mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-11 11:06:16 -08:00
* fix(stalker): send cmd in the reference MAG wire format
A real MAG sends cmd unencoded and the portal decodes its query exactly
once, so a cmd that already contains percent sequences (%3A tokens,
pre-encoded path segments) must pass through untouched. The previous
encodeURIComponent transport (2c032cd3c, 0.22) double-encoded such cmds
(%3A -> %253A): strict portals and reseller panels that compare cmd
literally, and stock create_link handlers matching the decoded value,
saw a different string than a real STB sends.
The new shared encodeStalkerCmdValue() reproduces the reference wire
bytes: % passes through verbatim, characters the WHATWG URL serializer
keeps raw in a query stay raw (so the bytes survive the axios/new URL
transport unchanged), and everything else is percent-encoded. That
preserves the 0.22 injection protection - &, # (and ; for PHP setups
with a ; argument separator) inside cmd cannot append or truncate query
parameters; they decode back to the original byte server-side.
Both transports now share the format: the Electron query builder is
extracted to buildStalkerRequestUrl() and the web-backend /stalker
proxy appends cmd to the portal URL itself instead of letting axios
turn slashes into %2F (the opposite divergence).
Also unifies the two divergent response-side cmd normalizers: the
cross-portal collection resolver now uses the Stalker store's
normalizeStalkerPlaybackCommand/resolveStalkerPlaybackUrl, so playing
from Favorites/global collections resolves relative (/media/...) and
query-only (?token=...) create_link replies against the portal base
instead of handing the player a bare relative path.
The mock portal's create_link response gains mock-only cmd_received/
query_keys_received diagnostics; a new Electron e2e pins the contract
end-to-end (single decode, injection blocked). Unit corpus tests cover
the encoder, the Electron builder, the web-backend proxy, and the
resolver.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(pwa): sanitize portal URL before appending stalker cmd
A registered portal URL carrying a fragment would swallow the appended
cmd (everything after # is never transmitted), and a trailing bare '?'
produced '??cmd='. Drop the hash and pick the separator from the
sanitized href before appending. Flagged by Greptile/Codex on #1334.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* refactor(pwa): make stalker cmd append visibly query-only for CodeQL
Rebuild the /stalker request URL through the URL object and concatenate
the encoded cmd strictly behind a literal '?', so static analysis can
see the tainted value never reaches host or path (js/request-forgery
alert on the previous separator ternary). Behavior unchanged; the
fragment/bare-'?' regression tests still pin the wire format.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
215 lines
6.6 KiB
TypeScript
215 lines
6.6 KiB
TypeScript
import type { Page } from '@playwright/test';
|
|
|
|
import {
|
|
addStalkerPortal,
|
|
addXtreamPortal,
|
|
closeElectronApp,
|
|
defaultStalkerMacAddress,
|
|
defaultStalkerPortalName,
|
|
defaultXtreamPortalName,
|
|
expect,
|
|
expectPortalDebugSuccess,
|
|
goToDashboard,
|
|
launchElectronApp,
|
|
resetMockServers,
|
|
stalkerMockServer,
|
|
test,
|
|
waitForXtreamImportToFinish,
|
|
waitForStalkerCatalog,
|
|
waitForXtreamCatalog,
|
|
} from './electron-test-fixtures';
|
|
|
|
test.describe('Electron Provider Smoke Tests', () => {
|
|
test('@xtream @electron loads Xtream content through the Electron IPC path', async ({
|
|
dataDir,
|
|
request,
|
|
}) => {
|
|
await resetMockServers(request, ['xtream']);
|
|
|
|
const app = await launchElectronApp(dataDir);
|
|
|
|
try {
|
|
await addXtreamPortal(app.mainWindow);
|
|
await waitForXtreamCatalog(app.mainWindow);
|
|
await expectPortalDebugSuccess(app.mainWindow, 'xtream');
|
|
|
|
await goToDashboard(app.mainWindow);
|
|
await expectRecentSourceCard(
|
|
app.mainWindow,
|
|
defaultXtreamPortalName
|
|
);
|
|
} finally {
|
|
await closeElectronApp(app);
|
|
}
|
|
});
|
|
|
|
test('@stalker @electron loads Stalker content through the Electron IPC path', async ({
|
|
dataDir,
|
|
request,
|
|
}) => {
|
|
await resetMockServers(request, ['stalker']);
|
|
|
|
const app = await launchElectronApp(dataDir);
|
|
|
|
try {
|
|
await addStalkerPortal(app.mainWindow, {
|
|
portalUrl: `${stalkerMockServer}/portal.php`,
|
|
});
|
|
await waitForStalkerCatalog(app.mainWindow);
|
|
await expectPortalDebugSuccess(app.mainWindow, 'stalker');
|
|
|
|
await goToDashboard(app.mainWindow);
|
|
await expectRecentSourceCard(
|
|
app.mainWindow,
|
|
defaultStalkerPortalName
|
|
);
|
|
} finally {
|
|
await closeElectronApp(app);
|
|
}
|
|
});
|
|
|
|
test('@stalker @electron delivers cmd to the portal decoded exactly once with query injection blocked', async ({
|
|
dataDir,
|
|
request,
|
|
}) => {
|
|
await resetMockServers(request, ['stalker']);
|
|
|
|
const app = await launchElectronApp(dataDir);
|
|
|
|
try {
|
|
// Stored cmd with a pre-encoded token (%3A), a literal '+', and a
|
|
// query-injection attempt (&injected=1#frag).
