the Cascade continues.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Builds and pushes ghcr.io/r0m1k3/xtremflow:latest (+ sha tag) so update
managers (Unraid/Watchtower/Portainer) can detect new images instead of
relying on a local build context.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The frontend CI job ran `flutter analyze` from the repo root, which also
analyzed the bin/ server package without its dependencies resolved
(shelf_router, sqlite3, bcrypt, test), producing hundreds of
uri_does_not_exist errors. bin/ is a standalone package covered by the
backend job, so it is now excluded from root analysis.
Also:
- Remove all unused fields/variables flagged as analyzer warnings
(api_client, cache_service, player_screen, subtitle_service,
live_tv_tab, mobile screens)
- Run `flutter analyze --no-fatal-infos` in CI: pre-existing deprecation
infos (withOpacity, dart:html) stay non-fatal while errors and warnings
still fail the build
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Security:
- Replace unsalted SHA-256 password hashing with bcrypt (lazy rehash on login)
- Add authenticated /api/xtream-api gateway: Xtream credentials are injected
server-side and never sent to the frontend; /api/playlists no longer
returns passwords
- Redact credentials from all logs (login body, proxy/FFmpeg/scheduler URLs)
- Add auth to recordings, EPG, season-passes and streaming routes
(HttpOnly session cookie for hls.js; loopback bypass for local FFmpeg)
- Lock player postMessage to same-origin in both directions
- Vendor and pin hls.js 1.6.7 / mpegts.js 1.7.3 (drop CDN @latest)
- Fix rate limiter (client IP was never resolved), add login rate limit,
restrict CORS, add CSP Report-Only, block private-IP SSRF targets,
fix path traversal in recording log retrieval, chmod 777 -> 770
- Remove dead HiveService (seeded admin/admin into IndexedDB with SHA-256)
- Fix authMiddleware not populating 'user' context (getPlaylist ignored the
logged-in user; admin purge always returned 403)
Streaming:
- New FfmpegSessionManager: process registry, idle reaper (4 min live /
15 min VOD), orphan cleanup at startup, clean SIGTERM shutdown,
fast-fail with stderr instead of 30 s timeout
- Quality selection (source/high/medium/low) for live and VOD; source mode
streams with -c:v copy (zero transcoding); selector wired into the player
- Concurrent recordings (MAX_CONCURRENT_RECORDINGS, default 2); conflicts
retry on the next tick instead of silently failing
- Lower live latency (HLS window 20 -> 10 segments, liveSync 10 -> 3)
- Fix recording log lookup (.mp4 vs .mkv mismatch)
Design:
- Replace hardcoded colors with AppColors tokens (12 files)
- web/theme.css syncs HTML players with the Flutter palette
- DPAD/keyboard navigation (arrow-key focus, player shortcuts)
- Tooltips on player icon buttons, Semantics on content cards
- Remove 7 dead widgets broken since the Stitch merge
Quality:
- bin/test/: 21 unit tests (bcrypt, redaction, traversal, SSRF, recording
conflicts) plus a quality-selector widget test
- GitHub Actions CI (analyze + test + build web)
- Archive stale status docs into docs/archive/
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
player_lite (Live TV desktop) ignored set_volume messages from Flutter,
so mute/unmute button had no effect. Added handler matching player.html.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Replace deprecated GlassContainer(opacity:/hasBorder:) calls in
dashboard_screen.dart and player_screen.dart with .glass() constructor.
- Fix epg_grid_screen.dart missing provider import and Playlist type mismatch.
- Delete broken/unreferenced files: network_service.dart, epg_grid_screen.dart.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Resolved conflicts by keeping remote functional features (RecordingScheduler,
FFmpeg HLS transcoding, mobile player, channel cards) and restoring local
Stitch theme foundation (app_colors, app_theme, glass_container, mobile_theme).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Replace the legacy Apple TV-style purple/cyan theme with the full
Google Stitch Cyber-Cinematic Glass design system across the
entire app (desktop + mobile).
