mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 01:56:16 -08:00
Four review findings, all the same root cause — the session key was not applied consistently: - The in-run token cache still used an identity-only key, so editing the portal URL without restarting returned the cached token and sent that bearer to the newly configured host. Both caches now use one key. - Credentials were in neither key, so changing a status-2 portal's login kept serving the previous account's session indefinitely. - A stored token with NO recorded fingerprint was accepted. Rows written before the fingerprint existed carry exactly that, and re-presenting one after an edit is the disclosure the fingerprint prevents. Missing now counts as unverified; such a row owes a full profile anyway, so nothing is lost. - `StreamResolverService` read `playlist.isFullStalkerPortal` directly instead of the shared predicate, so a legacy row with an absent flag but a canonical URL skipped authentication — a restored older backup opened a direct-URL radio favorite with no Bearer header. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>