mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 10:06:15 -08:00
Three review findings, all on the persisted-session work: - `createSqliteFallbackPlaylist()` rebuilds the playlist field by field and did not copy `stalkerSessionIdentity`, `stalkerWatchdogTimeout` or `stalkerTimeslot`. Every cold Electron session therefore lost the cadence and could not run the identity-mismatch check at all — defeating the guard on the desktop app specifically. - A persisted session was bound to the device identity only, so a playlist repointed at a different host kept its token, and `ensureToken()` re-presented it in a handshake — disclosing the previous portal's bearer token to an unrelated server. Sessions are now keyed by portal origin AND identity (`stalkerSessionFingerprint`); the in-run token cache keeps its identity-only key. - The repair probe fingerprint ignored credentials, so a probe that failed on a wrong login stayed declined for the session even after the login was corrected — now that credentials are part of the discovery outcome, they belong in the fingerprint. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>