Files
iptvnator/apps/electron-backend-e2e/src/providers.e2e.ts
T
4grayandClaude Fable 5 297e9fbef8 fix(stalker): send cmd in the reference MAG wire format (#1334)
* fix(stalker): send cmd in the reference MAG wire format

A real MAG sends cmd unencoded and the portal decodes its query exactly
once, so a cmd that already contains percent sequences (%3A tokens,
pre-encoded path segments) must pass through untouched. The previous
encodeURIComponent transport (2c032cd3c, 0.22) double-encoded such cmds
(%3A -> %253A): strict portals and reseller panels that compare cmd
literally, and stock create_link handlers matching the decoded value,
saw a different string than a real STB sends.

The new shared encodeStalkerCmdValue() reproduces the reference wire
bytes: % passes through verbatim, characters the WHATWG URL serializer
keeps raw in a query stay raw (so the bytes survive the axios/new URL
transport unchanged), and everything else is percent-encoded. That
preserves the 0.22 injection protection - &, # (and ; for PHP setups
with a ; argument separator) inside cmd cannot append or truncate query
parameters; they decode back to the original byte server-side.

Both transports now share the format: the Electron query builder is
extracted to buildStalkerRequestUrl() and the web-backend /stalker
proxy appends cmd to the portal URL itself instead of letting axios
turn slashes into %2F (the opposite divergence).

Also unifies the two divergent response-side cmd normalizers: the
cross-portal collection resolver now uses the Stalker store's
normalizeStalkerPlaybackCommand/resolveStalkerPlaybackUrl, so playing
from Favorites/global collections resolves relative (/media/...) and
query-only (?token=...) create_link replies against the portal base
instead of handing the player a bare relative path.

The mock portal's create_link response gains mock-only cmd_received/
query_keys_received diagnostics; a new Electron e2e pins the contract
end-to-end (single decode, injection blocked). Unit corpus tests cover
the encoder, the Electron builder, the web-backend proxy, and the
resolver.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(pwa): sanitize portal URL before appending stalker cmd

A registered portal URL carrying a fragment would swallow the appended
cmd (everything after # is never transmitted), and a trailing bare '?'
produced '??cmd='. Drop the hash and pick the separator from the
sanitized href before appending. Flagged by Greptile/Codex on #1334.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(pwa): make stalker cmd append visibly query-only for CodeQL

Rebuild the /stalker request URL through the URL object and concatenate
the encoded cmd strictly behind a literal '?', so static analysis can
see the tainted value never reaches host or path (js/request-forgery
alert on the previous separator ternary). Behavior unchanged; the
fragment/bare-'?' regression tests still pin the wire format.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-02 07:38:11 +02:00

