mirror of
https://github.com/R0m1k3/xtremflow.git
synced 2026-10-11 17:30:00 +02:00
Security: - Replace unsalted SHA-256 password hashing with bcrypt (lazy rehash on login) - Add authenticated /api/xtream-api gateway: Xtream credentials are injected server-side and never sent to the frontend; /api/playlists no longer returns passwords - Redact credentials from all logs (login body, proxy/FFmpeg/scheduler URLs) - Add auth to recordings, EPG, season-passes and streaming routes (HttpOnly session cookie for hls.js; loopback bypass for local FFmpeg) - Lock player postMessage to same-origin in both directions - Vendor and pin hls.js 1.6.7 / mpegts.js 1.7.3 (drop CDN @latest) - Fix rate limiter (client IP was never resolved), add login rate limit, restrict CORS, add CSP Report-Only, block private-IP SSRF targets, fix path traversal in recording log retrieval, chmod 777 -> 770 - Remove dead HiveService (seeded admin/admin into IndexedDB with SHA-256) - Fix authMiddleware not populating 'user' context (getPlaylist ignored the logged-in user; admin purge always returned 403) Streaming: - New FfmpegSessionManager: process registry, idle reaper (4 min live / 15 min VOD), orphan cleanup at startup, clean SIGTERM shutdown, fast-fail with stderr instead of 30 s timeout - Quality selection (source/high/medium/low) for live and VOD; source mode streams with -c:v copy (zero transcoding); selector wired into the player - Concurrent recordings (MAX_CONCURRENT_RECORDINGS, default 2); conflicts retry on the next tick instead of silently failing - Lower live latency (HLS window 20 -> 10 segments, liveSync 10 -> 3) - Fix recording log lookup (.mp4 vs .mkv mismatch) Design: - Replace hardcoded colors with AppColors tokens (12 files) - web/theme.css syncs HTML players with the Flutter palette - DPAD/keyboard navigation (arrow-key focus, player shortcuts) - Tooltips on player icon buttons, Semantics on content cards - Remove 7 dead widgets broken since the Stitch merge Quality: - bin/test/: 21 unit tests (bcrypt, redaction, traversal, SSRF, recording conflicts) plus a quality-selector widget test - GitHub Actions CI (analyze + test + build web) - Archive stale status docs into docs/archive/ Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
193 lines
5.6 KiB
Dart
193 lines
5.6 KiB
Dart
import 'dart:async';
|
|
import 'dart:convert';
|
|
import 'dart:io';
|
|
|
|
/// One running FFmpeg transcoding session (live, VOD or recording playback).
|
|
class FfmpegSession {
|
|
final String id;
|
|
final Process process;
|
|
final Directory dir;
|
|
final bool isLive;
|
|
DateTime lastAccess = DateTime.now();
|
|
bool exited = false;
|
|
int? exitCode;
|
|
|
|
/// Last stderr lines, kept for fast-fail diagnostics.
|
|
final List<String> recentStderr = [];
|
|
|
|
FfmpegSession({
|
|
required this.id,
|
|
required this.process,
|
|
required this.dir,
|
|
required this.isLive,
|
|
});
|
|
|
|
void touch() => lastAccess = DateTime.now();
|
|
}
|
|
|
|
/// Registry of FFmpeg transcoding processes.
|
|
///
|
|
/// Responsibilities:
|
|
/// - one process per session id (`live_{id}_{quality}`, `vod_{id}`, ...)
|
|
/// - reaper kills sessions idle beyond a TTL (no viewer fetching segments)
|
|
/// - startup wipe of the HLS temp dir (orphan dirs after a crash)
|
|
/// - SIGTERM/SIGINT hook so `docker stop` leaves no orphan ffmpeg
|
|
class FfmpegSessionManager {
|
|
final Directory baseDir;
|
|
final Map<String, FfmpegSession> _sessions = {};
|
|
Timer? _reaper;
|
|
|
|
static const liveIdleTimeout = Duration(minutes: 4);
|
|
static const vodIdleTimeout = Duration(minutes: 15);
|
|
|
|
FfmpegSessionManager(this.baseDir);
|
|
|
|
/// Wipe orphan session dirs and start the reaper. Call once at startup.
|
|
Future<void> init() async {
|
|
if (baseDir.existsSync()) {
|
|
try {
|
|
baseDir.deleteSync(recursive: true);
|
|
} catch (e) {
|
|
print('[FFmpegManager] Could not wipe temp dir: $e');
|
|
}
|
|
}
|
|
baseDir.createSync(recursive: true);
|
|
|
|
_reaper = Timer.periodic(const Duration(seconds: 60), (_) => _reap());
|
|
|
|
// Clean shutdown for docker stop / Ctrl+C
|
|
ProcessSignal.sigterm.watch().listen((_) {
|
|
killAll();
|
|
exit(0);
|
|
});
|
|
ProcessSignal.sigint.watch().listen((_) {
|
|
killAll();
|
|
exit(0);
|
|
});
|
|
}
|
|
|
|
FfmpegSession? get(String id) => _sessions[id];
|
|
|
|
/// Marks a session as recently used (call from playlist AND segment routes).
