Files
iptvnator/docs
4grayandClaude Fable 5 226ffbb9e6 fix(stalker): key every session by endpoint, identity and credentials
Four review findings, all the same root cause — the session key was not applied
consistently:

- The in-run token cache still used an identity-only key, so editing the portal
  URL without restarting returned the cached token and sent that bearer to the
  newly configured host. Both caches now use one key.
- Credentials were in neither key, so changing a status-2 portal's login kept
  serving the previous account's session indefinitely.
- A stored token with NO recorded fingerprint was accepted. Rows written before
  the fingerprint existed carry exactly that, and re-presenting one after an
  edit is the disclosure the fingerprint prevents. Missing now counts as
  unverified; such a row owes a full profile anyway, so nothing is lost.
- `StreamResolverService` read `playlist.isFullStalkerPortal` directly instead
  of the shared predicate, so a legacy row with an absent flag but a canonical
  URL skipped authentication — a restored older backup opened a direct-URL
  radio favorite with no Bearer header.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-03 18:41:55 +02:00
..