Commit Graph
100 Commits
Author SHA1 Message Date
MichaelandClaude Fable 5 e332895d7d feat(design): Projector Noir theme - tungsten amber on film-black
Full visual refonte replacing the generic neon-blue glass look:

- palette: warm film-black surface ladder, tungsten amber primary,
  warm taupe secondary, verdigris teal tertiary; semantic and
  category colors retuned to match (coral live, gold movies)
- typography: Syne (display/headlines) + Instrument Sans (body/UI)
  replace Space Grotesk/Inter/Outfit across all screens
- glassmorphism tokens warmed (amber inner glow, warm-white borders)
- web player theme.css + index.html loader mirror the new tokens
- hardcoded Colors.blue* in streaming settings and recordings tabs
  now use AppColors tokens
- DESIGN_SYSTEM.md updated to v3.0 Projector Noir

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 14:52:45 +02:00
MichaelandClaude Fable 5 9595afcc99 fix(streaming): stop streams dying mid-playback
- reaper no longer kills exited sessions immediately: a finished VOD
  transcode was reaped (segments deleted) while still being watched
- reuse completed VOD/recording sessions instead of re-transcoding
- live input: add -rw_timeout 30s and -reconnect_at_eof so a stalled
  upstream triggers reconnect instead of wedging ffmpeg forever
- reaper watchdog restarts live sessions whose playlist stopped updating
- waitForPlaylist fails fast on clean ffmpeg exit without output
- direct .ts proxy: close http.Client on stream end/error (socket leak)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 14:34:31 +02:00
MichaelandClaude Fable 5 92634dba13 perf: faster stream startup
- Stop sending no-store on vendored player libraries: hls.min.js and
  mpegts.min.js (~750 KB) were re-downloaded on every player open
- hls.js: start with 1 live segment instead of 3, lower buffer-first
  threshold 1.5s -> 0.8s, poll buffer every 100ms
- mpegts.js: initial stash 512KB -> 128KB, start at 0.5s buffered
- Live FFmpeg: -hls_init_time 1 closes the first segment after ~1s

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 11:23:32 +02:00
MichaelandClaude Fable 5 dcf1c00cca chore: prod compose back to GHCR image (publish workflow fixed)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 11:05:34 +02:00
MichaelandClaude Fable 5 a49b0d94c8 fix(docker): stop ignoring entrypoint.sh
.dockerignore excluded entrypoint.sh while the Dockerfile COPYs it into
the runtime stage; buildx (docker-container driver) fails hard on this
where the legacy builder only warned.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:59:24 +02:00
MichaelandClaude Fable 5 b749960d26 fix: stream auth middleware blocked non-streaming requests
streamAuthMiddleware wrapped the whole streaming router inside the
Cascade, so any unmatched path without a session (e.g. GET / through the
reverse proxy) returned 401 before reaching the static file handler.
Now only /api/live, /api/vod and /api/recordings/stream are guarded;
other paths fall through to the router's 404 and the Cascade continues.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:58:11 +02:00
MichaelandClaude Fable 5 29c40239db chore: prod compose builds from GitHub until GHCR publish is fixed
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:51:56 +02:00
MichaelandClaude Fable 5 3904a1b9c8 chore: add production compose using GHCR image
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:46:20 +02:00
MichaelandClaude Fable 5 066de08cf7 ci: publish Docker image to GHCR on push to main
Builds and pushes ghcr.io/r0m1k3/xtremflow:latest (+ sha tag) so update
managers (Unraid/Watchtower/Portainer) can detect new images instead of
relying on a local build context.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:35:07 +02:00
MichaelandClaude Fable 5 2e6bc7c7d6 chore: untrack local Claude settings
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:17:54 +02:00
MichaelandClaude Fable 5 969d40dec5 fix(ci): exclude bin/ from root analyzer and clean remaining warnings
The frontend CI job ran `flutter analyze` from the repo root, which also
analyzed the bin/ server package without its dependencies resolved
(shelf_router, sqlite3, bcrypt, test), producing hundreds of
uri_does_not_exist errors. bin/ is a standalone package covered by the
backend job, so it is now excluded from root analysis.

