Commit Graph
11 Commits
Author SHA1 Message Date
obscuremindandClaude Opus 5 3eabc7a6f9 fix(auth): catch-up routing, proxy-only check and adaptive variants
- Timeshift through a proxy read $rChannelInfo, which the timeshift path
  never sets, so catch-up always bypassed the archive server's proxy (and
  an archive server that requires one refused it). It now uses the
  archive server's proxies, like live.
- The cached pre-check compared the type to 'archive', which requests
  never carry, so catch-up fell into the live check and a channel whose
  live stream was down refused its own catch-up. The same block used
  variables that are not set yet (and SERVER_ID, not yet defined there).
- The proxy-only rule trusted the client-set X-IP header; any client could
  name a public proxy IP and pass. nginx now passes the TCP peer
  ($realip_remote_addr) as XC_PEER_ADDR and auth checks that; the header
  counts only from an XC_VM server/whitelisted peer, or on an nginx config
  too old to pass the peer.
- Adaptive masters skip a variant with no server (or no proxy) instead of
  building URLs from a failed redirect.
- Connection uuids come from random_bytes() rather than md5(uniqid()).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:19:50 +01:00
Divarion_D 4056d9349e fix(lb): restore streaming X-Accel locations in LB nginx.conf (Phase G)
The LB build overrides bin/nginx/conf/nginx.conf with lb_configs/nginx.conf
(Makefile: cp $(CONFIG_DIR)/nginx.conf ...), and that file had drifted stale —
it lacked ALL three streaming X-Accel internal locations that the main nginx.conf
carries. On a freshly-installed LB node this breaks:
  - P1 HLS: segment.php always emits X-Accel-Redirect: /xc_hls/<file> -> 404
  - P2 live fan-out: live.php emits /xc_fanout/<id> -> 404
  - P2/B daemon HLS segments: /xc_fanout_hls/<id>_<seq> -> 404
i.e. daemon delivery (and even plain on-disk HLS) never worked on a stock LB —
matching the canary LB, whose nginx.conf 'predated' these and was patched by hand.

Add the three internal locations verbatim from the main nginx.conf so a stock
'make lb' node serves HLS + daemon fan-out out of the box. (libogg0 is already in
LbInstallFlow::getPackages for every distro; service starts the daemon keepalive +
fanout_sync on any node; fanout_binary/FanoutSync/RootSignals are not LB-stripped.)
2026-08-18 19:52:08 +03:00
Divarion-D 6d9cd5821c fix(nginx): add LB loopback admin routes and correct Public docroot case
LoadBalancer nginx had no ^/admin/ location, so when a server higher in
the tree pulled a stream whose source is an LB, the LB returned 404 for
/admin/{live,timeshift,thumb,vod} before the request ever reached PHP.
The MAIN→LB direction worked (MAIN has the route); LB→MAIN was silently
broken — stream shown down, nothing in the panel logs.

Add a reduced admin location exposing ONLY the loopback handlers
(live|timeshift|thumb|vod) — not index|api|proxy_api — so the admin
panel itself is never served from a LoadBalancer. Mirrors the MAIN
admin gateway block.

Also fix a PSR-4 rename miss: the directory rename public/ → Public/
(1a296d09) updated src/bin/nginx/conf/nginx.conf but left
lb_configs/nginx.conf pointing at /home/xc_vm/public/ everywhere
(root, stream, progress, api). On a case-sensitive fresh LB install the
on-disk path is Public/, so every SCRIPT_FILENAME 404'd — all LB
streaming broke, not just loopback. Repoint the 8 filesystem paths to
Public/; SCRIPT_NAME stays /public/ (logical CGI path, matches MAIN).
2026-06-26 20:00:30 +03:00
Divarion-D 7e1b796c5b Implement VOD streaming endpoint and remove legacy files
- Added a new VOD stream delivery endpoint in `vod.php` to handle video on demand streaming with authentication and connection management.
- Created 404 Not Found HTML pages for various image directories to improve user experience when accessing non-existent resources.
- Deleted obsolete `index.php`, `constants.php`, and other related files from the admin and stream directories to clean up the codebase and remove deprecated functionality.
- Removed legacy initialization and progress handling scripts to streamline the application and enhance maintainability.
2026-06-12 13:20:13 +03:00
Brett PetchandGitHub d77786faa2 fix(nginx): Reenable mutli_accept 2026-05-19 18:20:46 +00:00
DanilandGitHub 7de97dbea2 Merge pull request #113 from brettpetch/patch-2
performance(nginx): Utilize `reuseport` instead of `mutli_accept` and `accept_mutex`
2026-05-14 18:22:20 +03:00
Brett PetchandGitHub e55ea0ffa9 remove accept_mutex and mutli_accept as superceded by reuseport 2026-05-14 11:07:57 -04:00
Brett PetchandGitHub fce9dc7bf0 security(nginx): CVE-2026-42945 2026-05-14 10:54:28 -04:00
Divarion-D a32889bce7 feat: improve routing, streaming gateway, and stability across nginx and services
- update nginx routing and add legacy endpoints for admin and progress
- implement stream gateway endpoint for nginx rewrites
- ensure certbot webroot directory is created automatically if missing
- fix safe handling of country code retrieval in EPG and playlist logic
2026-05-01 19:17:11 +03:00
Divarion-D 77ee92bc79 Phase 11: Unify API layer — route all API endpoints through Front Controller
Steps 11.1–11.6: migrated all standalone API entry points to controller classes
dispatched via the Front Controller, then deleted the legacy PHP files.

Controllers created:
- PlayerApiController (player_api.php, 12 actions + numeric aliases)
- Enigma2ApiController (enigma2.php + xplugin.php)
- PlaylistApiController (playlist.php)
- EpgApiController (epg.php)
- InternalApiController (api.php, ~40 server-to-server actions)

Nginx changes (MAIN + LB configs):
- Add location block for streaming API endpoints → FC with XC_SCOPE=api
- Add location block for internal API (/api.php) → FC with XC_API=internal
- Change 6 rewrite rules from break→last for deleted file URLs
- Remove allow/deny from /api.php location — auth handled by PHP
  (password + IP whitelist + brute-force guard)

Front Controller (public/index.php):
- Add section 3a: REST API dispatch (XC_SCOPE=includes/api/*)
- Add section 3b: Streaming API dispatch (XC_SCOPE=api, XC_API=*)
- Move autoloader require to top (section 1b) for all code paths
- Controller map: endpoint name → controller class → init → dispatch

Bootstrap changes:
- www/init.php, www/stream/init.php: replace FC_API_NAME constant with
  direct $rFilename variable (set by FC before require, checked via isset)

Bug fixes:
- PlayerApiController: fix 3 PHP 8 warnings ($rBouquets undefined,
  missing 'rating'/'subtitle' array keys in get_vod_info)
- Fix server-to-server API calls blocked by nginx deny all (api_url_ip
  uses external server IP, not 127.0.0.1)

Deleted files (8):
- www/player_api.php, www/enigma2.php, www/xplugin.php
- www/epg.php, www/playlist.php, www/api.php
- includes/api/admin/index.php, includes/api/reseller/index.php

New files:
- tools/test_player_api.sh — comprehensive Player API test suite (13 sections)
2026-03-12 21:26:20 +03:00
Divarion-D 938e8b0868 init 2025-07-10 20:01:56 +03:00