Commit Graph
648 Commits
Author SHA1 Message Date
Divarion-D fd35f00c4d fix(views): import migrated classes at top of 5 admin view templates
enigma, episode, episodes, process_monitor and stream_view referenced migrated
classes (UserRepository, BouquetService, StreamRepository, RequestManager,
SettingsManager, ...) by short name with either no `use` or a `use` placed
*below* the first usage. PHP imports outside the top scope are positional, so the
short name resolved to a now-nonexistent global class — a runtime fatal on those
admin pages (php -l passes; not covered by PHPStan/PHPUnit). The migration's
automated `use` insertion missed them due to the interleaved HTML / short-tag
(<? , <?=) structure, and the later php-cs-fixer pass stripped some as 'unused'
because it could not see usage inside short-tag blocks.

- Consolidate every needed `use XcVm\...;` into a single top-of-file PHP block.
- Exclude Public/Views and Modules/*/views from php-cs-fixer (no_unused_imports
  is unreliable on short-tag templates); their import correctness is enforced by
  the new check_procedural_use gate instead.

Verified: php -l (short_open_tag=1) clean; PHPStan no errors; PHPUnit green.
2026-06-25 20:57:37 +03:00
Divarion-D fc0fdb2f29 Fix documentation links in Reseller controllers and related classes to point to the correct GitHub repository URL. Remove unused directory registration code in autoload.php. 2026-06-25 20:32:18 +03:00
Divarion-D 9eec63937e style: import/namespace hygiene across src (PHP-CS-Fixer)
Apply 'make cs-fix' — 493 files. Mechanical, import-block only:
- sort use statements alphabetically (class/function/const grouped);
- drop imports left unused by the PSR-4 migration (e.g. classes referenced by
  leading-backslash FQCN whose redundant 'use' the automated insertion had added);
- one blank line after namespace and after the import block; collapse stray
  blank lines around use.

No logic changes. Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; and a
temporary PHPStan pass over src/Public/Controllers confirms no still-referenced
import was removed (0 unresolved classes). 'use' after inline HTML in view
templates is valid and aliases correctly (verified) — those imports are sorted too.
2026-06-25 20:24:36 +03:00
Divarion-D 1a0ad5667a chore(cs): add PHP-CS-Fixer (import/namespace hygiene only)
Add friendsofphp/php-cs-fixer as a committed Composer dev dependency (src/vendor/,
same model as PHPStan — no composer install on deploy).

- .php-cs-fixer.dist.php: deliberately NARROW ruleset — no_unused_imports,
  ordered_imports, no_leading_import_slash, single_line_after_imports,
  blank_line_after_namespace, no_extra_blank_lines[use]. NO @PSR12 / indentation
  rules: the codebase is tab-indented legacy and a full reformat would be
  unreviewable. Indent forced to tabs, LF endings. Excludes vendor, the bundled
  Modules/tmdb/lib, tmp/, backups/.
- Makefile: 'make cs' (dry-run, fails on diff — CI) and 'make cs-fix' (apply).
- CI: new 'Code Style (PHP-CS-Fixer)' job running 'make cs' on PHP 8.3.
- .gitignore: ignore .php-cs-fixer.cache.
2026-06-25 20:24:34 +03:00
Divarion-D 50ae44a87c chore(psr4): final phase — retire the XC_Autoloader fallback scanner
The per-file PSR-4 migration is complete: every class resolves via the Composer
autoloader (src/vendor/, PSR-4 XcVm\* + M3uParser/Chrisyue) or an explicit require
(the bundled tmdb/lib + M3u libs, MinistraBootstrap, procedural entry points). The
ioncube XC_VM class stays guarded.

- XC_Autoloader::init() is now a no-op: it no longer registers the SPL directory
  scanner. The class is kept one release as a no-op stub (its clearCache()/
  warmCache() remain so StartupCommand keeps working); it will be deleted in a
  follow-up (then dropped from bootstrap require / PHPStan scanFiles /
  LB_ROOT_FILES / deleted_files.txt).
- bootstrap.php still requires autoload.php (it defines MAIN_HOME and the stub).

Verified: only the Composer autoloader is registered (XC_Autoloader gone from the
SPL stack); every layer + vendored lib resolves via Composer; the 4 modules load
via the ModuleLoader PSR-4 resolver; PHPStan no errors; PHPUnit 295/295 — and ~20x
faster (0.26s vs 5s) now that class misses no longer trigger a full directory rescan.
2026-06-25 20:06:32 +03:00
Divarion-D 045b8f6bd0 chore(deps): install PHPStan via Composer, drop downloaded PHAR
The downloaded phpstan.phar could not resolve namespaced third-party
packages now living in src/vendor/ (M3uParser, PhpM3u8), failing CI with
class.notFound on StreamService::parseM3U.

- add phpstan/phpstan 2.1.17 as a Composer dev dependency (committed to
  src/vendor/); the vendor/bin/phpstan binary auto-loads
  src/vendor/autoload.php, so vendor symbols resolve
- Makefile: drop the phpstan-install PHAR download; run src/vendor/bin/phpstan
- remove the stale Core/Parsing/M3uParser excludePath from phpstan.dist.neon
- drop the obsolete tools/phpstan/phpstan.phar gitignore entry

make phpstan: No errors (278 files).
2026-06-25 19:58:38 +03:00
Divarion-D 6582b911cb chore(deps): fix composer.json post-update note (lock is gitignored)
composer.lock is no longer committed (gitignored); update the
post-update-cmd notice to reference only the committed vendor/.
2026-06-25 19:50:01 +03:00
Divarion-D 7c35be68cc chore(deps): migrate PhpM3u8 to Composer (chrisyue/php-m3u8 ^4)
- add chrisyue/php-m3u8 4.0.3 to committed vendor/ (PHP >=7.4, no
  transitive dependencies)
- remove vendored Core/Parsing/PhpM3u8 snapshot and manual bootstrap
- autoload \Chrisyue\PhpM3u8\ from committed vendor/ instead of a path
  mapping; library is used only by the test suite
2026-06-25 19:42:13 +03:00
Divarion-D db9b8ea7fc chore(deps): migrate M3uParser to Composer (gemorroj/m3u-parser 6.0.1)
- add gemorroj/m3u-parser 6.0.1 to committed vendor/ (PHP >=8.0.2;
  upstream 6.1.0 requires PHP 8.2, incompatible with the 8.1 target)
- remove vendored Core/Parsing/M3uParser snapshot and manual bootstraps
- autoload \M3uParser\ from committed vendor/ instead of a path mapping
- stop tracking composer.lock (already gitignored); CI now audits the
  committed vendor/composer/installed.json without --locked
2026-06-25 19:36:18 +03:00
Divarion-D 1499da6a14 chore(psr4): phase 3 — namespace Public controllers (final layer)
Namespace all 174 Public controllers into XcVm\Public\Controllers\<Admin|Api|
Player|Reseller>, completing the per-file namespace migration. View templates and
entry points (index.php, admin/*.php, stream/*.php, progress/, routes/*.php,
Views/*) stay procedural/global and only gain use imports.

