Commit Graph
56 Commits
Author SHA1 Message Date
Divarion_D c2c686b3a2 docs(bootstrap): rewrite the file header to state its purpose
XC_Bootstrap is now a thin facade, so the old header — a full description of every
context plus four usage examples — described the pre-refactor monolith. Replace it
with a short statement of what the file is (entry point: MAIN_HOME + Composer
autoloader + the BC facade) and a pointer to where the logic lives (BootKernel and
its stages; the context is a BootContext).
2026-09-16 18:24:44 +03:00
Divarion_D e1bb80672e refactor(bootstrap): split XC_Bootstrap into an injectable BootKernel pipeline
Replace the fully-static XC_Bootstrap god-class with a stage pipeline so the boot
logic becomes unit-testable and the per-context sequences are explicit.

- BootState replaces the 8 static readiness flags with a value object threaded
  through the pipeline; stages read/write it instead of static state.
- BootStageInterface + BootPipeline run an ordered stage list and abort loudly
  on a throwing stage.
- 16 stages under Core/Bootstrap/Stage/ hold one subsystem each, extracted
  verbatim from the old private methods (constants, config, flood, host, session,
  database, legacy core, redis, process title, admin API, translator, admin
  shutdown, status constants, admin globals, container populate, health check).
- StageProfiles builds the ordered list per context, mirroring the exact previous
  sequence; BootKernel resolves options, sets up the container and runs it.
- XC_Bootstrap is now a thin BC facade delegating to BootKernel; its getters read
  the returned BootState. reset() also clears EventDispatcher and the new
  DatabaseFactory::reset() (a side-effect-free registry clear for test isolation).

The DB-touching contexts (Cli/Stream/Admin) still require a live MySQL and the
xcvm_core extension, so they are verified on a canary rather than in CI; the
Minimal context and the pipeline/profile composition are covered by new tests.
2026-09-16 16:58:49 +03:00
Divarion_D 45b82938a0 refactor(bootstrap): source STATUS_* from ConstantsInitializer::initStatus()
Replace the ~49 inline define() calls in XC_Bootstrap::defineStatusConstants()
with a single delegation to ConstantsInitializer::initStatus(). New code and
tests can now read the values via StatusRegistry without the one-shot define()
blocking per-test variation; the legacy STATUS_* reads are unchanged.
2026-09-16 16:34:24 +03:00
Divarion_D c08f2ba8ba style: drop the extra blank line after <?php in Core files
Collapse the double blank line between the opening <?php and the namespace
declaration to a single one across 17 Core files (Auth, Enum, Events,
Reference, bootstrap). Whitespace only — no code changes.
2026-09-13 15:20:38 +03:00
Divarion_D 758a9cab0b style: apply K&R + tab formatting across the codebase (make cs-fix)
Mechanical, behaviour-preserving reformat produced by 'make cs-fix' under
the new build/phpcs.xml.dist ruleset: K&R braces, tab indentation, and the
other whitespace normalisations. No logic changes.
2026-09-13 14:14:23 +03:00
DanilandGitHub 0bde979972 Merge pull request #188 from obscuremind/main
Sync Repository
2026-09-13 12:37:24 +03:00
Divarion_D 71ccdac452 refactor: convert inline \XcVm\ FQNs to PSR-4 use imports
Replace fully-qualified \XcVm\... class references (in code and in
docblocks/@see/@param/@return/@throws) with short names backed by
top-of-file use imports, project-wide. Same-namespace references drop
the prefix with no import; view templates gain the top-level imports the
check-procedural-use gate expects. Purely mechanical, no behavior change.
2026-09-13 12:13:01 +03:00
rootandClaude Opus 5 010cdb1bc9 fix(auth): sign admins and resellers in on a fresh session id, and harden the session cookie
A successful admin or reseller login wrote the signed-in user into whatever
session the visitor arrived with; nothing in the panel ever called
session_regenerate_id. With session.use_strict_mode off, PHP adopts any id a
client presents, so an id planted in an admin's browser beforehand (a cookie
set from a sibling subdomain, a shared machine) became a signed-in admin
session the moment they logged in — session fixation.

Login (admin and reseller) and the first-run setup page now move the session
onto a fresh id and discard the old one. The admin session also starts with
use_strict_mode on, so ids this server never issued are refused, and with the
cookie HttpOnly: no panel script reads it, and an XSS should not be able to.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EuZvjFSdodqgpyXtaoH1Xt
2026-09-12 21:53:20 +00:00
Divarion_D 1aede3bf4c refactor(i18n): co-locate language files with the Translator
Move the .ini language files from src/resources/langs/ to
src/Core/Localization/lang/, next to the Translator subsystem that owns
them — which already defaulted its $langsDir to __DIR__ . '/lang/'. This
dissolves the now-vestigial src/resources/ bucket (its data/ tree went
with admin_constants, libs/ was empty).

