mirror of
https://github.com/R0m1k3/xtremflow.git
synced 2026-10-11 17:30:00 +02:00
Security: - Replace unsalted SHA-256 password hashing with bcrypt (lazy rehash on login) - Add authenticated /api/xtream-api gateway: Xtream credentials are injected server-side and never sent to the frontend; /api/playlists no longer returns passwords - Redact credentials from all logs (login body, proxy/FFmpeg/scheduler URLs) - Add auth to recordings, EPG, season-passes and streaming routes (HttpOnly session cookie for hls.js; loopback bypass for local FFmpeg) - Lock player postMessage to same-origin in both directions - Vendor and pin hls.js 1.6.7 / mpegts.js 1.7.3 (drop CDN @latest) - Fix rate limiter (client IP was never resolved), add login rate limit, restrict CORS, add CSP Report-Only, block private-IP SSRF targets, fix path traversal in recording log retrieval, chmod 777 -> 770 - Remove dead HiveService (seeded admin/admin into IndexedDB with SHA-256) - Fix authMiddleware not populating 'user' context (getPlaylist ignored the logged-in user; admin purge always returned 403) Streaming: - New FfmpegSessionManager: process registry, idle reaper (4 min live / 15 min VOD), orphan cleanup at startup, clean SIGTERM shutdown, fast-fail with stderr instead of 30 s timeout - Quality selection (source/high/medium/low) for live and VOD; source mode streams with -c:v copy (zero transcoding); selector wired into the player - Concurrent recordings (MAX_CONCURRENT_RECORDINGS, default 2); conflicts retry on the next tick instead of silently failing - Lower live latency (HLS window 20 -> 10 segments, liveSync 10 -> 3) - Fix recording log lookup (.mp4 vs .mkv mismatch) Design: - Replace hardcoded colors with AppColors tokens (12 files) - web/theme.css syncs HTML players with the Flutter palette - DPAD/keyboard navigation (arrow-key focus, player shortcuts) - Tooltips on player icon buttons, Semantics on content cards - Remove 7 dead widgets broken since the Stitch merge Quality: - bin/test/: 21 unit tests (bcrypt, redaction, traversal, SSRF, recording conflicts) plus a quality-selector widget test - GitHub Actions CI (analyze + test + build web) - Archive stale status docs into docs/archive/ Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1.7 KiB
1.7 KiB
Activation de l'Agent Bmad Master
Context
Activation de l'agent Bmad Master pour coordonner les modules BMAD et gérer le flux de travail du projet xtremflow.
Current Focus
Refonte du Guide TV pour inclure les catégories et corriger l'EPG.
Master Plan
- Analyser le workflow Bmad Master (
bmad-core-agents-bmad-master.md) - Configurer l'environnement pour l'agent Master
- Initialiser la session avec l'agent Master
- Correction initiale du parsing EPG
- Suppression du tri alphabétique forcé
- Refonte du Guide TV (Catégories + EPG détaillé)
- Correction de l'endpoint EPG Backend (Fallback)
- Correction du lecteur Mobile (LitePlayerView)
- Alignement UI Mobile (Tri, EPG, URLs)
- Correction Connectivité Mobile (Auto-origin + Manuel Override)
- Compatibilité Streaming iOS (HLS Live + Proxy Streaming)
- Correction Chemins HLS Relatifs (Bug chemins absolus FFmpeg)
- Résolution Erreur 502 Proxy (Nettoyage Headers + API Buffer)
- Optimisation HLS iOS (Force Keyframes + Anti-Empty Playlist)
- Support Plein Écran Mobile (Orientations Landscape + UI Auto-hide)
Progress Log
- Identification du workflow dans
.agent/workflows/bmad/ - Lecture du workflow et de la configuration
- Validation du plan d'activation par Michael
- Activation de l'identité Bmad Master
- Correction initiale du parsing EPG
- Suppression du tri alphabétique forcé
- Refonte du Guide TV avec catégories
- Implémentation du fallback EPG Backend vers get_short_epg
- Diagnostic de l'incompatibilité du lecteur mobile
- Remplacement du lecteur Web par LitePlayerView sur mobile