|
|
void touch(String id) => _sessions[id]?.touch();
|
|
|
|
bool contains(String id) => _sessions.containsKey(id);
|
|
|
|
/// Returns the existing healthy session or starts a new FFmpeg process.
|
|
///
|
|
/// [argsBuilder] receives the session working directory and returns the
|
|
/// FFmpeg argument list. The session directory is recreated for new
|
|
/// sessions.
|
|
Future<FfmpegSession> getOrStart({
|
|
required String id,
|
|
required bool isLive,
|
|
required String ffmpegPath,
|
|
required List<String> Function(Directory dir) argsBuilder,
|
|
}) async {
|
|
final existing = _sessions[id];
|
|
if (existing != null && !existing.exited) {
|
|
existing.touch();
|
|
return existing;
|
|
}
|
|
if (existing != null) {
|
|
// Process died: clean up before restarting
|
|
killSession(id);
|
|
}
|
|
|
|
final dir = Directory('${baseDir.path}/$id');
|
|
if (dir.existsSync()) dir.deleteSync(recursive: true);
|
|
dir.createSync(recursive: true);
|
|
|
|
final args = argsBuilder(dir);
|
|
final process = await Process.start(
|
|
ffmpegPath,
|
|
args,
|
|
workingDirectory: dir.path,
|
|
);
|
|
|
|
final session = FfmpegSession(
|
|
id: id,
|
|
process: process,
|
|
dir: dir,
|
|
isLive: isLive,
|
|
);
|
|
_sessions[id] = session;
|
|
|
|
process.stderr.transform(utf8.decoder).listen((data) {
|
|
session.recentStderr.add(data);
|
|
if (session.recentStderr.length > 20) session.recentStderr.removeAt(0);
|
|
print('[FFmpeg $id] $data');
|
|
});
|
|
|
|
process.exitCode.then((code) {
|
|
session.exited = true;
|
|
session.exitCode = code;
|
|
print('[FFmpegManager] Session $id exited with code $code');
|
|
});
|
|
|
|
return session;
|
|
}
|
|
|
|
/// Waits until the session's playlist references at least one segment.
|
|
/// Fails fast when the process dies before producing output, returning
|
|
/// the recent stderr for diagnostics.
|
|
Future<({bool ready, String? error})> waitForPlaylist(
|
|
FfmpegSession session, {
|
|
Duration timeout = const Duration(seconds: 30),
|
|
}) async {
|
|
final playlistFile = File('${session.dir.path}/playlist.m3u8');
|
|
final deadline = DateTime.now().add(timeout);
|
|
|
|
while (DateTime.now().isBefore(deadline)) {
|
|
if (session.exited && session.exitCode != 0) {
|
|
return (
|
|
ready: false,
|
|
error: 'FFmpeg exited (${session.exitCode}): '
|
|
'${session.recentStderr.join().trim()}'
|
|
);
|
|
}
|
|
if (playlistFile.existsSync() &&
|
|
playlistFile.readAsStringSync().contains('.ts')) {
|
|
return (ready: true, error: null);
|
|
}
|
|
await Future.delayed(const Duration(milliseconds: 500));
|
|
}
|
|
return (ready: false, error: 'Timeout waiting for transcoder');
|
|
}
|
|
|
|
void killSession(String id) {
|
|
final session = _sessions.remove(id);
|
|
if (session == null) return;
|
|
try {
|
|
session.process.kill(ProcessSignal.sigterm);
|
|
} catch (_) {}
|
|
try {
|
|
if (session.dir.existsSync()) session.dir.deleteSync(recursive: true);
|
|
} catch (e) {
|
|
print('[FFmpegManager] Could not delete dir for $id: $e');
|
|
}
|
|
}
|
|
|
|
void killAll() {
|
|
print('[FFmpegManager] Killing ${_sessions.length} session(s)');
|
|
for (final id in _sessions.keys.toList()) {
|
|
killSession(id);
|
|
}
|
|
_reaper?.cancel();
|
|
}
|
|
|
|
void _reap() {
|
|
final now = DateTime.now();
|
|
for (final session in _sessions.values.toList()) {
|
|
final timeout = session.isLive ? liveIdleTimeout : vodIdleTimeout;
|
|
if (session.exited || now.difference(session.lastAccess) > timeout) {
|
|
print(
|
|
'[FFmpegManager] Reaping idle session ${session.id} '
|
|
'(idle ${now.difference(session.lastAccess).inSeconds}s)',
|
|
);
|
|
killSession(session.id);
|
|
}
|
|
}
|
|
}
|
|
}
|