- bootstrap.php calls Translator::init() with no argument, relying on the
  class's own __DIR__-relative default instead of MAIN_HOME . 'resources/langs/'.
- Makefile LB removal list points at Core/Localization/lang (and drops the
  gone resources/langs, resources/libs); LB still ships no UI translations.
- Drop the stale src/resources entries from phpstan scanDirectories and the
  phpunit coverage excludes.
- Update the English docs (translations guide, build-system table); the ru
  tree is regenerated before release.
2026-08-31 21:28:16 +03:00
Divarion_D 47bf5eed89 refactor(i18n): drop the global $language, provide it from the controller layer
$language was a bootstrap-set global (literally Translator::class) that
reached views through four separate bridges: the BaseAdminController
extract whitelist, admin/functions.php, and the renderUnifiedLayoutHeader/
Footer $GLOBALS pulls. Removing the global and sourcing $language where
each page is actually assembled makes the dependency explicit.

- BaseAdminController::render() sets $data['language'] = Translator::class,
  covering every admin/reseller page it renders.
- renderUnifiedLayoutHeader()/Footer() and admin/functions.php set a local
  $language for the legacy header/footer and the standalone login/setup/post
  pages; the reseller login/post controllers set their own local.
- Non-view code (TableController, SearchAjaxController, Admin/Reseller
  ScopeBootstrap) calls Translator::get()/setLanguage() directly instead of
  through `global $language`.
- bootstrap.php no longer creates the $language global; initTranslator()
  and $allowedLangs call Translator:: directly.

Views keep their `$language::get(...)` syntax unchanged; $language is now a
local in every scope that renders one.
2026-08-31 21:18:58 +03:00
Divarion_D c27950093f refactor(admin): replace admin_constants globals with reference classes and enums
Move the 17 global lookup arrays from resources/data/admin_constants.php
into PSR-4 classes and enums, eliminating the last big pile of `global`
reference data.

New XcVm\Core\Reference\* (const + static accessors, FfmpegBinaries-style):
GeoReference, LocaleReference, DeviceReference, UiReference,
PermissionReference, StatusBadge. New XcVm\Core\Enum\* (backed enums with
label()/options(), ModuleState-style): Theme (int), ResellerAction and
ClientFilter (string).

All consumers migrated off `global $rX` / `$GLOBALS['rX']` and the
BaseAdminController extract bridge: TableController, DashboardController,
SearchAjaxController, SettingsController, ResellerAPI and
ResellerLoginController call the classes directly, and 21 view templates
import them via `use`. The extract whitelist entries, the bootstrap
require and admin_constants.php itself are removed.

Fixes a latent bug: TableController read $rClientFilters without a
`global`, so the client-request log showed raw status codes instead of
labels; ClientFilter::labelFor() now resolves them.

The reference classes and the three new enums are excluded from the
load-balancer build (all consumers are already MAIN-only).

Adds unit tests for the enums, StatusBadge and the reference data.
2026-08-31 20:58:23 +03:00
Divarion_D 08a3c69e0b refactor: drop redundant require_once for PSR-4-autoloaded classes
Audited every require/include in src/. Removed 45 manual require_once/require
statements that load a XcVm\* class in a context where the Composer autoloader
is already registered — the class resolves on first use, so the require is dead:

- CronTrait ×26 (Cli/CronJobs/*), DaemonTrait ×7 (Cli/Commands/*)
- DropboxClient ×5 (Core/Backup/BackupService)
- XmlStringStreamer (EpgCronJob; was a bare `require`, a redeclare risk)
- Thread + Multithread (CacheEngineCronJob)
- Logger, DatabaseHandler, LegacyInitializer, Translator (bootstrap.php — the
  autoloader is registered earlier at line 89; these are also `use`-imported)

Deliberately KEPT (not redundant):
- The lightweight WebApiBootstrap / StreamingRequestBootstrap / StreamingBootstrap
  have NO Composer autoloader (intentional, for high-traffic endpoints) — their
  manual requires are load-bearing.
- ErrorHandler.php (global namespace, not PSR-4), and the define()-only config
  files AppConfig.php / Paths.php / Binaries.php (autoload never loads constants).
- All view/template/procedural/dynamic includes.

