mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-09 01:16:15 -08:00
test(stalker): serialize the portal specs and bind mocks to loopback
Review follow-up on #1324 (Codex, 4xP2): - Parallel-reset race: under the workspace `fullyParallel` preset the new auth file ran concurrently with stalker.e2e.ts against one shared mock process, and each `beforeEach` wiped global state (sessions, favorites) mid-assertion in the other. Reproduced locally: both suites green in isolation, two failures when run together. Merged the auth tests into stalker.e2e.ts and pinned the file to `mode: 'serial'`, which also removes the pre-existing race between that file's own tests. 19/19 green across three consecutive runs. - Watchdog was recorded but never asserted, so the suite would stay green if the full-portal workflow stopped pinging or dropped its token — `sendWatchdogPing` swallows failures. Now polls for an authenticated `get_events`. - Both mock servers listened on every interface (stalker: `listen(PORT)` with no host; xtream: an explicit `0.0.0.0` default), which made the CodeQL exclusion's "binds to localhost" rationale untrue. Both now default to `127.0.0.1` with a `HOST` opt-in, and the config comment states plainly what the directory-wide ignore trades away. - Documented that the login-required scenario is HTTP-level only for now: the client's `do_auth` path is dormant and sends empty credentials, so the fixture is waiting on that client-side work rather than claiming end-to-end coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
ad27c06396
commit
4b31f71672
7 files changed
+269
-280
No files matched your search
@@ -1,16 +1,20 @@
|
||||
name: 'IPTVnator CodeQL config'
|
||||
|
||||
# The mock servers are development/E2E fixtures. They bind to localhost, serve
|
||||
# fabricated data, ship in no released artifact, and deliberately imitate the
|
||||
# quirks of the upstream IPTV protocols — including reading a session token
|
||||
# from a GET query string, which is what the real Stalker backend proxy does
|
||||
# and therefore what the app must be tested against.
|
||||
# The mock servers are development/E2E fixtures. They bind to loopback by
|
||||
# default (HOST=0.0.0.0 is an explicit opt-in for pointing a phone/STB at
|
||||
# them), serve fabricated data, ship in no released artifact, and deliberately
|
||||
# imitate the quirks of the upstream IPTV protocols — including reading a
|
||||
# session token from a GET query string, which is what the real Stalker
|
||||
# backend proxy does and therefore what the app must be tested against.
|
||||
#
|
||||
# CodeQL's web-service hygiene rules (missing rate limiting, sensitive data in
|
||||
# GET requests) assume an internet-facing service and produce only false
|
||||
# positives here; a rate limiter on a fixture that the E2E suite hammers would
|
||||
# actively break the tests. Injection, path-traversal and similar rules still
|
||||
# apply to everything the app itself ships.
|
||||
# actively break the tests. paths-ignore is all-or-nothing per path — CodeQL
|
||||
# has no per-path rule filter — so this deliberately trades away injection/
|
||||
# path-traversal coverage for the two fixture apps, which parse no input
|
||||
# beyond the local test driver. Everything the app itself ships keeps full
|
||||
# coverage.
|
||||
paths-ignore:
|
||||
- apps/stalker-mock-server
|
||||
- apps/xtream-mock-server
|
||||
Reference in new issue
Block a user