Fail closed on missing playback ACK; log node /play hits for diagnosis.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jos Vooges | STH 2026-08-25 02:47:41 +02:00
parent 2aac72cd71
commit 974b3124d0
2 changed files with 9 additions and 7 deletions

View file

@ -339,9 +339,9 @@ class NodeConnectionManager {
const acked = new Promise<boolean>((resolve) => { const acked = new Promise<boolean>((resolve) => {
const timer = setTimeout(() => { const timer = setTimeout(() => {
// Optimistic: node has 1s grace on /play; prefer play over hard fail. // Fail closed: never hand Stremio a node URL without a confirmed session.
this.pendingSessionAcks.delete(payload.sessionId); this.pendingSessionAcks.delete(payload.sessionId);
resolve(true); resolve(false);
}, timeoutMs); }, timeoutMs);
this.pendingSessionAcks.set(payload.sessionId, { resolve, timer }); this.pendingSessionAcks.set(payload.sessionId, { resolve, timer });
}); });

View file

@ -116,13 +116,15 @@ func (s *Server) handlePlay(w http.ResponseWriter, r *http.Request) {
return return
} }
clientIP := clientIP(r) ip := clientIP(r)
if !s.acquireIP(clientIP) { log.Printf("GET /play request from %s method=%s range=%q", ip, r.Method, r.Header.Get("Range"))
log.Printf("GET /play/[REDACTED] rejected: too many connections from %s", clientIP)
if !s.acquireIP(ip) {
log.Printf("GET /play/[REDACTED] rejected: too many connections from %s", ip)
http.Error(w, "Too Many Requests", http.StatusTooManyRequests) http.Error(w, "Too Many Requests", http.StatusTooManyRequests)
return return
} }
defer s.releaseIP(clientIP) defer s.releaseIP(ip)
tokenHash := hashToken(token) tokenHash := hashToken(token)
sess, err := s.store.GetSessionByTokenHash(tokenHash) sess, err := s.store.GetSessionByTokenHash(tokenHash)
@ -134,7 +136,7 @@ func (s *Server) handlePlay(w http.ResponseWriter, r *http.Request) {
} }
} }
if err != nil { if err != nil {
log.Printf("GET /play/[REDACTED] invalid session from %s", clientIP) log.Printf("GET /play/[REDACTED] invalid session from %s", ip)
http.NotFound(w, r) http.NotFound(w, r)
return return
} }