Also:
- Remove all unused fields/variables flagged as analyzer warnings
  (api_client, cache_service, player_screen, subtitle_service,
  live_tv_tab, mobile screens)
- Run `flutter analyze --no-fatal-infos` in CI: pre-existing deprecation
  infos (withOpacity, dart:html) stay non-fatal while errors and warnings
  still fail the build

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:17:40 +02:00
MichaelandClaude Fable 5 60d3f42901 feat: security hardening, streaming overhaul, design polish, tests
Security:
- Replace unsalted SHA-256 password hashing with bcrypt (lazy rehash on login)
- Add authenticated /api/xtream-api gateway: Xtream credentials are injected
  server-side and never sent to the frontend; /api/playlists no longer
  returns passwords
- Redact credentials from all logs (login body, proxy/FFmpeg/scheduler URLs)
- Add auth to recordings, EPG, season-passes and streaming routes
  (HttpOnly session cookie for hls.js; loopback bypass for local FFmpeg)
- Lock player postMessage to same-origin in both directions
- Vendor and pin hls.js 1.6.7 / mpegts.js 1.7.3 (drop CDN @latest)
- Fix rate limiter (client IP was never resolved), add login rate limit,
  restrict CORS, add CSP Report-Only, block private-IP SSRF targets,
  fix path traversal in recording log retrieval, chmod 777 -> 770
- Remove dead HiveService (seeded admin/admin into IndexedDB with SHA-256)
- Fix authMiddleware not populating 'user' context (getPlaylist ignored the
  logged-in user; admin purge always returned 403)

Streaming:
- New FfmpegSessionManager: process registry, idle reaper (4 min live /
  15 min VOD), orphan cleanup at startup, clean SIGTERM shutdown,
  fast-fail with stderr instead of 30 s timeout
- Quality selection (source/high/medium/low) for live and VOD; source mode
  streams with -c:v copy (zero transcoding); selector wired into the player
- Concurrent recordings (MAX_CONCURRENT_RECORDINGS, default 2); conflicts
  retry on the next tick instead of silently failing
- Lower live latency (HLS window 20 -> 10 segments, liveSync 10 -> 3)
- Fix recording log lookup (.mp4 vs .mkv mismatch)

Design:
- Replace hardcoded colors with AppColors tokens (12 files)
- web/theme.css syncs HTML players with the Flutter palette
- DPAD/keyboard navigation (arrow-key focus, player shortcuts)
- Tooltips on player icon buttons, Semantics on content cards
- Remove 7 dead widgets broken since the Stitch merge

Quality:
- bin/test/: 21 unit tests (bcrypt, redaction, traversal, SSRF, recording
  conflicts) plus a quality-selector widget test
- GitHub Actions CI (analyze + test + build web)
- Archive stale status docs into docs/archive/

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:07:18 +02:00
MichaelandClaude Opus 4.7 b985f11704 fix: resolve all compile errors from Stitch theme merge
- Add missing AppTheme animation constants (durationSm/Md/Lg/Xl, curveSmooth)
  to satisfy remote widget references.
- Replace deprecated GlassContainer(opacity:) with .glass()/.floating()/.base()
  in login_screen, live_tv_tab, mobile_live_tv_tab, player_screen,
  dashboard_screen.
- Fix const-eval errors by removing const from BorderSide/Text/BoxDecoration
  using AppColors.focusColor and AppColors.border (runtime getters).
- Fix subtitle_service.dart: padEnd → padRight (Dart String API).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-28 07:37:37 +02:00
MichaelandClaude Opus 4.7 60228f5576 fix: resolve GlassContainer API mismatch and broken remote files
- Replace deprecated GlassContainer(opacity:/hasBorder:) calls in
  dashboard_screen.dart and player_screen.dart with .glass() constructor.
- Fix epg_grid_screen.dart missing provider import and Playlist type mismatch.
- Delete broken/unreferenced files: network_service.dart, epg_grid_screen.dart.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-28 07:24:41 +02:00
MichaelandClaude Opus 4.7 2ba16caf55 Merge remote-tracking branch 'origin/main' into main
Resolved conflicts by keeping remote functional features (RecordingScheduler,
FFmpeg HLS transcoding, mobile player, channel cards) and restoring local
Stitch theme foundation (app_colors, app_theme, glass_container, mobile_theme).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-27 22:17:52 +02:00
MichaelandClaude Opus 4.7 f7eaa724e2 feat(theme): complete redesign to Cyber-Cinematic Glass (Stitch)
Replace the legacy Apple TV-style purple/cyan theme with the full
Google Stitch Cyber-Cinematic Glass design system across the
entire app (desktop + mobile).