215 lines
6.6 KiB
TypeScript

import type { Page } from '@playwright/test';
import {
addStalkerPortal,
addXtreamPortal,
closeElectronApp,
defaultStalkerMacAddress,
defaultStalkerPortalName,
defaultXtreamPortalName,
expect,
expectPortalDebugSuccess,
goToDashboard,
launchElectronApp,
resetMockServers,
stalkerMockServer,
test,
waitForXtreamImportToFinish,
waitForStalkerCatalog,
waitForXtreamCatalog,
} from './electron-test-fixtures';
test.describe('Electron Provider Smoke Tests', () => {
test('@xtream @electron loads Xtream content through the Electron IPC path', async ({
dataDir,
request,
}) => {
await resetMockServers(request, ['xtream']);
const app = await launchElectronApp(dataDir);
try {
await addXtreamPortal(app.mainWindow);
await waitForXtreamCatalog(app.mainWindow);
await expectPortalDebugSuccess(app.mainWindow, 'xtream');
await goToDashboard(app.mainWindow);
await expectRecentSourceCard(
app.mainWindow,
defaultXtreamPortalName
);
} finally {
await closeElectronApp(app);
}
});
test('@stalker @electron loads Stalker content through the Electron IPC path', async ({
dataDir,
request,
}) => {
await resetMockServers(request, ['stalker']);
const app = await launchElectronApp(dataDir);
try {
await addStalkerPortal(app.mainWindow, {
portalUrl: `${stalkerMockServer}/portal.php`,
});
await waitForStalkerCatalog(app.mainWindow);
await expectPortalDebugSuccess(app.mainWindow, 'stalker');
await goToDashboard(app.mainWindow);
await expectRecentSourceCard(
app.mainWindow,
defaultStalkerPortalName
);
} finally {
await closeElectronApp(app);
}
});
test('@stalker @electron delivers cmd to the portal decoded exactly once with query injection blocked', async ({
dataDir,
request,
}) => {
await resetMockServers(request, ['stalker']);
const app = await launchElectronApp(dataDir);
try {
// Stored cmd with a pre-encoded token (%3A), a literal '+', and a
// query-injection attempt (&injected=1#frag).
const storedCmd =
'ffrt3 http://example.com/ch/123?token=a%3Ab+c&injected=1#frag';
const response = await app.mainWindow.evaluate(
async ({ url, macAddress, cmd }) =>
window.electron.stalkerRequest({
url,
macAddress,
params: { action: 'create_link', type: 'itv', cmd },
}),
{
url: `${stalkerMockServer}/portal.php`,
macAddress: defaultStalkerMacAddress,
cmd: storedCmd,
}
);
const js = (
response as {
js: { cmd_received: string; query_keys_received: string[] };
}
).js;
// The portal must see the stored cmd decoded exactly once —
// %3A → ':', '+' → space — the same view it gets from a real STB.
// The old encodeURIComponent transport double-encoded '%' and
// delivered the %3A/+ sequences still encoded.
expect(js.cmd_received).toBe(
'ffrt3 http://example.com/ch/123?token=a:b c&injected=1#frag'
);
// The '&'/'#' inside cmd stayed inside the cmd value instead of
// restructuring the portal query.
expect(js.query_keys_received).toEqual([
'JsHttpRequest',
'action',
'cmd',
'type',
]);
} finally {
await closeElectronApp(app);
}
});
test('@xtream @electron shows refresh overlay immediately from the dashboard Xtream source menu', async ({
dataDir,
request,
}) => {
await resetMockServers(request, ['xtream']);
const app = await launchElectronApp(dataDir);
try {
await addXtreamPortal(app.mainWindow);
await waitForXtreamCatalog(app.mainWindow);
await expectPortalDebugSuccess(app.mainWindow, 'xtream');
await goToDashboard(app.mainWindow);
await refreshRecentXtreamSourceFromDashboard(
app.mainWindow,
defaultXtreamPortalName
);
await waitForXtreamImportToFinish(app.mainWindow);
} finally {
await closeElectronApp(app);
}
});
});
async function expectRecentSourceCard(
page: Page,
title: string
): Promise<void> {
await expect(page.getByTestId('dashboard-recent-sources-rail')).toBeVisible(
{
timeout: 20000,
}
);
await expect(
page
.getByTestId('dashboard-recent-sources-rail-card')
.filter({
hasText: title,
})
.first()
).toBeVisible({
timeout: 20000,
});
}
async function refreshRecentXtreamSourceFromDashboard(
page: Page,
title: string
): Promise<void> {
const sourceCard = page
.getByTestId('dashboard-recent-sources-rail-card')
.filter({
hasText: title,
})
.first();
await expect(sourceCard).toBeVisible({ timeout: 20000 });
await sourceCard.hover();
await sourceCard
.getByTestId('dashboard-recent-sources-rail-card-actions')
.click();
await page
.getByRole('menuitem', {
name: 'Refresh Xtream playlist from remote',
exact: true,
})
.click();
const dialog = page.locator('mat-dialog-container');
await expect(dialog).toBeVisible();
await dialog.getByRole('button', { name: 'Yes', exact: true }).click();
const refreshOverlay = page.locator('app-workspace-shell-import-overlay');
await expect(refreshOverlay).toBeVisible({ timeout: 5000 });
await expect(
refreshOverlay.getByRole('heading', {
name: 'Refreshing playlist',
exact: true,
})
).toBeVisible();
await expect(refreshOverlay).toContainText(/Local library/);
await expect(refreshOverlay).toContainText(
/Preserving your library data|Removing cached streams|Removing cached categories/
);
await page.waitForSelector('mat-dialog-container', { state: 'detached' });
}