[codex] Add scoped EPG security trust controls (#1054)

* Add scoped EPG security trust controls

* fix: address scoped trust review feedback

---------

Co-authored-by: 4gray <fourgray@proton.me>
This commit is contained in:
4grayand4gray authored and GitHub committed 2026-06-12 20:46:24 +02:00
1 parent 9043116ebd
commit e8aa7c3a34
56 files changed
+1683 -243

No files matched your search

+8 -5
View File
@@ -306,12 +306,15 @@ Useful narrower flags:
Security-sensitive network compatibility flags are opt-in:
- `IPTVNATOR_ALLOW_PRIVATE_NETWORK_URLS=1` permits EPG URLs that resolve to
localhost, LAN, or other private addresses. Leave this unset for playlists
you do not fully trust.
- `IPTVNATOR_ALLOW_PRIVATE_NETWORK_URLS=1` permits strict EPG fetches from
playlist metadata (`url-tvg`) to resolve to localhost, LAN, or other private
addresses. Directly configured Xtream/Stalker portals and private playlist
servers remain supported without this flag. Prefer the in-app source-scoped
“Allow source” action for a trusted EPG URL.
- `IPTVNATOR_ALLOW_INSECURE_TLS=1` disables certificate validation for remote
playlist imports and refreshes. Use it only for a trusted provider with a
self-signed or otherwise invalid certificate.
playlist imports and refreshes for the whole Electron process. Prefer the
in-app host-scoped trust action for a trusted provider with a self-signed or
otherwise invalid certificate.
If the local Nx daemon gets into a bad state before rerunning Electron, reset it: