mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 10:06:15 -08:00
Split across two calls, a half-failure had no honest outcome. Reporting success left a surviving alias to win the next lookup and start the source the user had just replaced; reporting failure — which the previous round changed it to — left the canonical row durable while the UI showed a pin that was no longer the stored one. Review was right both times, which is the tell that the two-step shape was the problem. `setVodSourcePin` now takes the keys to retire and does both inside one `db.transaction()`, with the synchronous `.run()` form the better-sqlite3 driver requires there (issue #1137's lesson). `retireKeys` rides through the worker op, the IPC contract, the preload bridge and the service, so there is one call and one outcome. Also corrects the architecture doc: the scan path is reached whenever no token clears the trigram minimum, not only when the whole title is one or two characters — the claim the previous commit's code change had already falsified. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>