Commit Graph
35 Commits
Author SHA1 Message Date
4grayandClaude Opus 4.8 23ead63b1f fix(packaging): ship ms so the updater doesn't crash the app (#1103) (#1113)
* fix(packaging): ship `ms` so the updater doesn't crash the app (#1103)

The 0.22 AppImage crashed on launch with "Cannot find module 'ms'" after
the desktop updater landed (b1119189). electron-updater requires
`debug` -> `ms` unguarded at startup, but the packaged app.asar shipped
`debug` without `ms`.

Root cause: with pnpm's isolated node-linker, electron-builder 26 uses its
PnpmNodeModulesCollector, which builds the bundle from `pnpm list --json`.
pnpm deduplicates repeated packages there, so all but one `debug@4.4.3`
occurrence report empty `dependencies` — and the collector (unlike the npm
collector) has no implicit-dependency recovery, so it drops `ms` entirely.
It stayed latent because the only prior `debug` consumer (follow-redirects
via axios) guards its require in try/catch; electron-updater is the first
packaged module to hit it unguarded.

Fix: declare `ms` as a direct dependency so it becomes a top-level,
fully-expanded node in the collector's tree and is bundled. This keeps the
isolated pnpm layout intact — `node-linker=hoisted` was rejected because it
removes `node_modules/.pnpm`, which apps/electron-backend/build-embedded-mpv.js
scans to resolve @electron/node-gyp, breaking the native build on every
platform.

Also add a packaged-asar dependency-closure guard to
verify-electron-package-layout.mjs: it audits every package shipped in the
archive and fails if any non-optional dependency is missing, so this class
of regression is caught in CI. Logic is extracted to a unit-tested module.

Verified locally: repackaged app.asar now ships `ms`, the embedded-mpv
native build succeeds, and the closure guard reports 0 missing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(packaging): harden asar dependency-closure guard from review findings

Addresses review feedback on #1113 plus an adversarial-review finding:

- Walk every ancestor directory in resolvePackagedDependency (not just
  node_modules boundaries) so a dependency hoisted to the archive root
  resolves for packages under app subdirectories, matching Node's real
  resolution (Codex review).
- Skip dependencies also declared in peerDependencies: host-provided
  peers (e.g. electron) listed in both fields are not packaging defects
  (Greptile review).
- Fix a silent no-op on Windows: @electron/asar lists entries and
  resolves extractFile paths with the host separator, so the posix-only
  matching audited zero packages on the Windows CI leg. Listings are now
  normalized to posix and lookup paths converted back to the host
  separator (pathSep is injectable for tests).
- Reject vacuous passes structurally: inspectPackagedDependencyClosure
  now reports packageCount and manifestReadFailures, and the verifier
  errors when the audit saw no packages or failed to read manifests,
  so the guard can never silently audit nothing again.

Verified: 27 packaging tests pass; the real app.asar audits 235 packages
with 0 missing under both posix and simulated win32 IO; hiding `ms` from
a win32-shaped listing correctly flags it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-01 23:58:21 +02:00
4gray b1119189e2 feat(updater): add GitHub releases desktop updater
Adds the GitHub Releases desktop updater with release notes, startup notification, packaging metadata, tests, and CI fixes for Electron E2E.
2026-06-28 22:21:20 +02:00
4grayandClaude Fable 5 8e0abe6feb feat(ui): custom title bar with window controls for Windows and Linux (#1042)
* feat(ui): add custom title bar window controls for Windows and Linux

Hide the native title bar on win32/linux (titleBarStyle: 'hidden', frame
untouched so native resize borders and snapping keep working) and render
minimize / maximize-restore / close buttons in the renderer, mirroring the
existing macOS traffic-light setup.

- New WINDOW:* IPC contract (minimize, toggle-maximize, close, get-state)
  handled in window.events.ts, resolved from the sender WebContents;
  close goes through win.close() so window-bounds persistence still runs.
- WINDOW:STATE_CHANGED pushed on maximize/unmaximize/fullscreen so the
  maximize/restore glyph stays correct for OS-triggered changes; controls
  hide while fullscreen.
- WindowControlsComponent mounts once in app-root as a manual popover so
  it stays in the browser top layer above CDK overlays (dialogs,
  multi-EPG) - same behavior as macOS traffic lights.
- Theme-aware via CSS vars (--app-on-surface, --app-hover-overlay);
  Windows-red close hover. Drag regions get right padding through a
  body-level frameless-platform class.
- Gated by RuntimeCapabilitiesService.usesCustomWindowControls; PWA and
  macOS never mount the controls.

