Files
iptvnator/libs/shared/interfaces/src/lib/epg-source-reference.util.ts
T
d438f5c655 feat(epg): accept local XMLTV files as EPG sources (#1600)
* feat(epg): accept local XMLTV files as EPG sources

Settings → EPG and the playlist dialog accepted `file://` in their form
pattern, but the main process rejected everything except http(s), so a local
XMLTV entry saved fine and then failed on import. Both surfaces now take a
remote link, a `file:` URL, an absolute POSIX path or a Windows drive/UNC
path (`classifyEpgSourceReference` in shared/interfaces), and the settings
section spells out the accepted formats with examples.

The EPG worker opens every source through `openEpgSourceStream`: remote
links keep the validated-redirect client and trust policy, local files are
read from disk behind the signature-sniffing optional gunzip stage, so
.xml, .xml.gz and extension-less gzip all parse. Only hand-typed sources
may be local: `extractM3uEpgUrls` harvests http(s) links only from M3U
headers, since the local branch bypasses `validateRemoteUrl`.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* feat(epg): pick local XMLTV files with a native file dialog

A folder button beside each EPG source row (Settings → EPG and the playlist
dialog) opens the native open-file dialog and writes the chosen absolute
path into the row. New `EPG_OPEN_FILE_DIALOG` IPC behind
`ElectronBridgeApi.openEpgFileDialog`, gated in the renderer by
`RuntimeCapabilitiesService.supportsEpgFilePicker`.

The row's refresh/remove buttons carry `data-test-id`s now, and the EPG
e2e suites address them by id instead of index, since the folder button
became the first button in a row.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(epg): authorize local XMLTV files in the main process

Review follow-up (Greptile P1, Codex P1). The renderer hands source strings
to FETCH_EPG/EPG_FORCE_FETCH unchanged, so the form validator alone could
not enforce the provenance rule: a compromised renderer, or a legacy
`file://` entry an older version stored from an M3U header, could name any
file on disk.

`EpgWorkerService.startFetch` now asks a main-process
`EpgLocalSourceAuthorizer` before a local path reaches the worker: a path
the native picker returned is trusted at once, a hand-typed path is
confirmed once in a native message box the renderer cannot fake, and a
refusal is reported in the progress panel. Allowed paths persist under
TRUSTED_LOCAL_EPG_SOURCES in the main-process config. The worker opens its
local branch only when main set `allowLocalFile`; the service defaults to
deny-all until epg.events installs the persisted authorizer.
`resolvePlaylistEpgSourceState` and `filterPlaylistEpgUrlsForFetch` drop a
stored non-remote entry unless it is also in `manualEpgUrls`.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(epg): fail a refused local EPG fetch instead of resolving it

Review follow-up (Codex P2). A denied native confirmation now rejects the
fetch after reporting the error row, so handleFetchEpg and the renderer's
fetch result cannot claim the file was read. Also restores the unrelated
CLAUDE.md paragraph an earlier formatter pass had reflowed into a list.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(epg): cancel a local source retired during its authorization prompt

Review follow-up (Codex P2). startFetch keeps the request generation
captured before awaiting the native confirmation and rechecks it
afterwards: a source retired meanwhile ends as cancelled instead of
starting an import that a pending clear would then have to await.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(epg): leave the local XMLTV e2e with a pristine settings form

The local-file test ended with the EPG source field still dirty, which
arms the main-process close guard: the app then waited for the unsaved
changes dialog instead of closing, the close timeout killed it, and on
Windows the killed process kept iptvnator.db busy (EBUSY on the data-dir
cleanup) and hung the Playwright worker teardown. Discarding the form
before the app closes takes the test from 15 s to 4 s locally.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: 4gray <fourgray@proton.me>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-13 21:04:41 +02:00

73 lines
2.4 KiB
TypeScript

/**
* Classification of the value a user types as an EPG source.
*
* A source is either a remote XMLTV link (`http:`/`https:`) or a local file:
* a `file:` URL, an absolute POSIX path, a Windows drive path or a UNC path.
* Relative paths are refused on purpose — the main process has no meaningful
* working directory to resolve them against.
*
* Only values the user entered by hand (Settings → EPG, the playlist dialog)
* may be local. URLs harvested from an M3U header are filtered to remote ones
* before they are stored, so a downloaded playlist can never point the EPG
* importer at a file on the user's disk.
*/
export type EpgSourceReferenceKind = 'remote' | 'local';
export const EPG_SOURCE_REFERENCE_ERROR = 'epgSourceReference';
const REMOTE_EPG_SOURCE_PATTERN = /^https?:\/\/[^\s"]+$/i;
const FILE_URL_EPG_SOURCE_PATTERN = /^file:\/\/[^\s"]+$/i;
const POSIX_ABSOLUTE_PATH_PATTERN = /^\/[^\0]+$/;
const WINDOWS_DRIVE_PATH_PATTERN = /^[a-z]:[\\/][^\0]*$/i;
const WINDOWS_UNC_PATH_PATTERN = /^\\\\[^\\/\0]+\\[^\\/\0]+/;
export function classifyEpgSourceReference(
value: string | null | undefined
): EpgSourceReferenceKind | null {
const trimmed = value?.trim() ?? '';
if (trimmed === '') {
return null;
}
if (REMOTE_EPG_SOURCE_PATTERN.test(trimmed)) {
return 'remote';
}
if (
FILE_URL_EPG_SOURCE_PATTERN.test(trimmed) ||
POSIX_ABSOLUTE_PATH_PATTERN.test(trimmed) ||
WINDOWS_DRIVE_PATH_PATTERN.test(trimmed) ||
WINDOWS_UNC_PATH_PATTERN.test(trimmed)
) {
return 'local';
}
return null;
}
export function isRemoteEpgSourceUrl(
value: string | null | undefined
): boolean {
return classifyEpgSourceReference(value) === 'remote';
}
export function isLocalEpgSourceReference(
value: string | null | undefined
): boolean {
return classifyEpgSourceReference(value) === 'local';
}
/**
* Form validator shared by the Settings EPG list and the playlist dialog.
* Typed structurally so this contracts library stays Angular-free; an empty
* control is valid, mirroring `Validators.pattern`.
*/
export function validateEpgSourceReferenceControl(control: {
value: unknown;
}): Record<typeof EPG_SOURCE_REFERENCE_ERROR, true> | null {
const value = control.value;
if (typeof value !== 'string' || value.trim() === '') {
return null;
}
return classifyEpgSourceReference(value)
? null
: { [EPG_SOURCE_REFERENCE_ERROR]: true };
}