mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 01:56:16 -08:00
Review follow-up on #1324 (Codex P2, valid — the "passes for the wrong reason" class): the re-auth test only polled for a fresh handshake and a negative body-text assertion, both of which pass even if the original content request is never replayed or stays unauthorized. Capture the content token from the initial import, then assert a post-invalidation CONTENT request goes out under a DIFFERENT token and that the ITV categories actually render — the mock only answers content for an adopted token, so this proves the new token round-tripped through get_profile. Verified against a live mock that the token genuinely rotates (old token -> "Authorization failed.", new token -> content). Also documents the second Codex P2: the mock is deliberately strict on /server/load.php (a real portal enforces auth there); the import dialog vs session predicate divergence is a separate app bug the strict endpoint will let a later PR cover. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>