Includes unit specs for the component and IPC handlers, an Electron E2E
suite (window-controls.e2e.ts), and a window-chrome section in
docs/architecture/workspace-shell.md.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(linux): upgrade Electron to 41 for frameless window decorations on Wayland

With the native title bar hidden, Linux windows lost the WM-drawn shadow
and rounded corners. Electron draws client-side decorations only on
native Wayland, and frameless-window CSD (GTK drop shadow + extended
resize boundaries) landed in Electron 41 - before that, frameless
windows render as plain rectangles.

- electron ^39.8.5 -> ^41.7.2 (Wayland auto-detected since 38.2; X11
  sessions remain undecorated, matching other frameless Electron apps;
  Windows keeps its DWM shadow and rounded corners).
- better-sqlite3 pinned to exactly 12.9.0: the last release shipping
  prebuilt binaries for both Node 20 (ABI 115, Jest) and Electron 41
  (ABI 145, runtime). 12.10.0 dropped the Node 20 prebuilds, forcing a
  from-source build that fails without a C++ toolchain.
- pnpm override node-abi 3.85.0 -> 3.92.0 so electron-builder
  install-app-deps can map Electron 41 to ABI 145.

Reviewed Electron 40/41 breaking changes: only the renderer clipboard
deprecation, which this app does not use.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(e2e): address review feedback and window-managerless Linux CI

- Skip the three window-manager-dependent E2E assertions (maximize
  toggle, main-process state sync, minimize) on Linux CI: GitHub's
  ubuntu runners drive Electron under xvfb without a window manager, so
  maximize/minimize state never materializes there. Windows CI and
  local Linux/macOS runs keep the coverage.
- WINDOW:TOGGLE_MAXIMIZE now returns the requested state instead of
  re-reading isMaximized() right after the call, which races on Linux
  window managers where maximize()/unmaximize() complete
  asynchronously; the WINDOW:STATE_CHANGED push stays authoritative.
- Skip attaching window-state push listeners on macOS, where the
  custom controls never mount and the IPC traffic had no subscriber.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ui): gate custom window controls on the full bridge surface

Include getWindowState and onWindowStateChange in the
usesCustomWindowControls capability check — the controls rely on both
for initial state and for keeping the maximize/restore glyph in sync
with OS-triggered changes, so a partial bridge should not mount them.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 12:03:27 +02:00
4grayand4gray ef900d0f2a [codex] Add scoped coverage reporting (#1024)
* add scoped coverage reporting

* fix coverage review feedback

---------

Co-authored-by: 4gray <fourgray@proton.me>
2026-06-06 17:41:40 +02:00
4gray 2184fd7c45 Merge pull request #899 from 4gray/dependabot/npm_and_yarn/axios-1.15.2
chore(deps): bump axios from 1.15.0 to 1.15.2
2026-05-22 17:23:27 +03:00
dependabot[bot] 3c7dbda398 chore(deps): bump serialize-javascript from 6.0.2 to 7.0.5
Bumps [serialize-javascript](https://github.com/yahoo/serialize-javascript) from 6.0.2 to 7.0.5.
- [Release notes](https://github.com/yahoo/serialize-javascript/releases)
- [Commits](https://github.com/yahoo/serialize-javascript/compare/v6.0.2...v7.0.5)

---
updated-dependencies:
- dependency-name: serialize-javascript
  dependency-version: 7.0.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-22 06:40:16 +00:00
4gray 32cc0b74e8 feat: add self-hosted PWA backend runtime (#944)
* feat(web-backend): add self-hosted proxy app