- New Material 3 dark ColorScheme: background #121317, primary
  #adc6ff, primaryContainer #4b8eff, surface containers, etc.
- Typography: Space Grotesk (headlines) + Inter (body/labels)
- 3-level glassmorphism via GlassContainer: base, glass, floating
- Primary gradient: #007AFF → #00C6FF with blue glow effects
- Removed old compatibility aliases (focusColor, border, textPrimary,
  textSecondary); all code now uses semantic Stitch tokens
- Systematically replaced all Colors.white/black/red/grey and
  GoogleFonts.roboto/outfit with Stitch equivalents
- All 36 lib/ files updated, zero compilation errors

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-27 22:06:29 +02:00
Michael 9755f51af5 fix(ui): prevent NaN division crash in TvChannelGrid and fix playlist silent failure
- tv_channel_grid.dart: guard screenWidth <= 0 / NaN / Infinite on first
  Flutter Web layout pass (previously caused NaN ~/ 225.03 crash cascade).
  Also use .clamp(1.0, infinity) on item width for belt-and-suspenders safety.
  Fix invalid 'padding.vertical as double?' cast in TvHorizontalList by using
  padding.resolve(TextDirection.ltr).top instead.

- playlist_api_service.dart: remove silent catch-and-return-empty in
  getPlaylists(). Exceptions now propagate to the Riverpod FutureProvider
  so the UI shows the real error state (with Retry button) instead of
  a misleading 'No playlists available' when the API call actually failed
  (e.g., 401 Unauthorized or network error).
2026-03-26 16:24:18 +01:00
Michael 8c65e48bbe feat: Implement Xtream IPTV API service, including data fetching, caching, and proxy integration. 2026-03-10 16:48:28 +01:00
Michael f5b3457390 refactor: Consolidate Flutter web and Dart server compilation into a single Docker build stage for streamlined dependency management. 2026-03-10 16:25:46 +01:00
Michael 8098e024a9 build: optimize docker caching strategy to avoid redundant installs 2026-03-10 16:05:47 +01:00
Michael 36a74d9e97 fix: increase default timeouts and ensure they are applied to XtreamService 2026-03-10 15:44:04 +01:00
Michael 16b4bfc17a build: change compose context to local for reliable builds 2026-03-10 15:42:25 +01:00
Michael 1b022ba1d5 build: add verbosity and version tag to diagnose hang 2026-03-10 15:41:37 +01:00
Michael 3499d6ec8c build: merge stages for stability 2026-03-10 15:07:34 +01:00
Michael 9f3c29f6dd feat: implement Xtream API service for managing live channels, VOD, and series with caching and dynamic backend URL handling. 2026-03-10 14:57:44 +01:00
Michael 36a4de2140 fix(compilation): resolved undefined 'options' variable and optimized Docker build 2026-03-10 13:06:40 +01:00
Michael e707bda597 feat: implement Xtream Codes API service for authentication, live channels, VOD, and series, including caching and URL proxying. 2026-03-10 12:14:47 +01:00
Michael 129bcadd37 feat: Add Xtream API service for IPTV features and precache web artifacts in Dockerfile. 2026-03-10 12:00:43 +01:00
Michael e4922d7fce Remove --no-pub, --no-wasm-dry-run, and --verbose flags from the flutter build web command in the Dockerfile. 2026-03-10 11:23:06 +01:00
Michael 4f6b5fe14e feat: Implement Xtream Codes API service for IPTV content and streamline the Dockerfile web build process. 2026-03-10 11:19:15 +01:00