- Split the 3 multi-class Api files per PSR-4: AdminApiController→+AdminAPIWrapper,
  Enigma2ApiController→+SimpleXMLExtended (extends \SimpleXMLElement),
  ResellerRestApiController→+ResellerAPIWrapper (use-block copied to each new file).
- Add use to referrers — the procedural route files (routes/admin|player|reseller.php)
  and index.php now import each routed controller; sibling controllers extend their
  base class in the same namespace.
- Qualify built-ins/ioncube/global in the namespaced controllers (\Exception,
  \DateTime, \PDO, \SimpleXMLElement, \ZipArchive, \ReflectionClass,
  \XC_Bootstrap, \XC_VM, ...). Verified zero unresolved classes by temporarily
  analysing src/Public/Controllers under PHPStan, then reverting to scanDirectories
  (the ~346 pre-existing legacy findings there are out of scope for this migration).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; no global controller
class-files remain; leading-backslash re-sweep clean.
2026-06-25 19:26:09 +03:00
Divarion-D 43e2f275b1 chore(psr4): phase 3 — namespace module sub-classes
Namespace the modules' own classes into XcVm\Module\<Pascal> (Plex, Watch, Tmdb,
Ministra) — PlexController/PlexService/PlexCron/..., WatchController/WatchService/...,
TmdbController/TmdbCron/TmdbApiService/..., PortalHandler/PortalHelpers (~23 classes).
They now resolve through the Phase-2 ModuleLoader PSR-4 resolver.

- The bundled third-party tmdb/lib/* (TMDB client, Entities, roles, config) stays
  GLOBAL, like the other vendored libs; namespaced Tmdb classes reference it via
  \TMDB etc.
- Rewrite the *Module classes' (and any sibling) 'use ShortName;' imports → FQCN;
  add use to referrers; convert leading-backslash refs. Sub-classes keep the
  Core/Domain/Cli use imports added during those layers.
- Qualify built-ins (\DateTime, \Exception, \PDO, ...) and the global lib classes.
- phpstan-baseline.neon regenerated.

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; all 4 modules load and
their sub-classes (e.g. XcVm\Module\Plex\PlexService) resolve via the module
PSR-4 autoloader; re-sweep clean.
2026-06-25 19:12:48 +03:00
Divarion-D 3377236d77 chore(psr4): phase 3 (Cli) — namespace Cli + switch console.php to FQCN discovery
Namespace all 55 Cli classes into XcVm\Cli (CommandInterface, CommandRegistry,
CronTrait, DaemonTrait), XcVm\Cli\Commands (28) and XcVm\Cli\CronJobs (23);
migration_logic.php stays procedural/global.

- console.php: switch command discovery from basename==classname + manual require
  to FQCN resolution — each scan dir maps to its PSR-4 namespace, classes load via
  Composer, implementsInterface(CommandInterface::class). Drop the manual
  CommandInterface/CommandRegistry requires. This is the atomic switch the plan
  required to land with the Cli namespacing.
- Commands/CronJobs get 'use XcVm\Cli\CommandInterface;' (implements) and the
  trait imports 'use XcVm\Cli\CronTrait;'/'DaemonTrait;'; rewrite the modules'
  'use CommandRegistry;' → FQCN; qualify built-ins/global (\ReflectionClass,
  \PDO, \Exception, \RuntimeException, \XC_Autoloader, \XC_VM).
- Fixtures: 'use CommandRegistry;' → FQCN; InterfaceContractTest registerCommands
  param-type → FQCN. phpstan-baseline.neon regenerated.

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; FQCN discovery resolves
51 classes (49 implement CommandInterface); no mangled FQCNs; re-sweep clean.
2026-06-25 19:03:39 +03:00
Divarion-D 62d2d1d942 chore(psr4): phase 3 — namespace Streaming layer
Namespace all 17 Streaming classes into XcVm\Streaming\<Subdir> (Auth, Balancer,
Codec, Delivery, Health, Lifecycle, Protection + root AsyncFileOperations,
StreamingBootstrap, TS).

- Add namespace to every class; add use to referrers across src/ and tests/;
  convert leading-backslash refs from earlier commits (\FfmpegPaths,
  \FFprobeRunner, \ProcessChecker, \StreamingBootstrap) to FQCNs.
- Qualify built-ins/ioncube inside Streaming (\DateTime, \DateTimeZone,
  \Exception, \XC_VM).
- FfmpegPathsTest: new ReflectionClass('FfmpegPaths') string → ::class FQCN.
- phpstan-baseline.neon regenerated (291).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; no mangled FQCNs;
leading-backslash re-sweep clean.
2026-06-25 18:55:35 +03:00
Divarion-D aaa8e2a23a chore(psr4): phase 3 — namespace Infrastructure layer
Namespace the Infrastructure classes and PascalCase its subdirectories for PSR-4
consistency with Core/Domain:
- git mv bootstrap/→Bootstrap/, cache/→Cache/, database/→Database/, redis/→Redis/;
  update the require paths to the procedural Bootstrap/*.php glue files.
- Namespace the 7 classes: StreamingRequestBootstrap, WebApiBootstrap →
  XcVm\Infrastructure\Bootstrap; CacheReader → \Cache; DatabaseFactory →
  \Database; RedisManager → \Redis; ResellerApiDispatcher, ResellerTableRenderer
  → XcVm\Infrastructure. The procedural Bootstrap glue files stay global.
- Qualify built-ins/ioncube (\Redis, \RedisException, \DateTime, \Exception,
  \XC_VM) and still-global \StreamingBootstrap; add use to referrers; convert
  the leading-backslash \CacheReader/\DatabaseFactory/\RedisManager refs from
  earlier commits to FQCNs.
- deleted_files.txt: old lowercase subdir paths for client cleanup.
- phpstan-baseline.neon regenerated.