* feat(web): enable runtime PWA configuration

* test(web-e2e): cover self-hosted backend proxy

* test(web-e2e): clean self-hosted lint warnings

* fix(web-backend): validate proxied provider URLs

* fix(web-backend): proxy through registered provider targets

* fix(web-backend): document CodeQL SSRF validation boundary

* test(web-e2e): mock provider target registration

* fix(web): address self-hosted review feedback
2026-05-16 00:10:03 +02:00
dependabot[bot] 67b0e8b0b6 chore(deps): bump axios from 1.15.0 to 1.15.2
Bumps [axios](https://github.com/axios/axios) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.15.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-10 20:03:21 +00:00
4gray 1ca291d35c chore(nx): update Nx to 22.7.1 (#923)
* chore(nx): update Nx to 22.7.1
Entire-Checkpoint: f957cd9849e0

* fix(ci): patch nx-electron package metadata copy
Entire-Checkpoint: f957cd9849e0

* fix(packaging): preserve electron package metadata
Entire-Checkpoint: f957cd9849e0

* fix(packaging): address package verifier review
Entire-Checkpoint: f957cd9849e0
2026-05-10 22:01:25 +02:00
4gray 935ed1b1a9 fix(lockfile): remove duplicate minimatch snapshot 2026-05-10 11:06:06 +02:00
dependabot[bot] c84d65016a chore(deps): bump rollup from 4.52.3 to 4.59.0 (#796)
Bumps [rollup](https://github.com/rollup/rollup) from 4.52.3 to 4.59.0.
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rollup/rollup/compare/v4.52.3...v4.59.0)

---
updated-dependencies:
- dependency-name: rollup
  dependency-version: 4.59.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-10 10:53:26 +02:00
dependabot[bot] 5d66a04d05 chore(deps): bump immutable from 5.1.4 to 5.1.5 (#807)
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.4 to 5.1.5.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/immutable-js/immutable-js/compare/v5.1.4...v5.1.5)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-10 10:53:23 +02:00
dependabot[bot] a4fb202b62 chore(deps): bump svgo from 3.3.2 to 3.3.3 (#808)
Bumps [svgo](https://github.com/svg/svgo) from 3.3.2 to 3.3.3.
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](https://github.com/svg/svgo/compare/v3.3.2...v3.3.3)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-10 10:53:20 +02:00
dependabot[bot] 62f904ec86 chore(deps): bump express-rate-limit from 8.2.1 to 8.3.0 (#810)
Bumps [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) from 8.2.1 to 8.3.0.
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.2.1...v8.3.0)

---
updated-dependencies:
- dependency-name: express-rate-limit
  dependency-version: 8.3.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-10 10:53:17 +02:00
dependabot[bot] 23c74d6313 chore(deps): bump devalue from 5.6.2 to 5.6.4 (#818)
Bumps [devalue](https://github.com/sveltejs/devalue) from 5.6.2 to 5.6.4.
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/devalue/compare/v5.6.2...v5.6.4)

---
updated-dependencies:
- dependency-name: devalue
  dependency-version: 5.6.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-10 10:53:14 +02:00
dependabot[bot] 7da715c37f build(deps): bump @babel/plugin-transform-modules-systemjs (#915)
Bumps [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) from 7.28.5 to 7.29.4.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.4/packages/babel-plugin-transform-modules-systemjs)

---
updated-dependencies:
- dependency-name: "@babel/plugin-transform-modules-systemjs"
  dependency-version: 7.29.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-10 10:52:23 +02:00
4gray 04d2800ab1 chore: update dependencies
Entire-Checkpoint: c6e522b4276c
2026-04-21 00:19:23 +02:00
4gray 33583909db chore: update iptv-playlist-parser version and add libc specifications for various packages
- Updated iptv-playlist-parser version from 2b48764180edf25821dae3a4b1c9a6a7d0a3bf84 to 38a62d0b7c98f442bfa102ee8e1fe14169ae9386 in pnpm-lock.yaml.
- Added libc specifications for multiple packages targeting different architectures (arm64, arm, ppc64, riscv64, s390x, x64) to ensure compatibility with glibc and musl.
- Updated dependencies for minimatch and brace-expansion to their latest versions.