Every removed target verified to resolve via the production autoloader
(class_exists / trait_exists). make phpstan / cs / gates all green.
2026-08-27 16:20:09 +03:00
Divarion_D 1fbcb151e9 refactor(bootstrap): read enable_cache via SettingsManager::get()
Final call site: migrate the enable_cache check in the streaming cache path to
SettingsManager::get('enable_cache'), completing removal of the
getAll()['key'] pattern across src/.
2026-08-24 22:02:27 +03:00
Divarion_D 8661460868 style: remove unused imports + normalize use/namespace spacing (phpcs)
Apply the new phpcs + Slevomat ruleset across src/ (phpcbf): 85 files. The bulk
are unused `use` imports that PHP-CS-Fixer's no_unused_imports missed (class
name only present in a PHPDoc description), plus blank-line normalization around
the use/namespace blocks. Verified safe: `make phpstan` stays green (0 errors) —
no import used in code or a real docblock type was removed.
2026-08-21 17:55:25 +03:00
Divarion-D aa3f79d934 fix(player): redirect player URLs to include trailing slash for static asset resolution 2026-07-05 22:21:26 +03:00
Divarion-D f67de8963a fix(watchdog): ensure Redis health check does not disrupt operation 2026-07-03 22:34:05 +03:00
Divarion-D 85433cbefd fix(assets): drop tracked reseller symlink; panel recreates it
The absolute-path symlink src/Public/assets/reseller -> /home/xc_vm/public/assets/admin
broke `make main` (cp: cannot stat). Remove it from git and let
XC_Bootstrap::ensureResellerAssetsSymlink() create a relative reseller -> admin
link on admin boot (idempotent, repairs a stale/broken link).
2026-07-02 21:28:51 +03:00
Divarion-D 57e4805769 refactor: remove unused Database imports across multiple services 2026-06-28 20:45:17 +03:00
Divarion-D 578268a4a2 feat(database): refactor domain database wiring into a dedicated class 2026-06-28 13:08:15 +03:00
Divarion-D 2ddc516978 chore(deps): migrate Mobile_Detect to mobiledetect/mobiledetectlib (Composer)
Replace the bundled src/Core/Util/MobileDetect.php (Mobile_Detect v2.8.45, copied
  into XcVm\Core\Util) with the maintained Composer package, like M3uParser/PhpM3u8.

  - composer require mobiledetect/mobiledetectlib (^4.9; 4.11 needs PHP 8.2, deploy
    is 8.1.33 → Composer selected 4.9.0). Adds psr/simple-cache as a prod dependency.
  - bootstrap.php: new \XcVm\Core\Util\Mobile_Detect() -> new \Detection\MobileDetect();
    drop the manual require_once (Composer autoloads it). isMobile() unchanged.
  - Remove the bundled MobileDetect.php and its phpstan.dist.neon analyse-exclude.
  - .gitignore: whitelist the new prod packages under the prod-only vendor —
    !src/vendor/mobiledetect/ and, since psr/ is mixed, un-ignore psr/ then
    re-ignore psr/* and whitelist only psr/simple-cache (psr/container,
    event-dispatcher, log stay dev-ignored).
  - Commit the prod-only vendor + updated composer.lock.
2026-06-26 20:29:36 +03:00
copilot-swe-agent[bot]andGitHub 64f25ff517 Merge remote-tracking branch 'origin/main' into chore/psr4-migration
# Conflicts:
#	src/migrations/deleted_files.txt
2026-06-26 13:45:45 +00:00
Divarion-D 5863d1bd5e chore: remove legacy XC_Autoloader and update autoloading documentation 2026-06-26 16:35:18 +03:00
Divarion-D 2bed01e660 chore(psr4): final phase step 2 — remove the legacy autoload.php entirely
The XC_Autoloader fallback was already retired (no-op stub); this deletes it for
good. Resolution is now 100% Composer PSR-4 (+ ModuleLoader for modules), no
legacy scanner, no class-map cache.

- Move `define('MAIN_HOME', ...)` into bootstrap.php (autoload.php used to define
  it); bootstrap.php now requires only vendor/autoload.php.
- Drop `\XC_Autoloader::clearCache()/warmCache()` from StartupCommand.
- tests/bootstrap.php: locate-guard + require switched to vendor/autoload.php.
- Entry points that required autoload.php directly — Public/index.php,
  Public/admin/index.php, Public/stream/index.php, Public/progress/index.php,
  ministra/portal.php and Admin/Reseller TableController — switched to
  vendor/autoload.php (defining MAIN_HOME where they did not already). These were
  not in the plan's checklist; found via grep during execution.
- phpstan.dist.neon: drop src/autoload.php from scanFiles.
- Makefile: drop autoload.php from LB_ROOT_FILES.
- deleted_files.txt: add autoload.php (client cleanup on update).
- AutoloadOrderTest: now asserts the XC_Autoloader class and file are gone.
- git rm src/autoload.php.
- PSR4_MIGRATION_PLAN.md: mark final-phase step 2 done.

Verified: grep XC_Autoloader:: = 0; php -l clean; PHPStan no errors; PHPUnit
303/303; make gates pass; bootstrap smoke — MAIN_HOME + XC_Bootstrap present,
XC_Autoloader gone, only the Composer autoloader registered.
2026-06-25 21:11:00 +03:00
Divarion-D 9eec63937e style: import/namespace hygiene across src (PHP-CS-Fixer)
Apply 'make cs-fix' — 493 files. Mechanical, import-block only:
- sort use statements alphabetically (class/function/const grouped);
- drop imports left unused by the PSR-4 migration (e.g. classes referenced by
  leading-backslash FQCN whose redundant 'use' the automated insertion had added);
- one blank line after namespace and after the import block; collapse stray
  blank lines around use.

