mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-09 01:16:15 -08:00
Review follow-up on #1324 (Greptile 2xP1, Codex 3xP2), all valid: - adoptToken only accepts tokens the mock actually issued (or the already-bound one). The stock server pins any presented Bearer — handshake is stateless there — but a fixture that does the same cannot catch a client with a broken token pipeline; documented as a deliberate strictness divergence. - /invalidate-session clears tokens but keeps pinned device identity: losing a token never unpins device_id on a real portal, so changed identity after re-auth must still hit the device-conflict branch. - The login-required scenario gates on actual do_auth completion instead of auth_second_step: the app sends auth_second_step=1 on its very first get_profile, so the parameter check was trivially bypassed and the status-2 flow never exercised. do_auth is now the faithful boolean step (non-empty credentials -> {js:true}, recorded; empty -> {js:false}). - /server/load.php — the second URL shape isFullStalkerPortal recognizes — is now served and enforced, directly and through the /stalker proxy predicate, so full-portal tests cannot silently fall into the tolerant branch. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>