Entire-Checkpoint: c6e522b4276c
2026-04-20 00:26:10 +02:00
4gray b9ab4d5ab5 chore(deps): update pnpm version and remove unused electron-builder-sandbox-fix dependency
Entire-Checkpoint: 21b9b9f90f23
2026-04-12 11:47:34 +02:00
4gray d3e30056f6 refactor: remove deprecated moment dependency
Entire-Checkpoint: db35a98d337f
2026-04-11 10:38:52 +02:00
4gray 78de7dc125 chore(package): add unit test scripts and type checking commands; update font dependencies 2026-03-28 15:43:34 +01:00
markc1984 e3d1bf2048 fix: support raw MPEG-TS (.ts) streams in all embedded video players
Xtream Codes live streams with .ts format serve continuous raw MPEG-TS
data over HTTP, not HLS playlists. All three embedded players failed to
handle this: ArtPlayer had no handler, HTML5 player fed it to HLS.js,
and Video.js tried to parse it as an HLS manifest.

Add mpegts.js to handle raw MPEG-TS streams via Media Source Extensions
in ArtPlayer, HTML5 player, and Video.js. Fix the MIME type for .ts
sources from application/x-mpegURL to video/mp2t.
2026-03-03 06:47:34 +00:00
4gray d7ee25e3aa chore: add dev dependencies and bump version to v0.20 2026-02-21 08:41:59 +01:00
4gray fae4c44804 chore: update angular dependencies 2026-02-20 08:22:50 +01:00
4gray f8b8464c4a chore: update nx dependencies 2026-02-19 21:52:54 +01:00
4gray 59581bd890 chore: add @tailwindcss/typography package and update dependencies
- Added @tailwindcss/typography version 0.5.19 to package.json
- Updated pnpm-lock.yaml to include @tailwindcss/typography with its dependencies
- Updated sass version from 1.97.1 to 1.90.0 in pnpm-lock.yaml
2026-02-14 22:32:16 +01:00
4grayandClaude Opus 4.6 3dc3794ac2 feat(website): add Astro landing page and blog with cinematic broadcast design
Create a new IPTVnator website using Astro 5 + Tailwind CSS within the Nx monorepo.
Features include a landing page with hero section, feature grid with auto-scrolling
carousel, screenshot showcase, download CTA, blog with MDX content collections,
and a GitHub Pages deployment workflow. Design uses a cinematic broadcast aesthetic
with TV-effect hover animations, Playfair Display serif typography, and warm dark
surfaces. Also fixes .gitignore to cover nested node_modules directories.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Entire-Checkpoint: 8171359f42f3
2026-02-14 19:47:47 +01:00
4gray c161326406 chore: remove @rx-angular dependencies from package.json and pnpm-lock.yaml 2026-02-01 22:54:44 +01:00
4gray 38fb5c0aa1 refactor: add electron-dl and related dependencies to package-lock and pnpm-lock 2026-01-26 22:44:12 +01:00
4gray 8662fa90c6 fix(vjs-player): replace HLS quality plugin and add plugin guards
Swap videojs-hls-quality-selector for videojs-quality-selector-hls
and update package versions. Initialize plugins defensively: call the
new quality selector via qualitySelectorHls when available and wrap
both quality selector and aspectRatioPanel initializations in try/catch
blocks to avoid runtime errors if a plugin fails to load. Bump project
version to 0.18.0 and add the new dependency and packageManager entry.
2026-01-13 19:50:36 +01:00
4gray 128d15349e chore(config): add pnpm and webfetch rules to local Claude settings 2026-01-09 12:54:05 +01:00
4gray 747e602ed2 chore: update nx dependencies 2026-01-04 19:06:32 +01:00
4gray 943a55585b chore: add saxes, remove epg-parser 2026-01-02 17:22:09 +01:00
4gray 0d6e519709 chore(deps): update nx & angular packages
Update Angular in pnpm-lock to newer 20.3.x versions
and align CDK/Material specifiers to the compatible 20.2.12/20.2.12
releases. This brings core, common, compiler, platform-browser,
animations, forms and related packages to the 20.3.x series to fix
version skew and ensure dependency compatibility.

Add tsConfig for tests in libs/shared/interfaces project config so
jest runner uses the correct TypeScript spec configuration, fixing
test/compile issues for that library.

Remove husky commit-msg hooks and local pre-commit checks to avoid
running commitlint, tests and eslint on commit (CI remains unaffected).
2025-11-08 23:24:56 +01:00
4gray 516a376dc0 chore(deps): remove Tauri packages and bump test deps 2025-10-27 08:20:29 +01:00