No logic changes. Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; and a
temporary PHPStan pass over src/Public/Controllers confirms no still-referenced
import was removed (0 unresolved classes). 'use' after inline HTML in view
templates is valid and aliases correctly (verified) — those imports are sorted too.
2026-06-25 20:24:36 +03:00
Divarion-D aaa8e2a23a chore(psr4): phase 3 — namespace Infrastructure layer
Namespace the Infrastructure classes and PascalCase its subdirectories for PSR-4
consistency with Core/Domain:
- git mv bootstrap/→Bootstrap/, cache/→Cache/, database/→Database/, redis/→Redis/;
  update the require paths to the procedural Bootstrap/*.php glue files.
- Namespace the 7 classes: StreamingRequestBootstrap, WebApiBootstrap →
  XcVm\Infrastructure\Bootstrap; CacheReader → \Cache; DatabaseFactory →
  \Database; RedisManager → \Redis; ResellerApiDispatcher, ResellerTableRenderer
  → XcVm\Infrastructure. The procedural Bootstrap glue files stay global.
- Qualify built-ins/ioncube (\Redis, \RedisException, \DateTime, \Exception,
  \XC_VM) and still-global \StreamingBootstrap; add use to referrers; convert
  the leading-backslash \CacheReader/\DatabaseFactory/\RedisManager refs from
  earlier commits to FQCNs.
- deleted_files.txt: old lowercase subdir paths for client cleanup.
- phpstan-baseline.neon regenerated.

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; re-sweep clean.
2026-06-25 18:45:19 +03:00
Divarion-D 42d9ca8ea0 chore(psr4): phase 3 — namespace Domain layer
Namespace all of Domain into XcVm\Domain\<Subdir> (33 classes across Bouquet,
Device, Epg, Line, Security, Server, Stream, User, Vod).

- Add namespace to every Domain class; add use to referrers across src/ and
  tests/; convert the leading-backslash refs qualified in earlier Core commits
  (\UserRepository, \ServerRepository, \BouquetService, \CategoryService,
  \ConnectionTracker, \BlocklistService, ...) to their FQCNs.
- Qualify still-global / built-in deps inside Domain with leading backslash
  (\RedisManager, \TMDB, \WatchService, \FFprobeRunner, \ProcessChecker,
  \Exception, \DateTime, \PDO, ...) — Infrastructure/Streaming/module classes
  migrate later.
- BruteforceGuard: string guards class_exists('ServerRepository'/'BlocklistService')
  → ::class FQCN; drop the now-always-true method_exists check.
- phpstan-baseline.neon regenerated (292→291).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; leading-backslash
re-sweep across Domain classes is clean.
2026-06-25 18:39:28 +03:00
Divarion-D da291e20f8 chore(psr4): phase 3 (Core) — namespace remaining Core subdirs
Namespace the rest of Core, completing the Core layer:
- Backup, Boundary, Cache (CacheInterface/FileCache/RedisCache), Diagnostics,
  GeoIP (GeoIPService/MaxMindUpdater), Init (LegacyInitializer), Localization
  (Translator), Process (Thread/Multithread/ProcessManager), Updates
  (GitHubReleases), Util (NetworkUtils, AdminHelpers, Encryption, GeoIP,
  ImageUtils/ImageResizeService, Mobile_Detect, StreamUtils, SystemInfo,
  TimeUtils), Validation (InputValidator) → XcVm\Core\<Subdir>.
- Rename GithubReleases.php → GitHubReleases.php so the file matches its class
  name (PSR-4 is case-sensitive); fix the WebApiBootstrap require accordingly.
- Qualify built-ins (\Exception, \DateTime, \DateTimeZone, \Redis,
  \RuntimeException, \BadMethodCallException, ...) and still-global deps
  (\ServerRepository, \CacheReader, \DatabaseFactory, \BouquetService,
  \CategoryService, \FfmpegPaths, \StreamSorter, \XC_VM). LegacyInitializer's
  Domain calls stay \-qualified (the known Core→Domain exception).
- Add use to referrers; fix leading-backslash refs from earlier commits; fix
  string class refs class_exists('Translator'/'NetworkUtils'/...) → ::class.
  Remove the duplicate global 'use BoundaryInterface;' in MinistraModule.
- phpstan-baseline.neon regenerated.

Core is now fully namespaced (procedural constant/error/RequestGuard files stay
global by design; M3uParser/PhpM3u8 remain vendored). Verified: php -l clean;
PHPStan no errors; PHPUnit 295/295; leading-backslash re-sweep clean.
2026-06-24 22:35:33 +03:00
Divarion-D dc335a8334 chore(psr4): phase 3 (Core) — namespace Core/Enum + Core/Exception
- Core/Enum → XcVm\Core\Enum (BootContext, ModuleState, ServerEnvironment).
- Core/Exception → XcVm\Core\Exception (XcVmException) + \Container
  (ContainerException, CircularDependencyException, ServiceCreationException) +
  \Module (ModuleException + the 4 module exceptions). The hierarchy resolves:
  XcVmException extends \RuntimeException; the Container/Module exceptions extend
  XcVmException via use; ContainerException keeps its PSR ContainerExceptionInterface.
- Add use to referrers across src/ and tests/; fix the leading-backslash refs
  qualified in earlier hub commits (\ModuleState, \ServerEnvironment,
  \XcVmException, \ContainerException, \ModuleLoadException, ...) to their FQCNs.
- phpstan-baseline.neon regenerated (292→292).

