Files
iptvnator/.github/codeql/codeql-config.yml
T
4grayandClaude Fable 5 4b31f71672 test(stalker): serialize the portal specs and bind mocks to loopback
Review follow-up on #1324 (Codex, 4xP2):

- Parallel-reset race: under the workspace `fullyParallel` preset the new
  auth file ran concurrently with stalker.e2e.ts against one shared mock
  process, and each `beforeEach` wiped global state (sessions, favorites)
  mid-assertion in the other. Reproduced locally: both suites green in
  isolation, two failures when run together. Merged the auth tests into
  stalker.e2e.ts and pinned the file to `mode: 'serial'`, which also
  removes the pre-existing race between that file's own tests. 19/19
  green across three consecutive runs.
- Watchdog was recorded but never asserted, so the suite would stay green
  if the full-portal workflow stopped pinging or dropped its token —
  `sendWatchdogPing` swallows failures. Now polls for an authenticated
  `get_events`.
- Both mock servers listened on every interface (stalker: `listen(PORT)`
  with no host; xtream: an explicit `0.0.0.0` default), which made the
  CodeQL exclusion's "binds to localhost" rationale untrue. Both now
  default to `127.0.0.1` with a `HOST` opt-in, and the config comment
  states plainly what the directory-wide ignore trades away.
- Documented that the login-required scenario is HTTP-level only for now:
  the client's `do_auth` path is dormant and sends empty credentials, so
  the fixture is waiting on that client-side work rather than claiming
  end-to-end coverage.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-01 18:44:28 +02:00

21 lines
1.1 KiB
YAML

name: 'IPTVnator CodeQL config'
# The mock servers are development/E2E fixtures. They bind to loopback by
# default (HOST=0.0.0.0 is an explicit opt-in for pointing a phone/STB at
# them), serve fabricated data, ship in no released artifact, and deliberately
# imitate the quirks of the upstream IPTV protocols — including reading a
# session token from a GET query string, which is what the real Stalker
# backend proxy does and therefore what the app must be tested against.
#
# CodeQL's web-service hygiene rules (missing rate limiting, sensitive data in
# GET requests) assume an internet-facing service and produce only false
# positives here; a rate limiter on a fixture that the E2E suite hammers would
# actively break the tests. paths-ignore is all-or-nothing per path — CodeQL
# has no per-path rule filter — so this deliberately trades away injection/
# path-traversal coverage for the two fixture apps, which parse no input
# beyond the local test driver. Everything the app itself ships keeps full
# coverage.
paths-ignore:
- apps/stalker-mock-server
- apps/xtream-mock-server