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; re-sweep clean.
2026-06-25 18:45:19 +03:00
Divarion-D 42d9ca8ea0 chore(psr4): phase 3 — namespace Domain layer
Namespace all of Domain into XcVm\Domain\<Subdir> (33 classes across Bouquet,
Device, Epg, Line, Security, Server, Stream, User, Vod).

- Add namespace to every Domain class; add use to referrers across src/ and
  tests/; convert the leading-backslash refs qualified in earlier Core commits
  (\UserRepository, \ServerRepository, \BouquetService, \CategoryService,
  \ConnectionTracker, \BlocklistService, ...) to their FQCNs.
- Qualify still-global / built-in deps inside Domain with leading backslash
  (\RedisManager, \TMDB, \WatchService, \FFprobeRunner, \ProcessChecker,
  \Exception, \DateTime, \PDO, ...) — Infrastructure/Streaming/module classes
  migrate later.
- BruteforceGuard: string guards class_exists('ServerRepository'/'BlocklistService')
  → ::class FQCN; drop the now-always-true method_exists check.
- phpstan-baseline.neon regenerated (292→291).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; leading-backslash
re-sweep across Domain classes is clean.
2026-06-25 18:39:28 +03:00
Divarion-D da291e20f8 chore(psr4): phase 3 (Core) — namespace remaining Core subdirs
Namespace the rest of Core, completing the Core layer:
- Backup, Boundary, Cache (CacheInterface/FileCache/RedisCache), Diagnostics,
  GeoIP (GeoIPService/MaxMindUpdater), Init (LegacyInitializer), Localization
  (Translator), Process (Thread/Multithread/ProcessManager), Updates
  (GitHubReleases), Util (NetworkUtils, AdminHelpers, Encryption, GeoIP,
  ImageUtils/ImageResizeService, Mobile_Detect, StreamUtils, SystemInfo,
  TimeUtils), Validation (InputValidator) → XcVm\Core\<Subdir>.
- Rename GithubReleases.php → GitHubReleases.php so the file matches its class
  name (PSR-4 is case-sensitive); fix the WebApiBootstrap require accordingly.
- Qualify built-ins (\Exception, \DateTime, \DateTimeZone, \Redis,
  \RuntimeException, \BadMethodCallException, ...) and still-global deps
  (\ServerRepository, \CacheReader, \DatabaseFactory, \BouquetService,
  \CategoryService, \FfmpegPaths, \StreamSorter, \XC_VM). LegacyInitializer's
  Domain calls stay \-qualified (the known Core→Domain exception).
- Add use to referrers; fix leading-backslash refs from earlier commits; fix
  string class refs class_exists('Translator'/'NetworkUtils'/...) → ::class.
  Remove the duplicate global 'use BoundaryInterface;' in MinistraModule.
- phpstan-baseline.neon regenerated.

Core is now fully namespaced (procedural constant/error/RequestGuard files stay
global by design; M3uParser/PhpM3u8 remain vendored). Verified: php -l clean;
PHPStan no errors; PHPUnit 295/295; leading-backslash re-sweep clean.
2026-06-24 22:35:33 +03:00
Divarion-D dc335a8334 chore(psr4): phase 3 (Core) — namespace Core/Enum + Core/Exception
- Core/Enum → XcVm\Core\Enum (BootContext, ModuleState, ServerEnvironment).
- Core/Exception → XcVm\Core\Exception (XcVmException) + \Container
  (ContainerException, CircularDependencyException, ServiceCreationException) +
  \Module (ModuleException + the 4 module exceptions). The hierarchy resolves:
  XcVmException extends \RuntimeException; the Container/Module exceptions extend
  XcVmException via use; ContainerException keeps its PSR ContainerExceptionInterface.
- Add use to referrers across src/ and tests/; fix the leading-backslash refs
  qualified in earlier hub commits (\ModuleState, \ServerEnvironment,
  \XcVmException, \ContainerException, \ModuleLoadException, ...) to their FQCNs.
- phpstan-baseline.neon regenerated (292→292).

Verified: php -l clean; PHPStan no errors (first pass); PHPUnit 295/295;
leading-backslash re-sweep clean.
2026-06-24 22:23:42 +03:00
Divarion-D 432c8a010a chore(psr4): phase 3 (Core) — namespace Core/Events
Move Core/Events into XcVm\Core\Events and its sub-trees: \Contract
(StoppableEventInterface), \Auth, \Module, \Settings, \Stream (the event
classes), plus root EventDispatcher, ListenerProvider, ListensTo, AbstractEvent.

- Namespace 14 files across 6 namespaces; cross-namespace refs imported via use
  (AbstractEvent/EventDispatcher → Contract\StoppableEventInterface; Stream events
  → root AbstractEvent). Built-in \Attribute (ListensTo) and ioncube \XC_VM
  (PackageInstalledEvent) qualified.
- Rewrite 'use ListensTo;' → FQCN; add use to referrers across src/ and tests/;
  fix leading-backslash refs (\EventDispatcher, \ListensTo, \PackageInstalledEvent
  from the Module commit) to their FQCNs.
- Tests: add real top-level use imports to ModuleLoaderBootTest (EventDispatcher)
  and ListensToAttributeTest (ListensTo) — the use-inserter skipped/mis-placed them
  due to a namespace() method and a heredoc fixture already containing the FQCN.
- phpstan-baseline.neon regenerated (292→292).

Completes Core/Container + Core/Events. Verified: php -l clean; PHPStan no errors;
PHPUnit 295/295; EventDispatcher resolves and AbstractEvent implements
XcVm\Core\Events\Contract\StoppableEventInterface.
2026-06-24 22:18:52 +03:00
Divarion-D e8b7ab8b2e chore(psr4): phase 3 (Core) — namespace Core/Container
Move Core/Container into XcVm\Core\Container (ServiceContainer) and
Core/Container/Psr into XcVm\Core\Container\Psr (ContainerInterface,
ContainerExceptionInterface, NotFoundExceptionInterface, NotFoundException).