Michael df33c02d1d chore: Optimize Docker build by expanding ignored files and improving Flutter web build caching. 2026-03-10 11:14:08 +01:00
Michael f9098e02ed feat: Increase DART VM heap size to 16GB and precache web artifacts for build optimization. 2026-03-10 10:55:51 +01:00
Michael 1432ca12bc feat: Introduce HLS streaming API with FFmpeg-based live and VOD transcoding, including GPU acceleration, and add web player files and an Xtream service. 2026-03-10 10:44:27 +01:00
Michael 33d0e0a80d fix(streaming): optimize quality, audio sync, and content update refresh
- Increased FFmpeg video quality to 8Mbps and audio to 192kbps.
- Added audio resync filters and better presets.
- Optimized HLS buffer settings for mobile players to reduce interruptions.
- Reduced API cache duration to 15m and added refresh support for faster content updates.
2026-03-10 10:26:24 +01:00
Michael 33c6385d7e feat: introduce mobile player screen and lite player view with channel zapping functionality 2026-03-09 14:52:41 +01:00
Michael 4d1e08148b feat: implement mobile live TV tab with channel browsing, search, and a dedicated player screen supporting channel zapping. 2026-03-09 14:32:41 +01:00
Michael 12b799a7fd feat: introduce LitePlayerView for video playback with custom zapping controls and mobile fullscreen support. 2026-03-09 14:18:51 +01:00
Michael c57273be2c feat: Implement GPU-accelerated live HLS streaming with FFmpeg, including iOS optimizations and IPTV redirect resolution. 2026-03-09 14:10:13 +01:00
Michael d0a2a1ee6a feat: Implement Xtream proxy handler with SSRF protection and M3U8 URL rewriting, resolving 502 proxy errors. 2026-03-09 14:00:28 +01:00
Michael c9a212ec4f feat: implement live HLS streaming with FFmpeg transcoding, GPU acceleration, and HLS segment serving. 2026-03-09 13:52:46 +01:00
Michael 0b5aa3f9e4 feat: Implement initial streaming handler for live and VOD content using FFmpeg HLS transcoding with GPU acceleration support. 2026-03-09 13:46:56 +01:00
Michael bd7645922d feat: add Xtream API proxy with SSRF protection and streaming handler with FFmpeg integration. 2026-03-09 13:41:56 +01:00
Michael 7eb483fc07 feat: introduce IPTV settings management with a dedicated mobile tab, providers, and service. 2026-03-09 13:31:01 +01:00
Michael 7ea12511a0 feat: implement mobile series tab with pagination, search, and filtering for IPTV series. 2026-03-09 13:20:00 +01:00
Michael 829c5751ca feat: implement initial mobile IPTV feature with player screen, live TV, movies, and series tabs, along with the Xtream API service. 2026-03-09 13:16:29 +01:00
Michael b1f887af69 feat: Implement EPG API with caching and Xtream get_epg to get_short_epg fallback for program data. 2026-03-09 11:36:40 +01:00
Michael 3232a3a226 feat: introduce EPG API with caching and TV & Recordings UI with EPG Guide, Recordings, and Season Passes tabs. 2026-03-09 10:47:30 +01:00
Michael fa88746db6 feat: introduce IPTV data models and initial Live TV UI, including EPG overlay. 2026-03-09 10:12:55 +01:00
Michael 758cbe4c43 feat: implement Xtream proxy handler with M3U8 URL rewriting, SSRF protection, and content type handling. 2026-01-07 11:31:40 +01:00
Michael 755367018a feat: Implement core server application with API routing, streaming, and static content serving. 2026-01-07 11:29:00 +01:00
Michael 1dd77bd87a feat: implement core server with API routing, middleware, and static file serving 2026-01-07 11:24:26 +01:00
