mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
Review follow-up on #1324 (Codex, 4xP2): - Parallel-reset race: under the workspace `fullyParallel` preset the new auth file ran concurrently with stalker.e2e.ts against one shared mock process, and each `beforeEach` wiped global state (sessions, favorites) mid-assertion in the other. Reproduced locally: both suites green in isolation, two failures when run together. Merged the auth tests into stalker.e2e.ts and pinned the file to `mode: 'serial'`, which also removes the pre-existing race between that file's own tests. 19/19 green across three consecutive runs. - Watchdog was recorded but never asserted, so the suite would stay green if the full-portal workflow stopped pinging or dropped its token — `sendWatchdogPing` swallows failures. Now polls for an authenticated `get_events`. - Both mock servers listened on every interface (stalker: `listen(PORT)` with no host; xtream: an explicit `0.0.0.0` default), which made the CodeQL exclusion's "binds to localhost" rationale untrue. Both now default to `127.0.0.1` with a `HOST` opt-in, and the config comment states plainly what the directory-wide ignore trades away. - Documented that the login-required scenario is HTTP-level only for now: the client's `do_auth` path is dormant and sends empty credentials, so the fixture is waiting on that client-side work rather than claiming end-to-end coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
21 lines
1.1 KiB
YAML
21 lines
1.1 KiB
YAML
name: 'IPTVnator CodeQL config'
|
|
|
|
# The mock servers are development/E2E fixtures. They bind to loopback by
|
|
# default (HOST=0.0.0.0 is an explicit opt-in for pointing a phone/STB at
|
|
# them), serve fabricated data, ship in no released artifact, and deliberately
|
|
# imitate the quirks of the upstream IPTV protocols — including reading a
|
|
# session token from a GET query string, which is what the real Stalker
|
|
# backend proxy does and therefore what the app must be tested against.
|
|
#
|
|
# CodeQL's web-service hygiene rules (missing rate limiting, sensitive data in
|
|
# GET requests) assume an internet-facing service and produce only false
|
|
# positives here; a rate limiter on a fixture that the E2E suite hammers would
|
|
# actively break the tests. paths-ignore is all-or-nothing per path — CodeQL
|
|
# has no per-path rule filter — so this deliberately trades away injection/
|
|
# path-traversal coverage for the two fixture apps, which parse no input
|
|
# beyond the local test driver. Everything the app itself ships keeps full
|
|
# coverage.
|
|
paths-ignore:
|
|
- apps/stalker-mock-server
|
|
- apps/xtream-mock-server
|