Verified: php -l clean; PHPStan no errors (first pass); PHPUnit 295/295;
leading-backslash re-sweep clean.
2026-06-24 22:23:42 +03:00
Divarion-D 432c8a010a chore(psr4): phase 3 (Core) — namespace Core/Events
Move Core/Events into XcVm\Core\Events and its sub-trees: \Contract
(StoppableEventInterface), \Auth, \Module, \Settings, \Stream (the event
classes), plus root EventDispatcher, ListenerProvider, ListensTo, AbstractEvent.

- Namespace 14 files across 6 namespaces; cross-namespace refs imported via use
  (AbstractEvent/EventDispatcher → Contract\StoppableEventInterface; Stream events
  → root AbstractEvent). Built-in \Attribute (ListensTo) and ioncube \XC_VM
  (PackageInstalledEvent) qualified.
- Rewrite 'use ListensTo;' → FQCN; add use to referrers across src/ and tests/;
  fix leading-backslash refs (\EventDispatcher, \ListensTo, \PackageInstalledEvent
  from the Module commit) to their FQCNs.
- Tests: add real top-level use imports to ModuleLoaderBootTest (EventDispatcher)
  and ListensToAttributeTest (ListensTo) — the use-inserter skipped/mis-placed them
  due to a namespace() method and a heredoc fixture already containing the FQCN.
- phpstan-baseline.neon regenerated (292→292).

Completes Core/Container + Core/Events. Verified: php -l clean; PHPStan no errors;
PHPUnit 295/295; EventDispatcher resolves and AbstractEvent implements
XcVm\Core\Events\Contract\StoppableEventInterface.
2026-06-24 22:18:52 +03:00
Divarion-D e8b7ab8b2e chore(psr4): phase 3 (Core) — namespace Core/Container
Move Core/Container into XcVm\Core\Container (ServiceContainer) and
Core/Container/Psr into XcVm\Core\Container\Psr (ContainerInterface,
ContainerExceptionInterface, NotFoundExceptionInterface, NotFoundException).

- Namespace ServiceContainer + the 4 PSR-11 interfaces/classes.
- ServiceContainer: import the PSR siblings (use ...\Psr\ContainerInterface,
  NotFoundException); migrated deps (DatabaseHandler/ModuleInterface/Request/
  SettingsManager) keep their use; still-global exceptions/decorators qualified
  with leading backslash (\ContainerException, \XcVmException, \Exception, ...).
- Rewrite 'use ServiceContainer;' → FQCN (incl. module fixtures); add use to
  referrers across src/ and tests/; fix leading-backslash \ServiceContainer refs.
- Core/Exception/Container/ContainerException: import the moved PSR
  ContainerExceptionInterface.
- Router: class_exists('ServiceContainer') → ::class. InterfaceContractTest boot
  param-type → FQCN. Repaired use-inserter mis-placement in the two namespace()
  fixture tests.
- phpstan-baseline.neon regenerated (292→292).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; ServiceContainer
resolves and implements XcVm\Core\Container\Psr\ContainerInterface.
2026-06-24 22:13:35 +03:00
Divarion-D 42db4be509 chore(psr4): phase 3 (Core hubs) — namespace Core/Database
Move Core/Database into XcVm\Core\Database (DatabaseHandler, Database,
MigrationRunner, QueryHelper). First of the Core hub sub-layers.

- Namespace the 4 classes; DatabaseHandler extends Database (same namespace);
  built-ins/ioncube qualified (\PDO, \PDOException, \Exception, \Throwable,
  \XC_VM); Database keeps its 'use XcVm\Core\Logging\FileLogger;'.
- Add 'use XcVm\Core\Database\...;' to referencing files (DatabaseHandler 51,
  Database 64, QueryHelper 29, MigrationRunner 3) + 2 test files (PHPStan does not
  analyse tests/, so PHPUnit is the gate there).
- Rewrite pre-existing leading-backslash global refs (\DatabaseHandler etc., e.g.
  in @param docblocks of ResellerApiDispatcher/ResellerTableRenderer) to the full
  FQCN \XcVm\Core\Database\... — a 'use' import does not cover a leading-\
  reference. Done with a lookbehind so FQCN continuations and use-lines are intact.
- phpstan-baseline.neon regenerated (292→292; pre-existing Database/migration_logic
  findings re-anchored after class names in messages gained the namespace).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295.
2026-06-24 21:15:06 +03:00
Divarion-D 8ac1908554 chore(psr4): phase 3 (Core leaf) — namespace SettingsManager + SettingsRepository
Move the last two Core/Config classes into XcVm\Core\Config. SettingsManager
has the largest fan-out of the whole migration (referenced by ~224 files).

