Files
XC_VM/lb_configs
obscuremindandClaude Opus 5 3eabc7a6f9 fix(auth): catch-up routing, proxy-only check and adaptive variants
- Timeshift through a proxy read $rChannelInfo, which the timeshift path
  never sets, so catch-up always bypassed the archive server's proxy (and
  an archive server that requires one refused it). It now uses the
  archive server's proxies, like live.
- The cached pre-check compared the type to 'archive', which requests
  never carry, so catch-up fell into the live check and a channel whose
  live stream was down refused its own catch-up. The same block used
  variables that are not set yet (and SERVER_ID, not yet defined there).
- The proxy-only rule trusted the client-set X-IP header; any client could
  name a public proxy IP and pass. nginx now passes the TCP peer
  ($realip_remote_addr) as XC_PEER_ADDR and auth checks that; the header
  counts only from an XC_VM server/whitelisted peer, or on an nginx config
  too old to pass the peer.
- Adaptive masters skip a variant with no server (or no proxy) instead of
  building URLs from a failed redirect.
- Connection uuids come from random_bytes() rather than md5(uniqid()).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 16:19:50 +01:00
..
2025-07-10 20:01:56 +03:00