- Namespace ServiceContainer + the 4 PSR-11 interfaces/classes.
- ServiceContainer: import the PSR siblings (use ...\Psr\ContainerInterface,
  NotFoundException); migrated deps (DatabaseHandler/ModuleInterface/Request/
  SettingsManager) keep their use; still-global exceptions/decorators qualified
  with leading backslash (\ContainerException, \XcVmException, \Exception, ...).
- Rewrite 'use ServiceContainer;' → FQCN (incl. module fixtures); add use to
  referrers across src/ and tests/; fix leading-backslash \ServiceContainer refs.
- Core/Exception/Container/ContainerException: import the moved PSR
  ContainerExceptionInterface.
- Router: class_exists('ServiceContainer') → ::class. InterfaceContractTest boot
  param-type → FQCN. Repaired use-inserter mis-placement in the two namespace()
  fixture tests.
- phpstan-baseline.neon regenerated (292→292).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; ServiceContainer
resolves and implements XcVm\Core\Container\Psr\ContainerInterface.
2026-06-24 22:13:35 +03:00
Divarion-D 881991e52b chore(psr4): phase 3 (Core hubs) — namespace Core/Module
Move Core/Module into XcVm\Core\Module (BaseModule, ModuleInterface,
MigratableInterface, ModuleLoader, ModuleManager, NavbarRegistry, NavbarItem,
CoreNavbarProvider) and Core/Module/Contract into XcVm\Core\Module\Contract
(the 6 provider interfaces). Completes the Core hub layer.

- Namespace 14 files (8 root + 6 Contract). Root files import the contracts via
  'use XcVm\Core\Module\Contract\...'; NavbarProviderInterface imports the
  root NavbarRegistry. Qualify still-global deps with leading backslash
  (\ServiceContainer, \CommandRegistry, \ModuleState, \ServerEnvironment,
  \EventDispatcher, \ListensTo, the Module exceptions, \ZipArchive,
  \InvalidArgumentException, \RuntimeException) — Container/Events/Enum/Exception
  migrate later. Migrated deps (Router, StreamPipeline, ...) keep their use.
- Rewrite the modules' 'use BaseModule/NavbarRegistry/NavbarItem;' → FQCN; add
  'use XcVm\Core\Module\...;' to other referrers across src/ and tests/.
- Fix pre-existing leading-backslash refs to the FQCN.
- Tests: qualify the module fixtures' generated 'use ModuleInterface;' /
  'use BaseModule;' / 'use NavbarRegistry;' and the registerRoutes type hint to
  FQCN; add real top-level use imports to the fixture-builder tests; update
  InterfaceContractTest registerNavbar param-type to the FQCN. Repaired
  use-inserter mis-placements in the two tests that declare a namespace() method.
- Public/index.php: class_exists('ModuleLoader') → class_exists(ModuleLoader::class).
- phpstan-baseline.neon regenerated (292→292; no new/unknown-class errors).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; the 4 real modules
load and resolve as XcVm\Core\Module\ModuleInterface; leading-backslash
re-sweep across all migrated classes is clean.
2026-06-24 22:05:10 +03:00
Divarion-D 160adc1439 chore(psr4): phase 3 (Core hubs) — namespace Core/Auth
Move Core/Auth into XcVm\Core\Auth (Authenticator, Authorization, AuthRepository,
AuthService, BruteforceGuard, PageAuthorization, SessionManager).

- Namespace the 7 classes; same-namespace siblings unqualified; migrated deps
  (Logger, ApiClient, QueryHelper, SettingsManager, RequestManager) keep their
  existing use imports. Qualify still-global deps with leading backslash
  (\UserRepository, \NetworkUtils, \ServerRepository, \BlocklistService,
  \DatabaseFactory, \RedisManager, \AdminHelpers, \Encryption, \CodeService,
  \CodeRepository) — these migrate later with Domain/Util.
- Add 'use XcVm\Core\Auth\...;' to referencing files (Authorization 69,
  AuthRepository 24, BruteforceGuard 12, SessionManager/PageAuthorization 9,
  Authenticator 5, AuthService 3) across src/ and tests/.
- Fix pre-existing leading-backslash refs (e.g. Router's \Authorization, now
  \XcVm\Core\Auth\Authorization). Preserve class_exists('NetworkUtils',false)
  defensive string guards as-is (still-global classes).
- phpstan-baseline.neon regenerated (292→292; AuthRepository::getHMACById message
  re-anchored with namespace, no new/unknown-class errors).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; Auth classes resolve
via Composer; leading-backslash re-sweep clean.
2026-06-24 21:42:30 +03:00
Divarion-D 14202afd64 chore(psr4): phase 3 (Core hubs) — namespace Core/Http
Move Core/Http into XcVm\Core\Http (ApiClient, CurlClient, RequestManager,
Request, Response, Router) and Core/Http/Pipeline into XcVm\Core\Http\Pipeline
(StreamContext, StreamMiddlewareInterface, StreamPipeline). RequestGuard.php is
procedural (global functions) and stays global.

- Namespace the 9 classes; qualify still-global deps with leading backslash
  (\ServerRepository in ApiClient; \Authorization, \ServiceContainer,
  \AdminHelpers in Router) and built-in \Throwable; same-namespace siblings
  unqualified.
- Add 'use XcVm\Core\Http\...;' to referencing files — RequestManager 128,
  Router 19, ApiClient 15, Request 11, Response 6, CurlClient 5, plus Pipeline —
  across src/ and tests/.
- Rewrite the modules' 'use Router;' → 'use XcVm\Core\Http\Router;' (plex,
  watch, tmdb).
- Fix pre-existing leading-backslash global refs (\Router etc.) to the FQCN.
- Tests: fully-qualify the Router type hint in generated module fixtures
  (registerRoutes(\XcVm\Core\Http\Router ...)) and update the
  InterfaceContractTest param-type expectation to the FQCN. Also repaired two
  fixtures where the use-inserter mis-placed a 'use' (files declare a method
  literally named namespace(), which the tokenizer reports as T_NAMESPACE).
- phpstan-baseline.neon regenerated (292→292; class names in frozen messages
  gained the namespace, no new/unknown-class errors).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295; Http classes resolve
via Composer; leading-backslash re-sweep across migrated classes is clean.
2026-06-24 21:32:10 +03:00
Divarion-D 822e46af05 fix(psr4): qualify latent \SettingsManager refs in Public admin controllers
ServerController and ServerViewController called \SettingsManager::getAll() with a
leading backslash (global namespace), which broke after SettingsManager moved to
XcVm\Core\Config — the files' 'use' import does not cover a leading-\ reference.
PHPStan does not report src/Public and PHPUnit does not exercise these controllers,
so this was a latent runtime fatal on the admin server pages.