- New Material 3 dark ColorScheme: background #121317, primary
#adc6ff, primaryContainer #4b8eff, surface containers, etc.
- Typography: Space Grotesk (headlines) + Inter (body/labels)
- 3-level glassmorphism via GlassContainer: base, glass, floating
- Primary gradient: #007AFF → #00C6FF with blue glow effects
- Removed old compatibility aliases (focusColor, border, textPrimary,
textSecondary); all code now uses semantic Stitch tokens
- Systematically replaced all Colors.white/black/red/grey and
GoogleFonts.roboto/outfit with Stitch equivalents
- All 36 lib/ files updated, zero compilation errors
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Removed TabBar/TabBarView complexity
- Keep only recordings list display
- Simplified to show only recordings without guide TV and season passes tabs
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
- tv_channel_grid.dart: guard screenWidth <= 0 / NaN / Infinite on first
Flutter Web layout pass (previously caused NaN ~/ 225.03 crash cascade).
Also use .clamp(1.0, infinity) on item width for belt-and-suspenders safety.
Fix invalid 'padding.vertical as double?' cast in TvHorizontalList by using
padding.resolve(TextDirection.ltr).top instead.
- playlist_api_service.dart: remove silent catch-and-return-empty in
getPlaylists(). Exceptions now propagate to the Riverpod FutureProvider
so the UI shows the real error state (with Retry button) instead of
a misleading 'No playlists available' when the API call actually failed
(e.g., 401 Unauthorized or network error).
Fixed playlist loading failure by ensuring the auth token is automatically
restored from localStorage when ApiClient initializes. Previously, the token
was stored but never restored, causing 401 Unauthorized errors on API calls.
Added _restoreTokenFromStorage() method to ApiClient constructor to load
and apply stored token immediately on app startup. This ensures all API
calls (including playlist fetching) have proper authentication.
Fixes: "I still don't have a playlist" issue where playlists were not loading
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Fixed NaN error in TvChannelGrid width calculation by properly resolving
EdgeInsetsGeometry to concrete values before arithmetic operations.
EdgeInsetsGeometry.horizontal can return NaN/infinity, causing invalid
width calculations.
Changed from: padding.horizontal
To: padding.resolve(TextDirection.ltr).left + padding.resolve(TextDirection.ltr).right
This ensures we get concrete padding values before division operations.
Fixes: Unsupported operation: Result of truncating division is NaN: NaN ~/ 225.0357142857143
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Fixed NaN errors in FFmpeg bitrate argument generation by ensuring integer
conversion happens before integer division. The double multiplication (1.5, 2.0)
was happening before the ~/ operator, causing NaN values. Now properly converts
to int first, then divides.
- maxRateArg: ((bitrateBps * 1.5).toInt() ~/ 1000)
- bufferSizeArg: ((bitrateBps * 2).toInt() ~/ 1000)
Fixes: Unsupported operation: Result of truncating division is NaN
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Dashboard now has visible Apple TV-style glows:
- Teal glow (top-left): 40% opacity (was 25%)
- Blue glow (bottom-right): 35% opacity (was 15%)
- Larger glow sizes (800x800, 700x700) for better coverage
- Improved gradient background for depth
Changes:
- dashboard_screen.dart: increase glow opacity and size
- Add multi-stop gradients for smooth falloff
Result: Premium Apple TV background with visible glows instead of pure black
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
- Enhance category card gradient with teal accent (AppColors.primary)
- Add premium ambient glows to dashboard (teal + blue)
- Replace flat black background with subtle gradient for depth
- Increase glow intensity and size for better visual impact
- Apple TV inspired premium dark theme with accent lighting
Changes:
- live_tv_tab.dart: category gradient now uses AppColors.primary
- dashboard_screen.dart: add dual-glow background with premium styling
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>