Files
xtremflow/web/player_mobile.html
T
MichaelandClaude Fable 5 60d3f42901 feat: security hardening, streaming overhaul, design polish, tests
Security:
- Replace unsalted SHA-256 password hashing with bcrypt (lazy rehash on login)
- Add authenticated /api/xtream-api gateway: Xtream credentials are injected
  server-side and never sent to the frontend; /api/playlists no longer
  returns passwords
- Redact credentials from all logs (login body, proxy/FFmpeg/scheduler URLs)
- Add auth to recordings, EPG, season-passes and streaming routes
  (HttpOnly session cookie for hls.js; loopback bypass for local FFmpeg)
- Lock player postMessage to same-origin in both directions
- Vendor and pin hls.js 1.6.7 / mpegts.js 1.7.3 (drop CDN @latest)
- Fix rate limiter (client IP was never resolved), add login rate limit,
  restrict CORS, add CSP Report-Only, block private-IP SSRF targets,
  fix path traversal in recording log retrieval, chmod 777 -> 770
- Remove dead HiveService (seeded admin/admin into IndexedDB with SHA-256)
- Fix authMiddleware not populating 'user' context (getPlaylist ignored the
  logged-in user; admin purge always returned 403)

Streaming:
- New FfmpegSessionManager: process registry, idle reaper (4 min live /
  15 min VOD), orphan cleanup at startup, clean SIGTERM shutdown,
  fast-fail with stderr instead of 30 s timeout
- Quality selection (source/high/medium/low) for live and VOD; source mode
  streams with -c:v copy (zero transcoding); selector wired into the player
- Concurrent recordings (MAX_CONCURRENT_RECORDINGS, default 2); conflicts
  retry on the next tick instead of silently failing
- Lower live latency (HLS window 20 -> 10 segments, liveSync 10 -> 3)
- Fix recording log lookup (.mp4 vs .mkv mismatch)

Design:
- Replace hardcoded colors with AppColors tokens (12 files)
- web/theme.css syncs HTML players with the Flutter palette
- DPAD/keyboard navigation (arrow-key focus, player shortcuts)
- Tooltips on player icon buttons, Semantics on content cards
- Remove 7 dead widgets broken since the Stitch merge

Quality:
- bin/test/: 21 unit tests (bcrypt, redaction, traversal, SSRF, recording
  conflicts) plus a quality-selector widget test
- GitHub Actions CI (analyze + test + build web)
- Archive stale status docs into docs/archive/