Drop the leading backslash so the existing use import resolves it. Full re-sweep
confirms no leading-backslash references to any migrated class remain in src/ or
tests/.
2026-06-24 21:16:17 +03:00
Divarion-D 42db4be509 chore(psr4): phase 3 (Core hubs) — namespace Core/Database
Move Core/Database into XcVm\Core\Database (DatabaseHandler, Database,
MigrationRunner, QueryHelper). First of the Core hub sub-layers.

- Namespace the 4 classes; DatabaseHandler extends Database (same namespace);
  built-ins/ioncube qualified (\PDO, \PDOException, \Exception, \Throwable,
  \XC_VM); Database keeps its 'use XcVm\Core\Logging\FileLogger;'.
- Add 'use XcVm\Core\Database\...;' to referencing files (DatabaseHandler 51,
  Database 64, QueryHelper 29, MigrationRunner 3) + 2 test files (PHPStan does not
  analyse tests/, so PHPUnit is the gate there).
- Rewrite pre-existing leading-backslash global refs (\DatabaseHandler etc., e.g.
  in @param docblocks of ResellerApiDispatcher/ResellerTableRenderer) to the full
  FQCN \XcVm\Core\Database\... — a 'use' import does not cover a leading-\
  reference. Done with a lookbehind so FQCN continuations and use-lines are intact.
- phpstan-baseline.neon regenerated (292→292; pre-existing Database/migration_logic
  findings re-anchored after class names in messages gained the namespace).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295.
2026-06-24 21:15:06 +03:00
Divarion-D 1892bf8e67 chore(psr4): phase 3 (Core leaf) — split + namespace Core/Parsing/XmlStringStreamer
Split the 7-class Core/Parsing/XmlStringStreamer.php (bundled prewk/xml-string-
streamer) per PSR-4 and namespace all into XcVm\Core\Parsing:
- XmlStringStreamer stays in XmlStringStreamer.php (class only).
- ParserInterface, StreamInterface, StringWalker, UniqueNode, File, Stdin each
  extracted to their own file.
- Built-in \Exception qualified (new \Exception + @throws \Exception); internal
  cross-references (implements ParserInterface/StreamInterface, extends File,
  new File/StringWalker/UniqueNode, parser/stream type hints) resolve within the
  shared namespace.
- 'use XcVm\Core\Parsing\XmlStringStreamer;' added to the 2 referrers
  (EpgCronJob, EPG); the sub-classes are only used internally by the factory.
- phpstan-baseline.neon regenerated (293→292; pre-existing XmlStringStreamer
  findings re-anchored to the new files, no new/unknown-class errors).

This completes the Core leaf layer: Logging, Storage, Config (all classes),
Parsing are namespaced. Procedural files (AppConfig/Binaries/Paths/ErrorCodes/
ErrorHandler) remain global by design; vendored M3uParser/PhpM3u8 untouched.

Verified: php -l clean (7 files); PHPStan no errors; PHPUnit 295/295; all 7
classes resolve via Composer with cross-namespace implements/extends intact.
2026-06-24 21:02:22 +03:00
Divarion-D 8ac1908554 chore(psr4): phase 3 (Core leaf) — namespace SettingsManager + SettingsRepository
Move the last two Core/Config classes into XcVm\Core\Config. SettingsManager
has the largest fan-out of the whole migration (referenced by ~224 files).

- Namespace SettingsManager (self-contained singleton, no class deps) and
  SettingsRepository (\FileCache:: qualified).
- Add 'use XcVm\Core\Config\SettingsManager;' to 224 referencing files and
  'use ...\SettingsRepository;' to 12 — call sites (SettingsManager::get(), etc.)
  unchanged. Done with a token-based inserter (after namespace/declare/<?php,
  idempotent, same-namespace files skipped).
- ToolsCommand::processRecaptcha: drop dead class_exists('SettingsManager') +
  method_exists guard (always autoloadable now) → call SettingsManager::clearCache()
  directly. This was the only string-literal class reference.

Core/Config is now fully namespaced (ConfigReader, DomainResolver, SettingsManager,
SettingsRepository); the procedural constant files (AppConfig/Binaries/Paths)
remain global by design.

Verified: php -l clean (226 files); PHPStan no errors (baseline unchanged — it is
line-independent so the added use-lines don't disturb it); PHPUnit 295/295; all
Config FQCNs resolve via Composer; sample Public referrers lint-clean.
2026-06-24 20:52:00 +03:00
Divarion-D 481e805e83 chore(psr4): phase 3 (Core leaf) — namespace ConfigReader + DomainResolver
Move ConfigReader and DomainResolver into XcVm\Core\Config (Composer PSR-4).
SettingsManager/SettingsRepository stay global for now (migrated together later
due to SettingsManager's large fan-out).

- Add namespace to both classes.
- Qualify still-global / ioncube refs: \XC_VM:: in ConfigReader; \CacheReader::,
  \ConnectionTracker:: in DomainResolver.
- Add 'use XcVm\Core\Config\...;' to the 15 referencing files (bootstrap, CLI
  commands/cron, LegacyInitializer, ModuleManager, stream + player controllers,
  player views, PlaylistGenerator, ...) — call sites unchanged.
- ModuleManager::isLoadBalancer: string class_exists('ConfigReader') →
  class_exists(ConfigReader::class) (the literal would now always be false).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295.
2026-06-24 20:43:40 +03:00
Divarion-D 784274006d chore(psr4): phase 3 (Core leaf) — namespace + split Core/Storage
Split the two-class Core/Storage/DropboxClient.php per PSR-4 and namespace both
into XcVm\Core\Storage:
- DropboxClient stays in DropboxClient.php (namespaced).
- DropboxException extracted to its own DropboxException.php (extends \Exception).
- Built-ins qualified in DropboxClient (\Exception catch, \CurlHandle docblocks).
- BackupService gets 'use XcVm\Core\Storage\DropboxClient;' (call sites unchanged).
- phpstan-baseline.neon regenerated (294→293; pre-existing DropboxClient findings
  re-anchored after the line shift, no new/unknown-class errors).

