Revert to the shields Codecov badge for visual consistency with the
other for-the-badge badges (native badge has no matching style). Pin
branch=master, add the Codecov logo, and keep the canonical
app.codecov.io link. Note: the shields Codecov proxy is occasionally
slow and may briefly render 'unknown'.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The shields.io Codecov proxy intermittently rendered 'unknown' (extra
API hop, cached by GitHub's camo). Switch to Codecov's native master
branch badge and point the link at app.codecov.io directly.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The single donation button used a 'Buy Me A Coffee' image that actually
linked to GitHub Sponsors. Split it into two correctly labeled badges:
GitHub Sponsors and Ko-fi (ko-fi.com/4gray, same as the blog).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The workflow status badge pointed at a non-existent build-and-test.yaml.
Point it at the actual CI workflow, link it to the workflow page, and
label it CI.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the flat feature list with seven themed groups, drop granular
release-note-level items, and surface recent capabilities (TMDB
enrichment, embedded MPV, download manager, global search, dashboard,
auto-updater, remote control) with desktop-only markers.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add blog post warning about scam sites misusing the IPTVnator name to
sell IPTV services or push suspicious downloads (official sources + safety)
- Add "official sources only" callout to README linking to the post
- Replace enumerated language list with a count (18) linking to i18n files
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(security): harden Electron IPC against MITM, SSRF, path and injection risks
S1 TLS: validate certs by default on playlist/EPG fetches (opt-out via IPTVNATOR_ALLOW_INSECURE_TLS); new util/secure-https.ts.
S2: write-file IPC restricted to save-dialog-authorized paths.
S3: XTREAM_PROBE_URL guarded by assertRemoteUrlAllowed + maxRedirects:0; new events/url-safety.ts (+19 tests).
S4: EPG titles rendered via interpolation, not [innerHTML].
S5: downloads reveal/play limited to recorded download paths.
S6: Stalker cmd encoded (slash-preserving) to block query injection.
EPG-worker and Stalker fetches reject file://-style/credentialed URLs; LAN/self-hosted targets remain allowed.
* perf(player): lazy-load web video players via @defer
Wrap Video.js/HTML5/ArtPlayer in @defer (on immediate) so video.js, hls.js,
artplayer and mpegts.js split into a deferred chunk loaded on first playback
instead of eagerly on the player route. Embedded MPV (native) stays eager.
Spec uses DeferBlockBehavior.Playthrough.
* fix(player): remove leaked HTML video listeners on destroy
volumechange used a mismatched removeEventListener reference, while
loadedmetadata and timeupdate were never removed at all. Bind all three to
stable handler fields used for both add and remove, and add a teardown
regression test asserting each listener is detached on destroy.
* refactor(dashboard): extract pure navigation helpers from DashboardDataService
Move the 8 stateless link/navigation-state/type-kind helpers into a new
dashboard-navigation.util.ts so the routing logic is independently testable and
the 1260-line god-service shrinks. DashboardDataService keeps the public methods
as thin delegators (facade) so the public API and the single consumer
(workspace-dashboard-rails) are unchanged. First slice of the DashboardDataService
decomposition; verified by the existing service spec (33/33) and the app typecheck.
* fix(review): address PR feedback (IPv6 link-local, write-path cap, @defer placeholder)
- url-safety: broaden IPv6 link-local detection to the full fe80::/10 range
(fe80:: through febf::), not just the fe80:: prefix (+ regression tests).
- playlist.events: cap authorizedWritePaths (evict oldest past 32) so a save
dialog opened without a following write cannot accumulate entries until restart.
- web-player-view: add a @placeholder to each @defer (on immediate) player block
to avoid the one-frame blank/layout-shift before the chunk resolves.
* fix(security): close Electron network and download gaps
* test(downloads): cover cancellation and restart cleanup
* fix(downloads): address Greptile review gaps
* test(security): reproduce remaining Greptile findings
* fix(security): close remaining Greptile findings
* test(downloads): reproduce early database queue stall
* fix(downloads): release queue after setup failures
* test(downloads): reproduce completion queue stall
* fix(downloads): release queue after completion failures
Adds a top-level TRADEMARK.md spelling out that the IPTVnator name and
logo are unregistered trademarks reserved to the project, separate from
the MIT-licensed source code, and documenting what forks may and may
not do plus where to report misuse. README gets a short Trademark
section pointing to the new file.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 3f453cc0085a
Add a Troubleshooting section to the README covering two common
platform-specific launch issues and how to resolve them.
- macOS: document Gatekeeper "App is damaged and can't be opened"
and show how to clear the quarantine flag with xattr.
- Linux: document chrome-sandbox SUID permission error and provide
two solutions — fix permissions (chown/chmod) for packaged installs,
or run with --no-sandbox by editing the desktop launcher or using the
command line.
These instructions reduce user confusion and support requests by
providing clear, actionable steps to get IPTVnator running on affected
systems.