mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 01:56:16 -08:00
Two timing defects in the discovery/auth interaction: - The auth budget was written for "two sequential requests", but a status-2 portal costs FOUR — handshake, profile, do_auth, profile retry — and the Electron transport allows each 15 s. A valid but slow login-required portal was aborted before its final profile and reported as auth-rejected. - Aborting a timed-out attempt stops it from SENDING further requests, but a `get_profile` already on the wire is processed regardless, and discovery advanced immediately — so the abandoned attempt could adopt the MAC's token after the next candidate had negotiated its own, invalidating a portal that actually works. The run now drains the abandoned attempt (bounded by one request budget) instead of racing it. The second corrects a claim this branch made in the docs: the in-flight window was described as unclosable from the client. The request cannot be un-sent, but nothing forces us to have a competing session in flight while it lands. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>