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:07:18 +02:00

321 lines
11 KiB
HTML

<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">
<title>Mobile IPTV Player</title>
<!-- Vendored, pinned player libraries (no CDN dependency) -->
<script src="vendor/hls.min.js"></script>
<script src="vendor/mpegts.min.js"></script>
<link rel="stylesheet" href="theme.css">
<style>
* {
margin: 0;
padding: 0;
box-sizing: border-box;
-webkit-tap-highlight-color: transparent;
}
html, body {
background: var(--color-bg);
width: 100%;
height: 100%;
overflow: hidden;
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif;
}
#player-container {
width: 100%;
height: 100%;
position: relative;
display: flex;
justify-content: center;
align-items: center;
}
#video {
width: 100%;
height: 100%;
object-fit: contain;
background: var(--color-bg);
}
#loading {
position: absolute;
display: flex;
flex-direction: column;
align-items: center;
color: white;
z-index: 20;
text-shadow: 0 2px 4px rgba(0, 0, 0, 0.5);
}
.spinner {
width: 40px;
height: 40px;
border: 3px solid var(--color-border);
border-top-color: var(--color-accent);
border-radius: 50%;
animation: spin 0.8s cubic-bezier(0.4, 0, 0.2, 1) infinite;
margin-bottom: 12px;
}
@keyframes spin {
to { transform: rotate(360deg); }
}
/* Unmute button — shown when iOS plays muted */
#unmute-btn {
display: none;
position: absolute;
bottom: 32px;
left: 50%;
transform: translateX(-50%);
z-index: 30;
background: rgba(0, 0, 0, 0.75);
color: white;
border: 2px solid rgba(255, 255, 255, 0.6);
border-radius: 32px;
padding: 12px 28px;
font-size: 16px;
font-weight: 600;
letter-spacing: 0.5px;
cursor: pointer;
backdrop-filter: blur(10px);
-webkit-backdrop-filter: blur(10px);
pointer-events: auto;
}
#unmute-btn:active {
background: rgba(255, 255, 255, 0.2);
}
#error {
display: none;
position: absolute;
color: white;
text-align: center;
padding: 24px;
background: rgba(0, 0, 0, 0.85);
border-radius: 16px;
z-index: 30;
max-width: 80%;
border: 1px solid rgba(255, 255, 255, 0.1);
}
</style>
</head>
<body>
<div id="player-container">
<!-- muted + autoplay: iOS Safari autorise l'autoplay uniquement si muted -->
<video id="video" autoplay muted playsinline webkit-playsinline preload="auto"></video>
<!-- Bouton son — affiché après démarrage muted sur iOS -->
<button id="unmute-btn">🔇 Appuyer pour activer le son</button>
<div id="loading">
<div class="spinner"></div>
<div id="l-text" style="font-size: 14px; font-weight: 500;">Chargement...</div>
</div>
<div id="error">
<div style="font-size: 40px; margin-bottom: 12px;">⚠️</div>
<div id="err-msg" style="font-weight: 600;">Erreur de lecture</div>
<div id="err-sub" style="font-size: 12px; color: rgba(255,255,255,0.6); margin-top: 8px;">Vérifiez votre connexion</div>
</div>
</div>
<script>
const video = document.getElementById('video');
const loading = document.getElementById('loading');
const unmuteBtn = document.getElementById('unmute-btn');
const error = document.getElementById('error');
const params = new URLSearchParams(window.location.search);
const streamUrl = params.get('url');
const streamType = params.get('type') || 'live';
function log(m) { console.log('[MobilePlayer] ' + m); }
let retryCount = 0;
const maxRetries = 3;
function showError(code, msg) {
loading.style.display = 'none';
unmuteBtn.style.display = 'none';
error.style.display = 'block';
document.getElementById('err-msg').textContent = 'Erreur ' + code;
document.getElementById('err-sub').textContent = msg || 'Format non supporté ou lien expiré';
}
// Bouton son : user gesture DIRECT dans l'iframe → iOS accepte le unmute
unmuteBtn.addEventListener('click', (e) => {
e.preventDefault();
video.muted = false;
video.volume = 1.0;
unmuteBtn.style.display = 'none';
log('Unmuted by user');
window.parent.postMessage({ type: 'unmuted' }, window.location.origin);
});
video.addEventListener('touchend', () => {
window.parent.postMessage({ type: 'user_activity' }, window.location.origin);
});
video.addEventListener('playing', () => {
log('Video playing, muted=' + video.muted);
loading.style.display = 'none';
retryCount = 0;
// Si muted (iOS autoplay), afficher le bouton son
if (video.muted) {
unmuteBtn.style.display = 'block';
// Tenter de démueter automatiquement (fonctionne parfois après interaction)
video.muted = false;
if (video.muted) {
// iOS a refusé le unmute automatique — garder le bouton affiché
log('Unmute blocked by iOS, showing button');
} else {
unmuteBtn.style.display = 'none';
log('Auto-unmuted successfully');
}
}
});
video.addEventListener('error', () => {
const code = video.error?.code || '?';
const msg = video.error?.message || '';
log('Video error code=' + code + ' msg=' + msg + ' retry=' + retryCount);
if (retryCount < maxRetries) {
retryCount++;
log('Retry ' + retryCount + '/' + maxRetries + ' in 2s');
loading.style.display = 'flex';
error.style.display = 'none';
document.getElementById('l-text').textContent = 'Reconnexion ' + retryCount + '/' + maxRetries + '...';
setTimeout(startPlayback, 2000);
} else {
showError(code, msg);
}
});
function startPlayback() {
log('startPlayback: ' + streamUrl);
video.src = '';
video.load();
video.src = streamUrl;
video.load();
video.play().catch(e => {
log('play() rejected: ' + e);
// Ne pas montrer erreur ici — laisser l'event error gérer
});
}
function initHlsJs() {
log('Using HLS.js');
const hls = new Hls({
maxBufferLength: 30,
maxMaxBufferLength: 60,
liveSyncDurationCount: 5,
liveMaxLatencyDurationCount: 10,
enableWorker: true,
lowLatencyMode: false,
nudgeOffset: 0.8,
nudgeMaxRetries: 10,
manifestLoadingRetryDelay: 1000,
levelLoadingRetryDelay: 1000
});
hls.loadSource(streamUrl);
hls.attachMedia(video);
hls.on(Hls.Events.MANIFEST_PARSED, () => {
log('HLS manifest parsed');
video.play().catch(() => log('HLS autoplay blocked'));
});
hls.on(Hls.Events.ERROR, (e, d) => {
log('HLS error type=' + d.type + ' fatal=' + d.fatal);
if (d.fatal) {
if (d.type === Hls.ErrorTypes.NETWORK_ERROR) hls.startLoad();
else if (d.type === Hls.ErrorTypes.MEDIA_ERROR) hls.recoverMediaError();
else showError(d.type, 'Erreur HLS fatale');
}
});
}
function initMpegts() {
log('Using MpegTS');
const player = mpegts.createPlayer({
type: 'mpegts',
isLive: streamType === 'live',
url: streamUrl
}, {
enableWorker: true,
stashInitialSize: 512 * 1024,
enableStashBuffer: true,
liveBufferLatencyChasing: false,
maxStashSize: 30 * 1024 * 1024
});
player.on(mpegts.Events.ERROR, (type, detail) => {
log('MpegTS error type=' + type);
showError(type, JSON.stringify(detail));
});
player.attachMediaElement(video);
player.load();
player.play().catch(() => log('MpegTS autoplay blocked'));
}
function init() {
if (!streamUrl) {
log('No stream URL');
showError('URL', 'Pas de lien de flux');
return;
}
log('Init: ' + streamUrl + ' type=' + streamType);
const isHLS = streamUrl.toLowerCase().includes('m3u8');
const isTS = streamUrl.toLowerCase().endsWith('.ts');
log('isHLS=' + isHLS + ' isTS=' + isTS);
// iOS Safari — HLS natif avec muted autoplay
if (isHLS && video.canPlayType('application/vnd.apple.mpegurl')) {
log('iOS Safari native HLS (muted autoplay)');
startPlayback();
return;
}
// Android/Chrome — HLS.js
if (isHLS && Hls.isSupported()) {
initHlsJs();
return;
}
// MpegTS fallback
if (mpegts.isSupported()) {
initMpegts();
return;
}
// Direct fallback
log('Direct fallback');
startPlayback();
}
// Messages depuis Flutter
window.addEventListener('message', (e) => {
if (e.origin !== window.location.origin) return;
const d = e.data;
if (!d) return;
if (d.type === 'play') video.play().catch(() => {});
if (d.type === 'pause') video.pause();
if (d.type === 'set_volume') {
video.muted = d.value === 0;
video.volume = d.value;
if (d.value > 0) unmuteBtn.style.display = 'none';
}
});
init();
</script>
</body>
</html>