mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 01:56:16 -08:00
The import composed the fingerprint from endpoint and identity only, while the runtime computes it from the playlist — which carries the credentials too. So the first `ensureToken()` after importing a login-required portal mismatched the fingerprint the import had just written, refused the token and repeated the whole handshake/profile/do_auth flow, silently defeating reuse for exactly the portals this work exists for. Also refreshes the mock-server instructions the change invalidated: the README still described the client `do_auth` path as dormant and HTTP-only, and two comments still claimed the app sends `auth_second_step=1` on its first profile request — it now sends 0 first and 1 only on the retry after do_auth. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>