- Namespace SettingsManager (self-contained singleton, no class deps) and
  SettingsRepository (\FileCache:: qualified).
- Add 'use XcVm\Core\Config\SettingsManager;' to 224 referencing files and
  'use ...\SettingsRepository;' to 12 — call sites (SettingsManager::get(), etc.)
  unchanged. Done with a token-based inserter (after namespace/declare/<?php,
  idempotent, same-namespace files skipped).
- ToolsCommand::processRecaptcha: drop dead class_exists('SettingsManager') +
  method_exists guard (always autoloadable now) → call SettingsManager::clearCache()
  directly. This was the only string-literal class reference.

Core/Config is now fully namespaced (ConfigReader, DomainResolver, SettingsManager,
SettingsRepository); the procedural constant files (AppConfig/Binaries/Paths)
remain global by design.

Verified: php -l clean (226 files); PHPStan no errors (baseline unchanged — it is
line-independent so the added use-lines don't disturb it); PHPUnit 295/295; all
Config FQCNs resolve via Composer; sample Public referrers lint-clean.
2026-06-24 20:52:00 +03:00
Divarion-D 481e805e83 chore(psr4): phase 3 (Core leaf) — namespace ConfigReader + DomainResolver
Move ConfigReader and DomainResolver into XcVm\Core\Config (Composer PSR-4).
SettingsManager/SettingsRepository stay global for now (migrated together later
due to SettingsManager's large fan-out).

- Add namespace to both classes.
- Qualify still-global / ioncube refs: \XC_VM:: in ConfigReader; \CacheReader::,
  \ConnectionTracker:: in DomainResolver.
- Add 'use XcVm\Core\Config\...;' to the 15 referencing files (bootstrap, CLI
  commands/cron, LegacyInitializer, ModuleManager, stream + player controllers,
  player views, PlaylistGenerator, ...) — call sites unchanged.
- ModuleManager::isLoadBalancer: string class_exists('ConfigReader') →
  class_exists(ConfigReader::class) (the literal would now always be false).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295.
2026-06-24 20:43:40 +03:00
Divarion-D 15750f314c chore(psr4): phase 3 (Core leaf) — namespace Core/Logging
Move the Core/Logging layer into XcVm\Core\Logging (Logger, LoggerInterface,
FileLogger, DatabaseLogger, UpdateLogger). Composer PSR-4 now resolves them.

- Add namespace to the 5 logging classes; built-in \Throwable qualified in
  Logger; same-namespace LoggerInterface references unqualified.
- Add 'use XcVm\Core\Logging\...;' to the 16 referencing files (bootstrap,
  web/stream bootstraps, stream entry points, Database, EPG, update command/cron,
  auth, ministra) — call sites unchanged.
- Authenticator::logRecaptcha: drop the now-dead class_exists/method_exists
  guard (Logger is always autoloadable post-Composer) and call Logger::log
  directly.

Procedural Core/Error + Core/Config constants files (ErrorCodes/ErrorHandler/
AppConfig/Binaries/Paths — no classes) intentionally left global per plan.

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295.
2026-06-24 20:33:55 +03:00
Divarion-D 1a296d0985 chore(psr4): phase 1 — rename 7 top-level dirs to PascalCase
Atomic case-rename of the seven class-holding source directories to match the
PSR-4 namespace casing, plus every consequent path reference. No code logic
changes — pure structural rename. (config/content/resources/signals/migrations/
ministra/storage/tmp/vendor/www/bin stay lowercase.)

- git mv: core→Core, domain→Domain, infrastructure→Infrastructure,
  streaming→Streaming, modules→Modules, cli→Cli, public→Public (module subdirs
  like Modules/plex stay lowercase; loaded by ModuleLoader, not Composer).
- PHP filesystem paths updated across src/ + tests/: require/include, glob/scandir
  bases, view includes, asset/nginx-alias paths, autoload.php registerDirectories(),
  ModuleLoader/ModuleManager module roots, console.php discovery dirs.
- src/composer.json PSR-4 vendored-lib paths → Core/Parsing/...; vendor/ regenerated.
- nginx.conf: docroot + SCRIPT_FILENAME → Public/. SCRIPT_NAME and the public-facing
  /streaming/*.php compat routes are URLs, left unchanged.
- Build/CI: Makefile LB_DIRS / LB_DIRS_TO_REMOVE / LB_FILES_TO_REMOVE PascalCased
  (closes the LB-archive privileged-leak blocker); phpstan.dist.neon paths/
  scanDirectories/excludePaths; phpunit.xml.dist coverage; phpstan-baseline.neon
  regenerated (294→294 errors, no new resolution failures).
- migrations/deleted_files.txt: old lowercase trees listed for client cleanup
  (assumes case-sensitive FS — the supported Linux target).

Verified: grep-gate 0 live lowercase-dir require/include in src+tests; php -l clean;
PHPUnit 292/292; PHPStan no errors; Composer first / XC_Autoloader last in SPL stack;
global classes resolve from the renamed dirs.
2026-06-24 20:10:34 +03:00
Divarion-D a51ef1e356 fix: wire database into domain service classes before core initialization 2026-06-24 19:11:15 +03:00
Divarion-D 7e5732cdcb chore(psr4): phase 0 — Composer PSR-4 autoloader foundation
Introduce a committed Composer PSR-4 autoloader without changing class
resolution behavior, as the foundation for the incremental PSR-4 migration.

