mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 18:36:15 -08:00
Endpoint discovery deliberately preserves tenant base paths — the candidate builder has an explicit case for `/tenant/c/portal.php` — so two portals can share one origin. The session fingerprint kept only the origin, which made `/tenant-a/…` and `/tenant-b/…` the same session: editing a playlist between them re-presented tenant A's bearer token to tenant B. The key now carries origin AND path (query/fragment dropped, trailing slashes normalised). No handler-path equivalence rule is attempted: both sides of the comparison read the same persisted `portalUrl`, so the same portal always yields the same key, and the value changes only on a real edit or repair — both of which re-authenticate anyway. An equivalence rule would add machinery whose only failure mode is aliasing two genuinely different endpoints. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>