fix(tmdb): surface TMDB-only VOD score in the rating badge, drop youtube.com from CSP

Review follow-ups on PR #1123: the Xtream VOD detail badge renders
rating_imdb, but the merge wrote the TMDB score only into `rating`, so a
TMDB-only score was never displayed (Codex P2) — fill rating_imdb when the
provider left it empty, mirroring the Stalker merge. All trailer iframes
are normalized to youtube-nocookie.com, so the extra youtube.com frame-src
allowance was dead surface (greptile) — removed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Fable 5 committed 2026-07-04 14:33:33 +02:00
1 parent 60be8a2999
commit aa92a3b826
3 files changed
+19 -1

No files matched your search

+1 -1
View File
@@ -8,7 +8,7 @@
<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta
http-equiv="Content-Security-Policy"
content="default-src 'self'; base-uri 'self'; object-src 'none'; frame-src https://www.youtube-nocookie.com https://www.youtube.com; form-action 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' http: https: file: data: blob:; font-src 'self' data:; media-src 'self' http: https: file: data: blob:; connect-src 'self' http: https: ws: wss: blob: data:; worker-src 'self' blob:"
content="default-src 'self'; base-uri 'self'; object-src 'none'; frame-src https://www.youtube-nocookie.com; form-action 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' http: https: file: data: blob:; font-src 'self' data:; media-src 'self' http: https: file: data: blob:; connect-src 'self' http: https: ws: wss: blob: data:; worker-src 'self' blob:"
/>
<meta property="og:type" content="website" />
<meta property="og:title" content="IPTVnator" />
@@ -185,6 +185,20 @@ describe('mergeVodInfoWithTmdb', () => {
expect(merged.rating).toBe(7);
});
it('fills the displayed rating_imdb field only when the provider left it empty', () => {
const withoutImdb = mergeVodInfoWithTmdb(
providerVodInfo({ rating_imdb: '' }),
tmdbMovie
);
expect(withoutImdb.rating_imdb).toBe('8.2');
const withImdb = mergeVodInfoWithTmdb(
providerVodInfo({ rating_imdb: '7.9' }),
tmdbMovie
);
expect(withImdb.rating_imdb).toBe('7.9');
});
it('fills missing provider release date and country', () => {
const info = providerVodInfo({ releasedate: '', country: '' });
const merged = mergeVodInfoWithTmdb(info, tmdbMovie);
+4
View File
@@ -147,6 +147,10 @@ export function mergeVodInfoWithTmdb(
director: prefer(director, info.director),
genre: prefer(genre, info.genre),
rating: rating ?? info.rating,
// The VOD detail badge renders rating_imdb — fill it when the
// provider left it empty so a TMDB-only score is actually shown
rating_imdb:
info.rating_imdb || (rating !== null ? String(rating) : ''),
releasedate: info.releasedate || (details.release_date ?? ''),
country: info.country || country,
movie_image: prefer(poster, info.movie_image),