InputValidator::confirmIDs() kept an id when intval($id) > 0 but returned
the original value, and its callers implode the result into SQL `IN (...)`
lists (mass edit and delete of lines, users, streams, series; bouquet
contents; global search). '1) OR (1=1' has an intval of 1, so it passed the
filter and reached the query unchanged. It now returns the integers.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA
- add PHPUnit bootstrap and config under tests/
- add focused unit tests for GitHubReleases, InputValidator and FfmpegPaths
- fix GitHubReleases cache file handling when switching update channel
- document PHPUnit PHAR usage and debug run commands in RU/EN docs
- document SFTP sync for tests/ and contributor test workflow
- remove broad smoke coverage approach in favor of per-file tests