Michael 5d4dfa5e05 fix: Add Docker entrypoint script with gosu to manage volume permissions and drop user privileges. 2026-01-07 11:09:42 +01:00
Michael a149bf266c chore: add detailed login logging and update startup message 2026-01-07 10:39:06 +01:00
Michael 948e405307 chore: bump cachebust to force docker rebuild 2026-01-07 10:31:59 +01:00
Michael 842862006a fix(proxy): remove auth requirement to allow browser image requests, keep ssrf protection 2026-01-07 10:16:52 +01:00
Michael 38572fa747 fix(auth): move auth check inside proxy handler after path filtering 2026-01-07 09:32:51 +01:00
Michael 37c23d575b fix(docker): use libsqlite3-dev to provide libsqlite3.so symlink for Dart FFI 2026-01-07 09:26:53 +01:00
Michael 5ad3ad9f9e fix(stream): validate streamId AFTER stripping extension 2026-01-07 09:23:37 +01:00
Michael e0612ba67f fix(docker): resolve server deps from bin/pubspec.yaml 2026-01-07 09:19:32 +01:00
Michael 3a633cd74d chore: update task.md to reflect current local Docker environment maintenance tasks. 2026-01-07 09:13:05 +01:00
Michael d1933f7500 merge: resolve Dockerfile conflict (kept optimization + nvenc support) 2026-01-07 08:44:50 +01:00
Michael 8df9a37baa feat: security overhaul (proxy ssrf fix, streaming sanitization, docker optimization) 2026-01-07 08:43:33 +01:00
Michael 7e5d50f258 feat: Add IPTV player screen for live, VOD, and series streams with comprehensive playback controls. 2026-01-03 10:57:22 +01:00
Michael 71630d75e8 feat: Install FFmpeg with NVIDIA NVENC/NVDEC support via apt-get instead of a static build. 2026-01-03 10:26:17 +01:00
Michael 33a331dce9 Fix GPU rollbacks v2 - aresample filter, copyts, larger buffers 2026-01-02 09:21:51 +01:00
Michael d93d638b1b Unified Live TV control bar - EPG + buttons in single bar 2026-01-02 09:14:57 +01:00
Michael 8670e42cf8 Fix GPU Live TV rollbacks - add vsync cfr, async, smaller buffer, faster keyframes 2026-01-02 09:01:14 +01:00
Michael f6d5ae7764 UI fixes: remove center play button from Native player, align EPG/controls in Live TV, match background colors 2026-01-02 08:59:52 +01:00
Michael 409878e173 Fix VOD GPU transcoding - remove hwaccel_output_format, use CBR mode for HLS 2026-01-01 23:33:02 +01:00
Michael cd3a49ce63 Fix GPU transcoding timeout - use CBR mode, increase timeouts, add keyframe interval 2026-01-01 23:27:04 +01:00
Michael a00d5ae4da Force GPU transcoding (h264_nvenc) for Live TV when GPU toggle is enabled 2026-01-01 23:19:48 +01:00
Michael 363fa14453 Add debug logging for GPU setting detection 2026-01-01 23:18:08 +01:00
Michael 2d4f687b4b Use BtbN FFmpeg build with NVENC/NVDEC hardware acceleration support 2026-01-01 20:30:20 +01:00
Michael b4c1cd919f Revert Dockerfile to stable dart:stable base, add GPU toggle in settings UI 2026-01-01 20:26:34 +01:00
Michael c77b100a4e feat: Switch Dockerfile base image to NVIDIA CUDA, install Dart SDK, and add NVENC-enabled FFmpeg. 2026-01-01 20:17:52 +01:00
Michael ce82b9e824 feat: Implement API handlers for live and VOD streaming and create database module. 2026-01-01 20:13:56 +01:00
Michael 72e28a398a feat: add IPTV player screen with HTML iframe integration for live, VOD, and series streams 2026-01-01 20:10:14 +01:00
Michael 478107f0a4 feat: Add streaming handlers for live and VOD content using FFmpeg. 2026-01-01 20:05:40 +01:00