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295.
2026-06-24 20:39:03 +03:00
Divarion-D 15750f314c chore(psr4): phase 3 (Core leaf) — namespace Core/Logging
Move the Core/Logging layer into XcVm\Core\Logging (Logger, LoggerInterface,
FileLogger, DatabaseLogger, UpdateLogger). Composer PSR-4 now resolves them.

- Add namespace to the 5 logging classes; built-in \Throwable qualified in
  Logger; same-namespace LoggerInterface references unqualified.
- Add 'use XcVm\Core\Logging\...;' to the 16 referencing files (bootstrap,
  web/stream bootstraps, stream entry points, Database, EPG, update command/cron,
  auth, ministra) — call sites unchanged.
- Authenticator::logRecaptcha: drop the now-dead class_exists/method_exists
  guard (Logger is always autoloadable post-Composer) and call Logger::log
  directly.

Procedural Core/Error + Core/Config constants files (ErrorCodes/ErrorHandler/
AppConfig/Binaries/Paths — no classes) intentionally left global per plan.

Verified: php -l clean; PHPStan no errors; PHPUnit 295/295.
2026-06-24 20:33:55 +03:00
Divarion-D 1bd9438820 chore(psr4): phase 2 — real PSR-4 resolver in ModuleLoader
Rewrite ModuleLoader::registerModuleAutoloader() from a lossy short-name + glob
lookup into a true per-module PSR-4 resolver: the module's base namespace
(XcVm\Module\{Name}) maps onto its directory, and the namespace remainder
becomes the sub-path.

  XcVm\Module\Watch\WatchModule          → {modulePath}/WatchModule.php
  XcVm\Module\Watch\Service\WatchService → {modulePath}/Service/WatchService.php

- Only classes under the module's own namespace are claimed; everything else
  (global legacy classes, other modules, core) falls through untouched. This
  removes the short-name glob, so two modules — or two sub-namespaces in one
  module — can declare same-named classes without colliding.
- load() now derives the base namespace from the resolved FQCN and registers the
  autoloader after class resolution (reordered, still before the main require).
- Marketplace slug dirs unaffected (real $modulePath is used); encrypted-file
  handling preserved (require_once + zend_compile_file decrypt hook).
- resolveClassName()/load() already targeted XcVm\Module\{Pascal}\{Pascal}Module
  (done in earlier work) — left as is.

console.php FQCN discovery is intentionally NOT changed here: the Cli layer is
still global (CommandInterface, *Command, *CronJob), so switching discovery to
\XcVm\Cli\... would break it. Per the plan it switches atomically with the Cli
layer namespacing (phases 3..N).

New test tests/Unit/ModuleLoaderPsr4ResolverTest.php: sub-namespace resolution,
same-short-name no-collision, foreign-namespace fall-through.

Verified: php -l clean; PHPUnit 295/295 (+3); PHPStan no errors; all 4 real
modules (plex/watch/tmdb/ministra) load and their *Module FQCNs resolve.
2026-06-24 20:20:30 +03:00
Divarion-D 1a296d0985 chore(psr4): phase 1 — rename 7 top-level dirs to PascalCase
Atomic case-rename of the seven class-holding source directories to match the
PSR-4 namespace casing, plus every consequent path reference. No code logic
changes — pure structural rename. (config/content/resources/signals/migrations/
ministra/storage/tmp/vendor/www/bin stay lowercase.)

- git mv: core→Core, domain→Domain, infrastructure→Infrastructure,
  streaming→Streaming, modules→Modules, cli→Cli, public→Public (module subdirs
  like Modules/plex stay lowercase; loaded by ModuleLoader, not Composer).
- PHP filesystem paths updated across src/ + tests/: require/include, glob/scandir
  bases, view includes, asset/nginx-alias paths, autoload.php registerDirectories(),
  ModuleLoader/ModuleManager module roots, console.php discovery dirs.
- src/composer.json PSR-4 vendored-lib paths → Core/Parsing/...; vendor/ regenerated.
- nginx.conf: docroot + SCRIPT_FILENAME → Public/. SCRIPT_NAME and the public-facing
  /streaming/*.php compat routes are URLs, left unchanged.
- Build/CI: Makefile LB_DIRS / LB_DIRS_TO_REMOVE / LB_FILES_TO_REMOVE PascalCased
  (closes the LB-archive privileged-leak blocker); phpstan.dist.neon paths/
  scanDirectories/excludePaths; phpunit.xml.dist coverage; phpstan-baseline.neon
  regenerated (294→294 errors, no new resolution failures).
- migrations/deleted_files.txt: old lowercase trees listed for client cleanup
  (assumes case-sensitive FS — the supported Linux target).

Verified: grep-gate 0 live lowercase-dir require/include in src+tests; php -l clean;
PHPUnit 292/292; PHPStan no errors; Composer first / XC_Autoloader last in SPL stack;
global classes resolve from the renamed dirs.
2026-06-24 20:10:34 +03:00
Divarion-D 7e5732cdcb chore(psr4): phase 0 — Composer PSR-4 autoloader foundation
Introduce a committed Composer PSR-4 autoloader without changing class
resolution behavior, as the foundation for the incremental PSR-4 migration.

- src/composer.json: PSR-4 (XcVm\ -> ./, M3uParser\, Chrisyue\PhpM3u8\),
  platform php 8.1.33 (deploy runtime), optimize-autoloader/classmap-authoritative
  false (live path resolution, no class-map cache). autoload.files left empty:
  global functions are still loaded by existing require glue; moving them is
  deferred until that glue is removed.
- src/vendor/ + src/composer.lock: committed (deploy path has no Composer);
  generated with 'composer update' from src/. Regenerate with dump-autoload.
- src/bootstrap.php, tests/bootstrap.php: require vendor/autoload.php first,
  then the legacy autoload.php.
- src/autoload.php: drop the igbinary disk cache (enableFileCache/saveCache/
  shutdown handler/root-chown + bottom call); register at the END of the SPL
  queue (prepend=false) so Composer wins for XcVm\* and only still-global
  classes fall through to the in-memory scanner.
- Makefile: add vendor to LB_DIRS so load-balancer archives ship the loader.
- phpstan.dist.neon: exclude src/vendor/* from analysis.
- .gitignore: document that src/vendor/ is intentionally tracked.
- ci.yml: add composer-audit job (no-op until real require deps exist).