- src/composer.json: PSR-4 (XcVm\ -> ./, M3uParser\, Chrisyue\PhpM3u8\),
  platform php 8.1.33 (deploy runtime), optimize-autoloader/classmap-authoritative
  false (live path resolution, no class-map cache). autoload.files left empty:
  global functions are still loaded by existing require glue; moving them is
  deferred until that glue is removed.
- src/vendor/ + src/composer.lock: committed (deploy path has no Composer);
  generated with 'composer update' from src/. Regenerate with dump-autoload.
- src/bootstrap.php, tests/bootstrap.php: require vendor/autoload.php first,
  then the legacy autoload.php.
- src/autoload.php: drop the igbinary disk cache (enableFileCache/saveCache/
  shutdown handler/root-chown + bottom call); register at the END of the SPL
  queue (prepend=false) so Composer wins for XcVm\* and only still-global
  classes fall through to the in-memory scanner.
- Makefile: add vendor to LB_DIRS so load-balancer archives ship the loader.
- phpstan.dist.neon: exclude src/vendor/* from analysis.
- .gitignore: document that src/vendor/ is intentionally tracked.
- ci.yml: add composer-audit job (no-op until real require deps exist).

Verified: php -l clean; Composer first / XC_Autoloader last in the SPL stack;
tmp/cache/autoload_map no longer written; PHPUnit 292/292; PHPStan no errors.
2026-06-24 19:07:37 +03:00
Divarion-D b9e911e7e8 fix(phpstan): resolve false positives and real bugs (988 → 622)
Systemic fixes (cascade across modules):
- Type `$db` params as \DatabaseHandler in 38 files (was `object`), so
  PHPStan resolves get_row()/query() and stops inferring closed array
  shapes — clears offsetAccess.notFound clusters.
- Database/DatabaseHandler: correct get_row()/clean_row() PHPDoc to
  array<string,mixed>, and query() $buffered param to mixed (it is the
  first positional bind value via func_get_args, not a bool flag).
- constants stub generator: explicit type overrides (HOST/PAGE_NAME →
  string, PHP_ERRORS → bool) to avoid null/mixed false positives.
- phpstan.dist.neon: scanFiles autoload.php/bootstrap.php; ignore
  unactionable FPs (dynamic require paths, proprietary XC_VM ioncube
  class, MaxMind vendor lib, ext-inotify stub gap).

Real bugs fixed:
- streaming/ConnectionLimiter: appended the whole accumulated UUID array
  instead of a single uuid, breaking per-stream temp-file cleanup.
- streaming/TimeshiftClient: dead `|| $x == 3` branch (always redundant).
- streaming/AsyncFileOperations: redundant is_array after === false.
- core/Storage/DropboxClient: @param callback → callable|null.

streaming module is clean (0 errors); infrastructure 39 → 27.
2026-06-23 19:46:33 +03:00
Divarion-D 198b35bdf6 docs(core/Http,bootstrap): add English DocBlocks (19 methods)
ApiClient, CurlClient, StreamContext pipeline ctx, and bootstrap boot
sequences/polyfill. Completes core DocBlock coverage. No behavior change.
2026-06-22 11:21:56 +03:00
Divarion-D b7d4261807 feat(bootstrap): wire domain DI, container health check, and BootContext enum
wireDomainDatabase() called after container population — injects the db
service into all 32 domain classes and 6 module cron classes via their
static setDb() method so no domain code needs global \$db at runtime.

assertContainerHealth() added as a fail-fast guard after populateContainer():
verifies 'events' is always present, 'db' when database is ready, 'redis'
when Redis is ready. Throws RuntimeException listing all missing services.

