mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 18:36:15 -08:00
docs(stalker): tighten the token-revalidation trade-off wording
Greptile review feedback: the watchdog mitigation was the most important part of that paragraph and sat behind the caveat. It now follows the MAC-sharing vector directly, and the paragraph ends by naming what is actually left uncovered — a same-host static stream played while no watchdog is up — so a future reader can size the residual without re-deriving it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
dd8d2705a7
commit
041abeb4d7
1 file changed
+4
-3
@@ -401,9 +401,10 @@ an authorization failure. This is narrower than it sounds: per the 4.9.35
|
||||
reference, handshake tokens have **no TTL**, and failing to send the watchdog
|
||||
does **not** invalidate auth (it only clears the admin panel's "online"
|
||||
status). The one real vector left is another device performing `get_profile`
|
||||
on the same MAC — common enough on shared subscriptions. Where a watchdog is
|
||||
running it still self-heals within a ping cycle, because the ping goes through
|
||||
`makeAuthenticatedRequest`.
|
||||
on the same MAC — common enough on shared subscriptions, but wherever a
|
||||
watchdog is running it still self-heals within a ping cycle, because the ping
|
||||
goes through `makeAuthenticatedRequest` too. What is left uncovered is a
|
||||
same-host static stream played while no watchdog is up.
|
||||
|
||||
Revalidating on every static playback would cost exactly the round trip this
|
||||
section exists to remove, so it is deliberately not done here. The right home
|
||||
|
||||
Reference in new issue
Block a user