mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-09 17:36:15 -08:00
Two more places where the endpoint/identity/credential binding was defined but not enforced: - Collection playback read the RAW token cache, which skips the fingerprint check `ensureToken()` performs. After editing the MAC, endpoint or login, opening a direct-URL radio favorite before any other request put the previous account's token into the stream headers. It now always goes through `ensureToken()`, which returns the cached token when it is still valid, so a warm session costs nothing. - The repair's atomic row guard compared URL, mode and device identity but not credentials, so a login saved during a 45-second discovery let the outcome negotiated for the OLD account commit and adopt its token. The guard now matches `repairSourceFingerprint()`. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>