Michael e27fa6fec3 feat: Add IPTV player screen supporting live, VOD, and series playback with interactive controls. 2026-01-01 19:56:31 +01:00
Michael aa75347d0a feat: implement IPTV player screen with web-based video playback, controls, and EPG overlay. 2026-01-01 19:43:14 +01:00
Michael 440f15faa6 feat: add IPTV player screen with support for live, VOD, and series streams using iframe-based playback. 2026-01-01 19:27:32 +01:00
Michael b6a0016c00 feat: implement IPTV PlayerScreen with embedded web player for live, VOD, and series streams. 2026-01-01 19:19:52 +01:00
Michael e74aa822ad feat: add IPTV player screen supporting live, VOD, and series stream playback via embedded web players. 2026-01-01 19:16:51 +01:00
Michael 1547b376e0 feat: Implement web-based video player screen with playback controls and stream type handling. 2026-01-01 19:04:11 +01:00
Michael 4ecfd4f48c feat: Implement IPTV player screen supporting live and VOD streams via iframe. 2026-01-01 18:48:26 +01:00
Michael e19f0638f7 feat: add PlayerScreen for IPTV playback with web player integration and controls. 2026-01-01 18:44:29 +01:00
Michael 83e43b9da8 feat: Implement IPTV player screen with playback controls and stream type handling. 2026-01-01 18:41:02 +01:00
Michael 30218cb1d0 feat: add TvFocusableCard widget for interactive focus and hover effects. 2026-01-01 18:37:42 +01:00
Michael 2d418e4e0c feat: Add playlist selection screen and basic web IPTV player. 2026-01-01 18:32:39 +01:00
Michael c165ff5d40 feat: Implement IPTV player screen with web iframe integration for live and VOD streams, utilizing player_lite.html for live TV. 2026-01-01 18:26:05 +01:00
Michael 79ad1243fa feat: Add a themed loading screen widget and a web-based HLS/MPEG-TS video player. 2026-01-01 18:21:54 +01:00
Michael be51118dc2 feat: add LiveTVTab for browsing live channels with search and favorites, and PlayerScreen for channel playback. 2026-01-01 18:17:35 +01:00
Michael a1a8810ddc feat: introduce streaming handlers for live TV proxy and VOD HLS transcoding using FFmpeg. 2026-01-01 18:12:45 +01:00
Michael d22350fb89 feat(ui): increase Live TV grid density
- Categories: 4 → 6 columns on desktop
- Channels: 5 → 8 columns on desktop
- Also bumped tablet values for better density
2026-01-01 15:52:55 +01:00
Michael d955ab9523 fix(live): transcode audio to AAC for browser compatibility
- Keep video as direct copy (low CPU)
- Transcode audio to AAC (supports AC3/EAC3/DTS sources)
- Downmix to stereo for 5.1 surround streams
2026-01-01 15:48:49 +01:00
Michael 9da60f2141 fix(live): optimize FFmpeg streaming for faster start with reliable audio
- Add -fflags +nobuffer+fastseek+genpts for instant stream start
- Keep probesize at 5MB for reliable audio detection
- Set analyzeduration to 3s for balanced speed/reliability
2026-01-01 15:48:01 +01:00
Michael f5093e8d0e feat: Add streaming handlers for live TV (MPEG-TS proxy) and VOD (HLS transcoding) using FFmpeg. 2026-01-01 15:44:57 +01:00
Michael 6d87ada2b8 Resolve merge conflicts by accepting remote changes from origin/main 2025-12-17 08:38:35 +01:00
Michael 88caf38c8f fix: remove unsupported max_reload FFmpeg option 2025-12-16 20:59:52 +01:00
Michael 04508c37af fix: let FFmpeg handle HTTP redirects natively - manual resolution consumed one-time tokens 2025-12-16 20:50:21 +01:00