Verified: php -l clean; Composer first / XC_Autoloader last in the SPL stack;
tmp/cache/autoload_map no longer written; PHPUnit 292/292; PHPStan no errors.
2026-06-24 19:07:37 +03:00
Divarion-D 730aca1f7d fix(tmdb): correct entity get() @return array → mixed (clears 19 false positives)
The TMDB entity get($item) returns `empty($item) ? $this->_data : $this->_data[$item]`
— i.e. the whole array OR a single (scalar) item — but was annotated `@return
array`. That made PHPStan treat `$entity->get('id')` / `get('title')` as array,
producing false positives across the codebase: cast.string (TmdbCron, WatchItem),
argument.type (parseTitle/getMovie/getTVShow with array), and `.`-concatenation
"between string and array" errors. Corrected to `@return mixed` on get() in all
10 entity/config classes. No behaviour change; 19 false positives cleared, none
introduced.
2026-06-23 21:51:40 +03:00
Divarion-D cfad63c328 fix(tmdb): resolve TmdbService/TMDbService class-name collision (fatal)
PHP class names are case-insensitive, so the module's `TmdbService`
(search/getDetails/createClient) and the domain `TMDbService`
(getMovie/getSeries/addCategories) were the same identifier. getDetails() for a
series calls TMDbService::getSeriesTrailer(), which loaded the second file and
triggered a fatal "Cannot redeclare class" — series detail lookups crashed.

Renamed the module class to `TmdbApiService` (file, class, the two
TmdbController calls, the DI registration in TmdbModule, and doc refs). Also
cast TMDB ids to int at the getMovie/getTVShow/getSeason call sites.
2026-06-23 21:48:37 +03:00
Divarion-D fa34eeb7e7 fix(db,dropbox): declare variadic bind params; correct $expires type
- DatabaseHandler fetchAll/fetchAllKeyed/fetchOne/fetchValue/fetchColumn/
  update/delete documented `@param ...$params` but didn't declare the variadic
  in the signature (they read it via func_get_args). Declared `...$params` /
  `...$whereParams` so the @param is valid and callers get variadic checking.
  No behaviour change (func_get_args still captures everything).
- DropboxClient GetLink/GetCopyRef: the by-ref $expires out-param is a unix
  timestamp (int / int|false), not string|null — corrected the @param types.
2026-06-23 21:42:10 +03:00
Divarion-D 2cbf06b4e0 fix: ConnectionTracker == typo and Thread $process init type
- ConnectionTracker::getCapacity: `$rSettings['split_by'] == 'guar_band';` was a
  discarded comparison (==) where an assignment (=) was intended — the proxy
  maxclients→guar_band override never happened.
- Thread::__construct: initialised $process (typed resource|null) to int 0;
  set it to null to match the property type (and its own default).
2026-06-23 21:38:43 +03:00
Divarion-D 440e10fd60 fix(profile): GPU scale/deint dead-code — mirror CPU branch logic
In buildProfile() the GPU path (gpu_device != 0) wrapped its scale/deint
builder in `if (!software_decoding) {} else { ... }` with an EMPTY hardware
branch. Consequences:
- GPU + hardware decoding: scale/deint filters were never built at all.
- GPU + software decoding: ran, but the inner `if (!software_decoding)`
  selectors (the `[0:v]...[bg];[bg][1:v]` complex-filter variants) were dead,
  so only the simple software variants were ever emitted.

The CPU path (gpu_device == 0) has no such wrapper and selects hardware vs
software filter variants correctly via the same inner check. Removed the
erroneous wrapper so the GPU path mirrors it: the inner software_decoding
checks are now live and GPU+hardware-decode streams get their deint/scale.

BEHAVIOUR CHANGE for GPU transcoding (hardware decode now emits filters that
were previously dropped) — verify on a GPU hardware-decode stream before prod.
2026-06-23 21:31:54 +03:00
Divarion-D 1495390818 fix(modules): complete listModules() return shape (source/versions)
listModules() returns installed_version/source/previous_version (added to each
entry in the loop) but its @return shape omitted them, so consumers like
ModuleLicensesCronJob — `($m['source'] ?? '') === 'platform'` — were flagged as
always-false and the platform-module filter looked dead. Documented the keys.
2026-06-23 21:27:33 +03:00
Divarion-D 80437c7f2b fix(epg): validate strtotime before offset; phpstan dynamicConstantNames
- EPG::parse: `strtotime(...) + ($rOffset*60)` coerced a false (invalid date)
  to 0 before the `=== false` check, so invalid EPG timestamps were never
  skipped — they silently became epoch+offset. Validate the raw strtotime
  results first, then apply the offset.
- phpstan.dist.neon: declare the 129 runtime constants as dynamicConstantNames.
  PHPStan executes the bootstrap, so define('HOST', (string) mt_rand()) bound a
  literal value and comparisons like `HOST !== 'xc_vm'` read as always-true.
  Marking them dynamic makes PHPStan use the type, not the sampled value.
2026-06-23 21:24:18 +03:00
Divarion-D fa8ed403bc fix(user): undefined $rUser in UserService::massEdit owner guard
$rUser was used but never defined in massEdit() — and has been since the
initial import (the legacy API::massEditUsers had the same undefined var).
At runtime $rUser is null, so `$rUser == $rArray['owner_id']` is `null ==
owner_id`, which (owner_id is always intval) is true only when owner_id === 0.

