Commit Graph
5 Commits
Author SHA1 Message Date
AbdoAhmedElbanaaandDivarion_D e264443909 fix(player-api): tolerate null bouquets and stream icon during player login
Port of Rosmi720/XC_VM@8f41d206. Harden the streaming user-info path against
null/malformed data that caused a fatal TypeError on player login:

- ImageUtils::validateURL() accepts null/empty (nullable icon columns) → ''.
- UserRepository::decodeUserFields() tolerates already-decoded arrays, null
  columns and malformed JSON (via a shared decodeJsonField helper).
- aggregateBouquetIds() skips non-array bouquet groups (mergeBouquetGroup
  helper); getStreamingUserInfo() resolves the bouquet map from the shared
  cache / DB when the caller passes none (resolveBouquets helper).
- PlayerApiController::getOutputFormats() guards a non-iterable input and
  falls back to the full format set.

Adapted to this tree: kept the existing null-safe category_map / active_cons
handling, and split the added guards into small covered helpers to stay within
the complexity ceiling (unit test for resolveBouquets).
2026-09-21 18:55:17 +03:00
a8bec79d21 fix(player-api): sign-in crashed with a TypeError before answering
player_api loads the bouquet list only for the three stream-list
actions and passes null otherwise, but the cs-fix pass (758a9cab) typed
getStreamingUserInfo()'s $rBouquets as a non-nullable array. So the
sign-in call every app makes first, the category calls, the EPG and info
calls — even a wrong password — died with a TypeError page instead of
JSON: no player could sign in. The Ministra portal passes the cache's
null the same way when the bouquet cache file is missing.

Accept null as "no bouquets". Also skip a bouquet newer than the
category map (built by the heavy cache pass) instead of warning about an
undefined key — that warning alone broke the JSON where errors display.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y4P9p5BXijMoGXd31tN6Zp
2026-09-18 09:57:17 +00:00
rootandClaude Opus 5 fd13c94032 fix(devices): deleting an unpaired MAG or Enigma2 device failed
MagService::getById() and EnigmaService::getById() look up the paired line
with UserRepository::getLineById($rRow['user']['pair_id']), and pair_id is
NULL for a device without a pair. The `int` type the cs-fix pass (758a9cab)
put on getLineById() made that a TypeError, so loading such a device —
deleting it, among others — answered an empty page and changed nothing.
Found by the new E2E device test.

getLineById() is also fed activation codes' nullable subscriber_id and raw
request values, so the guard lives there: anything that is not a positive id
finds nothing, as the untyped version did.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016WDhDajBPziJwjWZcXnh6R
2026-09-16 14:18:09 +00:00
Divarion_D 8f72218ea6 refactor(user): consolidate getStreamingUserInfo/getUserInfo shared blocks
The two methods were ~90% duplicate, differing only in how they obtain
settings/cache/bouquets and in the divergent GeoIP + signal backends
(GeoIPService/file-signals vs GeoIP/Redis) that stay inline. Extract the
identical blocks into private helpers, called by both:

  loadUserRow             - credential resolution (token/cache file or DB),
                            resolving $rUserID by reference so the cached
                            re-verification keeps its exact behaviour
  verifyCachedCredentials - cached access-token / username+password re-check
  decodeUserFields        - JSON line fields -> arrays
  resolveOutputFormats    - allowed output-format keys
  aggregateBouquetIds     - bouquet -> channel/series/vod/live/radio id lists
  resolveCategoryIds      - bouquet -> category ids

Also de-obfuscate the remaining `if (cond) {} else { body }` blocks in both
methods. Net -74 lines despite adding the shared helpers (~240 lines of
duplication removed). Behaviour preserved; the file-vs-Redis signal divergence
is intentionally left as-is (separate decision).

Tests: UserRepositoryTest covers the pure helpers (aggregate/category/decode/
verify), 12 tests total. Validated live: player_api/testxc returns auth=1,
Active, allowed_output_formats=[m3u8,ts,rtmp]; on-demand /live start still works.

Verified: php -l, phpunit (430 tests, 962 assertions), make gates.
2026-08-09 01:19:04 +03:00
Divarion_D d9138f228a refactor(user): simplify getE2Info/getUserInfo, fix the isp_asn miss bug
- getE2Info: collapse the obfuscated `if (cond) {} else { body }` chain into
  straight positive-form ifs; drop the redundant re-init of pair_line_info.
- getUserInfo: same de-obfuscation of the ISP block, and fix the same
  "Undefined array key isp_asn" bug already fixed in getStreamingUserInfo — the
  ISP-persist step ran even on a GeoIP miss (con_isp_name null), reading the
  undefined isp_asn key and writing a null isp_desc/as_number to the line.
- Extract the persist predicate both methods shared into a pure, tested
  UserRepository::ispChanged() helper (+ tests/Unit/UserRepositoryTest.php).

Verified: php -l, phpunit (423 tests, 944 assertions), make gates.
2026-08-09 01:03:16 +03:00