|
|
const storedCmd =
|
|
'ffrt3 http://example.com/ch/123?token=a%3Ab+c&injected=1#frag';
|
|
|
|
const response = await app.mainWindow.evaluate(
|
|
async ({ url, macAddress, cmd }) =>
|
|
window.electron.stalkerRequest({
|
|
url,
|
|
macAddress,
|
|
params: { action: 'create_link', type: 'itv', cmd },
|
|
}),
|
|
{
|
|
url: `${stalkerMockServer}/portal.php`,
|
|
macAddress: defaultStalkerMacAddress,
|
|
cmd: storedCmd,
|
|
}
|
|
);
|
|
|
|
const js = (
|
|
response as {
|
|
js: { cmd_received: string; query_keys_received: string[] };
|
|
}
|
|
).js;
|
|
|
|
// The portal must see the stored cmd decoded exactly once —
|
|
// %3A → ':', '+' → space — the same view it gets from a real STB.
|
|
// The old encodeURIComponent transport double-encoded '%' and
|
|
// delivered the %3A/+ sequences still encoded.
|
|
expect(js.cmd_received).toBe(
|
|
'ffrt3 http://example.com/ch/123?token=a:b c&injected=1#frag'
|
|
);
|
|
|
|
// The '&'/'#' inside cmd stayed inside the cmd value instead of
|
|
// restructuring the portal query.
|
|
expect(js.query_keys_received).toEqual([
|
|
'JsHttpRequest',
|
|
'action',
|
|
'cmd',
|
|
'type',
|
|
]);
|
|
} finally {
|
|
await closeElectronApp(app);
|
|
}
|
|
});
|
|
|
|
test('@xtream @electron shows refresh overlay immediately from the dashboard Xtream source menu', async ({
|
|
dataDir,
|
|
request,
|
|
}) => {
|
|
await resetMockServers(request, ['xtream']);
|
|
|
|
const app = await launchElectronApp(dataDir);
|
|
|
|
try {
|
|
await addXtreamPortal(app.mainWindow);
|
|
await waitForXtreamCatalog(app.mainWindow);
|
|
await expectPortalDebugSuccess(app.mainWindow, 'xtream');
|
|
|
|
await goToDashboard(app.mainWindow);
|
|
await refreshRecentXtreamSourceFromDashboard(
|
|
app.mainWindow,
|
|
defaultXtreamPortalName
|
|
);
|
|
await waitForXtreamImportToFinish(app.mainWindow);
|
|
} finally {
|
|
await closeElectronApp(app);
|
|
}
|
|
});
|
|
});
|
|
|
|
async function expectRecentSourceCard(
|
|
page: Page,
|
|
title: string
|
|
): Promise<void> {
|
|
await expect(page.getByTestId('dashboard-recent-sources-rail')).toBeVisible(
|
|
{
|
|
timeout: 20000,
|
|
}
|
|
);
|
|
|
|
await expect(
|
|
page
|
|
.getByTestId('dashboard-recent-sources-rail-card')
|
|
.filter({
|
|
hasText: title,
|
|
})
|
|
.first()
|
|
).toBeVisible({
|
|
timeout: 20000,
|
|
});
|
|
}
|
|
|
|
async function refreshRecentXtreamSourceFromDashboard(
|
|
page: Page,
|
|
title: string
|
|
): Promise<void> {
|
|
const sourceCard = page
|
|
.getByTestId('dashboard-recent-sources-rail-card')
|
|
.filter({
|
|
hasText: title,
|
|
})
|
|
.first();
|
|
|
|
await expect(sourceCard).toBeVisible({ timeout: 20000 });
|
|
await sourceCard.hover();
|
|
await sourceCard
|
|
.getByTestId('dashboard-recent-sources-rail-card-actions')
|
|
.click();
|
|
await page
|
|
.getByRole('menuitem', {
|
|
name: 'Refresh Xtream playlist from remote',
|
|
exact: true,
|
|
})
|
|
.click();
|
|
|
|
const dialog = page.locator('mat-dialog-container');
|
|
await expect(dialog).toBeVisible();
|
|
await dialog.getByRole('button', { name: 'Yes', exact: true }).click();
|
|
|
|
const refreshOverlay = page.locator('app-workspace-shell-import-overlay');
|
|
await expect(refreshOverlay).toBeVisible({ timeout: 5000 });
|
|
await expect(
|
|
refreshOverlay.getByRole('heading', {
|
|
name: 'Refreshing playlist',
|
|
exact: true,
|
|
})
|
|
).toBeVisible();
|
|
await expect(refreshOverlay).toContainText(/Local library/);
|
|
await expect(refreshOverlay).toContainText(
|
|
/Preserving your library data|Removing cached streams|Removing cached categories/
|
|
);
|
|
|
|
await page.waitForSelector('mat-dialog-container', { state: 'detached' });
|
|
}
|