Replaced with the equivalent, intent-clear `$rArray['owner_id'] == 0`: when a
bulk owner change resolves to 0 (no owner selected), skip changing owner_id.
Behaviour is identical to the prior accidental semantics, minus the bug.
2026-06-23 20:43:07 +03:00
Divarion-D baf0bc46a2 fix(phpstan): real undefined-var bug + exclude view templates 566→498
- StreamsCronJob: $rBitrate/$rCompatible/$rResolution/$rAudioCodec/$rVideoCodec
  were only set inside `if ($rFFProbeOutput)` (and a nested codecs check) but
  consumed by the UPDATE query that runs whenever the .analyse file exists —
  undefined vars (nulls/warnings) when probing fails or returns no codecs.
  Initialise them to null before the conditional.
- phpstan.dist.neon: exclude src/modules/*/views/* from analysis. These are
  templates included into a controller's scope; their variables are injected by
  the caller, so standalone analysis flags every one as undefined (~60 false
  positives). Symbols are still indexed.
2026-06-23 20:34:44 +03:00
Divarion-D e4f301e0b8 fix(phpstan): genuine return-type bugs (wrong value types)
- EnigmaService::getByUserId: returned '' (string) from an array-typed getter
  on the not-found path — return array() instead (type-correct, falsy-safe).
- UserRepository::getParent: walks the permission tree and returns the resolved
  parent *id* (int), not a user row — corrected @return array|null → int.
2026-06-23 20:21:31 +03:00
Divarion-D 6d1e0c76eb fix(phpstan): genuine argument.type bugs 580→568
- DropboxClient::copyRef: apiCall() 2nd arg is $params (array) for every other
  caller, but here passed 'GET' — would set $params='GET' then write
  $params['cursor'] to a string offset. Dropped the bogus arg (endpoint takes
  no params).
- Request::cleanGlobals: chr('0') passed a string to chr(); intent is the NUL
  byte chr(0) (same as the "\x0" strip on the next line).
- PlaylistGenerator: json_decode() on a possibly-null category_id — cast to
  (string) to avoid the PHP 8.1 null deprecation.
- EpgService::getStreamEpg/getStreamsEpg: $rStartDate/$rFinishDate are compared
  against item timestamps and callers pass time(); corrected @param
  string|null → int|null.
- ServerService::changePort: body does intval($rType) and callers pass int
  codes; corrected @param string → int.
2026-06-23 20:15:45 +03:00
Divarion-D 39a768eb41 fix(phpstan): more real bugs (undefined-key access, wrong types) 585→580
- ResellerApiDispatcher: $rResponse['isp'] is only set when the request has an
  'isp' param, but was dereferenced unconditionally — guard with !empty().
- PlaylistGenerator: $rTypeKey is used as an array (foreach/in_array/implode)
  but documented @param string|null — corrected to string[]|null (a string
  value would have crashed the foreach).
- RedisCache::has(): `exists() > 0` is invalid against the phpredis stub union
  (Redis|bool|int); return (bool) cast — same semantics, type-safe.
- DropboxClient: removed unreachable `return null;` after `return $res;`.
2026-06-23 20:07:01 +03:00
Divarion-D 66ecbc8cbc fix(phpstan): fix real bugs (return contracts, arg/byref, stub types) 599→585
- constants stub: use mt_rand()-based exprs so PHPStan infers GENERAL types,
  not literal 0/'' — fixes false division-by-zero (PACKET_SIZE) and
  foreach-over-false (str_split with len 0). Load stub via bootstrapFiles so
  result-cache invalidates on change.
- return contracts: explicit returns where a path fell through to null and
  violated the declared type:
  - StreamRepository::getById/getWatchFolder, GroupService::getById,
    getStream() → return false (declared array|false).
  - ServerRepository::getPublicURL → return '' when server missing (array→string).
  - MagService::resetSTB → return query() result (declared bool).
  - StreamUtils::getPlaylistSegments → explicit return null.
  - NetworkUtils::stopDownload → @return null corrected to @return void.
- PlexController: getPlexToken() called with 5 args but accepts 4 — dropped
  the dead 5th argument.
- DropboxClient::getMetaFromHeaders: array_shift() on an array_filter()
  expression (not a variable, by-ref error) — assign to a var first.
- WatchdogCommand: wrap numeric-string subtractions (nginx/proc-stat values)
  in floatval()/intval().
2026-06-23 20:02:46 +03:00
Divarion-D b9e911e7e8 fix(phpstan): resolve false positives and real bugs (988 → 622)
Systemic fixes (cascade across modules):
- Type `$db` params as \DatabaseHandler in 38 files (was `object`), so
  PHPStan resolves get_row()/query() and stops inferring closed array
  shapes — clears offsetAccess.notFound clusters.
- Database/DatabaseHandler: correct get_row()/clean_row() PHPDoc to
  array<string,mixed>, and query() $buffered param to mixed (it is the
  first positional bind value via func_get_args, not a bool flag).
- constants stub generator: explicit type overrides (HOST/PAGE_NAME →
  string, PHP_ERRORS → bool) to avoid null/mixed false positives.
- phpstan.dist.neon: scanFiles autoload.php/bootstrap.php; ignore
  unactionable FPs (dynamic require paths, proprietary XC_VM ioncube
  class, MaxMind vendor lib, ext-inotify stub gap).

Real bugs fixed:
- streaming/ConnectionLimiter: appended the whole accumulated UUID array
  instead of a single uuid, breaking per-stream temp-file cleanup.
- streaming/TimeshiftClient: dead `|| $x == 3` branch (always redundant).
- streaming/AsyncFileOperations: redundant is_array after === false.
- core/Storage/DropboxClient: @param callback → callable|null.

streaming module is clean (0 errors); infrastructure 39 → 27.
2026-06-23 19:46:33 +03:00
Divarion-D 6b6fa720fd feat(licensing): add module license renewal functionality and UI support 2026-06-23 16:56:05 +03:00
hserver71 265810da58 UCS integration, added rUserID as the 6th parameter of the getStreamingURL function 2026-06-22 15:45:57 +00:00
Divarion-D 9d49ddd7e9 docs(infrastructure): English DocBlocks (39 methods)
ResellerApiDispatcher (API action handlers), ResellerTableRenderer (DataTables
renderers), StreamingRequestBootstrap, player utility functions. Completes the
critical core+domain+infrastructure DocBlock coverage. No behavior change.
2026-06-22 16:18:44 +03:00
Divarion-D b09525096b docs(domain/Device,Bouquet): English DocBlocks (35 methods)
EnigmaService, MagService (device CRUD, sync, reset) and BouquetService
(process/reorder/scan/items/CRUD). Completes domain DocBlock coverage.
No behavior change.
2026-06-22 16:14:25 +03:00