name: 'IPTVnator CodeQL config' # The mock servers are development/E2E fixtures. They bind to localhost, serve # fabricated data, ship in no released artifact, and deliberately imitate the # quirks of the upstream IPTV protocols — including reading a session token # from a GET query string, which is what the real Stalker backend proxy does # and therefore what the app must be tested against. # # CodeQL's web-service hygiene rules (missing rate limiting, sensitive data in # GET requests) assume an internet-facing service and produce only false # positives here; a rate limiter on a fixture that the E2E suite hammers would # actively break the tests. Injection, path-traversal and similar rules still # apply to everything the app itself ships. paths-ignore: - apps/stalker-mock-server - apps/xtream-mock-server