BootContext enum replaces the CONTEXT_* string constants; bootstrap now uses
BootContext::ADMIN, CLI, STREAM, MINIMAL throughout for type safety.
2026-06-15 18:06:55 +03:00
Divarion-D d243587d08 fix(bootstrap.php): create symlink for legacy 'reseller' assets to 'admin' 2026-06-14 15:21:14 +03:00
Divarion-D 93677ca087 Refactor code structure for improved readability and maintainability 2026-06-14 12:59:28 +03:00
Divarion-D 8f796254ed Refactor configuration handling and database connections
- Removed ConfigLoader.php and transitioned to using ConfigReader for configuration management.
- Updated DatabaseHandler instantiation to no longer rely on global $_INFO, instead using default parameters.
- Enhanced Database and MigrationRunner classes to improve error handling and connection management.
- Simplified RedisManager connection logic by utilizing XC_VM::redis_connect().
- Adjusted various controllers and services to align with the new configuration and database connection methods.
- Removed unnecessary global variables and improved code readability across multiple files.
- Updated comments and documentation to reflect changes in configuration handling and database connections.
2026-06-12 00:54:31 +03:00
Divarion-D 2b499bbd47 refactor(bootstrap): extract StreamingRequestBootstrap and WebApiBootstrap
- StreamingRequestBootstrap: unified entry for streaming endpoints
- WebApiBootstrap: unified entry for web API requests
- index.php: use new bootstrap classes instead of direct requires
- www/init.php, www/stream/init.php: mark as deprecated shims
- StatusCommand: use StreamingRequestBootstrap::init()
- autoload.php, bootstrap.php: register new classes
2026-04-20 20:34:19 +03:00
Divarion-D 788ec37637 refactor: replace DEVELOPMENT flag, fix bootstrap and logging
- Remove DEVELOPMENT constant from AppConfig.php; introduce DB_ACCESS_ENABLED
  (controls phpMiniAdmin access in admin panel only, not core DB connections)
- Detach bootstrap.php from www/constants.php: load core/Config/* and
  core/Logging/Logger directly; define PHP_ERRORS fallback
- Switch Logger::init() to PHP_ERRORS in bootstrap.php, stream/init.php,
  RequestGuard.php; remove leftover TODO comment
- Logger: always set error_reporting(E_ALL); UI visibility controlled
  separately via display_errors; rename $development -> $showErrors
- MigrationRunner: track applied/failed counts separately; failed migrations
  are not marked as applied
- Replace DEVELOPMENT with DB_ACCESS_ENABLED in admin settings.php and
  database.php (phpMiniAdmin gate)
- Replace DEVELOPMENT with PHP_ERRORS in CertbotCronJob
- Docs (en/ru): add DB_ACCESS_ENABLED flag description; update feature-flags,
  updates_checklist, http-request-handling; remove DEVELOPMENT references
- MIGRATION.md: mark L-1 as done, remove from backlog and wave A;
  unblock L-2; renumber steps
2026-04-19 18:13:56 +03:00
Divarion-D 6cc892f9a7 refactor: eliminate proxy functions, migrate to direct class method calls
312 files changed, 2866 insertions(+), 24110 deletions(-)

Proxy function replacements (130+ functions):
- goHome() -> AdminHelpers::goHome()
- checkPermissions() -> PageAuthorization::checkPermissions()
- getBouquet/getCategory/etc -> Service::getById()
- deleteStream/deleteLine/etc -> Repository/Service::delete()
- APIRequest/systemapirequest -> ApiClient::request/systemRequest()
- prepareArray/preparecolumn -> QueryHelper methods
- confirmIDs/parserelease/etc -> AdminHelpers methods
- getSettings/clearSettingsCache -> SettingsManager methods
- destroySession -> SessionManager::clearContext()
- getMag/getEnigma/deleteMAG/etc -> MagService/EnigmaService
- getSeriesTrailer/getMovieTMDB/etc -> TMDbService methods

Removed legacy files:
- src/includes/admin.php (main proxy hub)
- src/includes/libs/ (35+ files moved to core/modules)
- src/includes/python/ (moved to bin/python)
- src/includes/api/ (moved to Controllers)
- src/includes/ts.php, reseller_api.php
- src/infrastructure/legacy/admin_proxies.php
- tools/run_scan.sh, update_redis_conf.sh

Additional fixes:
- SQL query placeholder migration (BouquetService, CategoryService)
- PHP 8.x null-safe access (live.php, server_view.php, stream.php)
- TmdbCron: extracted variable for repeated similar_text calls
2026-04-09 21:24:48 +03:00
Divarion-D 59bfb6f942 Add EventDispatcher integration to bootstrap and module loader
- Updated the XC_Bootstrap class to include the EventDispatcher class in the service container.
- Modified the ModuleLoader class to utilize the EventDispatcher for subscribing to events, enhancing the event handling mechanism.
2026-04-07 21:48:20 +03:00
Divarion-D 738973c5db docs(php): add standardized file headers across codebase
- Add @author, @copyright, @link, @version, @license to 399 PHP files
- MERGE mode: inject metadata into 243 existing docblocks (preserving docs)
- INSERT mode: create new docblocks for 156 files without headers
- Skip 3 files that already had correct headers
- Exclude third-party libs (TMDb, mobiledetect, Dropbox, etc.)
- Exclude bin/, ministra/, content/, tmp/, resources/, module views
- Update tools/add_headers.php to v2 with MERGE strategy
2026-04-05 22:38:36 +03:00
Divarion-D d2c439df81 chore: remove stalker dead code, translate bootstrap comments to English 2026-03-20 16:10:47 +03:00
Divarion-D 3c876d4551 fix(bootstrap): add missing defineStatusConstants() call in CONTEXT_ADMIN
During bootstrap layer migration, `defineStatusConstants()` was moved to `XC_Bootstrap` but its invocation was not added to `boot()`. This left `STATUS_SUCCESS`, `STATUS_FAILURE` and other status constants undefined, causing a fatal error on admin login.

Added `self::defineStatusConstants()` to the `CONTEXT_ADMIN` branch before `initAdminGlobals()`.
2026-03-18 22:04:02 +03:00