diff --git a/.gitignore b/.gitignore index 6729808..ad9b67d 100644 --- a/.gitignore +++ b/.gitignore @@ -3,6 +3,8 @@ dist/ .next/ .env .env.local +.env.* +!.env.example *.log .DS_Store coverage/ @@ -17,3 +19,56 @@ apps/master-api/dist/ packages/*/dist/ apps/android-tv/apk-patch/ + +# Secrets / credentials / session material — never push +**/_fresh_creds.json +**/*_creds.json +**/cookies*.txt +**/*cookies*.txt +**/*.wvd +**/*.pem +**/*.p12 +**/*.pfx +**/credentials.json +**/service-account*.json +**/.env.secrets +**/secrets.local.* + +# Browser captures & local probe dumps +**/*.har +**/_viaplay_probe_out/ +**/_probe_out/ +**/_recovered/ +apps/ios/scripts/_probe_*.cjs +apps/ios/scripts/_parse_*.cjs +apps/ios/scripts/_parse_*.mjs +apps/ios/scripts/_dump_*.mjs +apps/ios/scripts/_rebuild_*.mjs +apps/ios/scripts/_recover*.mjs +apps/ios/scripts/_replay_*.mjs +apps/ios/scripts/_finalize_*.mjs +apps/ios/scripts/_find_*.mjs +apps/ios/scripts/VMC-TestFlight-*.command +apps/ios/scripts/probe_*.py +apps/ios/scripts/debug_*.py +apps/ios/scripts/diag_*.py +apps/ios/scripts/verify_*.py +apps/ios/scripts/verify_*.swift +apps/ios/scripts/verify-*.sh +apps/ios/scripts/live_*.py +apps/ios/scripts/analyze_*.py +apps/ios/scripts/dump_*.py +apps/ios/scripts/inspect_*.py +apps/ios/scripts/fetch_*.py +apps/ios/scripts/fetch-*.sh +apps/ios/scripts/run-*.sh +apps/ios/scripts/smoke_*.swift +apps/ios/scripts/vmc-tf-*.sh +apps/ios/scripts/hbo-*.mpd +apps/ios/scripts/*_sample.json +apps/master-api/odyssey-test.txt + +# Local build / crash dumps +apps/android-tv/assemble-*.txt +apps/android-tv/*.hprof +**/*.hprof diff --git a/apps/admin-ui/src/app/drm/page.tsx b/apps/admin-ui/src/app/drm/page.tsx index 97cb817..bed79ce 100644 --- a/apps/admin-ui/src/app/drm/page.tsx +++ b/apps/admin-ui/src/app/drm/page.tsx @@ -168,10 +168,10 @@ export default function DrmPage() {

Beveiliging

-

DRM keys

+

Stream-licenties

- Alle ooit opgehaalde ClearKey/Widevine-keys. Zoek op KID, KEY, MPD, zender of - event. Altijd eerst cache — alleen ophalen bij miss. + Opgeslagen stream-licenties per provider. Zoek op KID, manifest-URL, zender of + event. Cache-first — alleen vernieuwen bij miss.

diff --git a/apps/admin-ui/src/app/scripts/F1tvPanel.tsx b/apps/admin-ui/src/app/scripts/F1tvPanel.tsx index 8604124..c830573 100644 --- a/apps/admin-ui/src/app/scripts/F1tvPanel.tsx +++ b/apps/admin-ui/src/app/scripts/F1tvPanel.tsx @@ -306,8 +306,9 @@ export function F1tvPanel({ onChanged }: { onChanged?: (o: F1tvOverview) => void

F1TV

Events + F1-hub. Imperva blokkeert server-login: plak{" "} - ascendontoken + entitlementtoken uit DevTools (na browser-login). - Meerdere accounts: sessies worden als unie samengevoegd; play round-robint over owners. + ascendontoken + entitlementtoken uit een ingelogde + browsersessie. Meerdere accounts: sessies worden als unie samengevoegd; play + round-robint over owners.

diff --git a/apps/admin-ui/src/app/scripts/ViaplayPanel.tsx b/apps/admin-ui/src/app/scripts/ViaplayPanel.tsx index 56d560d..fca0fc2 100644 --- a/apps/admin-ui/src/app/scripts/ViaplayPanel.tsx +++ b/apps/admin-ui/src/app/scripts/ViaplayPanel.tsx @@ -237,9 +237,7 @@ export function ViaplayPanel({ onChanged }: { onChanged?: (o: ViaplayOverview) = }); const d = await r.json(); if (!r.ok) throw new Error(d.error?.message ?? "Sync mislukt"); - setMsg( - `Viaplay EPG: ${d.events ?? 0} events · ${d.daysOk ?? 0}/${d.daysTried ?? 0} dagen (${d.durationMs ?? "?"} ms)` - ); + setMsg(`Viaplay-agenda: ${d.events ?? 0} events · ${d.daysOk ?? 0}/${d.daysTried ?? 0} dagen (${d.durationMs ?? "?"} ms)`); await load(); } catch (e) { setErr(String((e as Error).message ?? e)); @@ -330,34 +328,34 @@ export function ViaplayPanel({ onChanged }: { onChanged?: (o: ViaplayOverview) =

Viaplay

- Sport-EPG (publiek) + live play/keys. Plak session +{" "} - accessToken (+ viaplay_profileId) uit DevTools na browser-login. - Cache-first: MPD/keys ±5 min vóór start, gestaggerd. Tray-tool volgt later. + Sportagenda en live streams voor gekoppelde Viaplay-accounts. Voeg een account toe met + sessie-token, access token en optioneel profile-id (uit een ingelogde browsersessie). + Manifests en licenties worden cache-first opgehaald (±5 min vóór start, gestaggerd).

Accounts

{accounts.length === 0 ? ( -

Nog geen accounts — voeg e-mail + cookies toe.

+

Nog geen accounts — voeg e-mail + sessie-tokens toe.

) : (
    {accounts.map((a) => ( @@ -379,7 +377,7 @@ export function ViaplayPanel({ onChanged }: { onChanged?: (o: ViaplayOverview) = {a.email} {" · "} - {a.hasSession && a.hasAccessToken ? "cookies ok" : "cookies missen"} + {a.hasSession && a.hasAccessToken ? "tokens ok" : "tokens missen"} {a.subscriptionSummary ? ` · ${a.subscriptionSummary}` : ""} {a.eventCount ? ` · ${a.eventCount} events` : ""} @@ -436,7 +434,7 @@ export function ViaplayPanel({ onChanged }: { onChanged?: (o: ViaplayOverview) = style={{ marginTop: 10 }} onClick={() => setShowCookies((v) => !v)} > - {showCookies ? "Cookies verbergen" : "Cookies plakken (vereist)"} + {showCookies ? "Tokens verbergen" : "Sessie-tokens plakken (vereist)"} {showCookies && ( @@ -448,7 +446,7 @@ export function ViaplayPanel({ onChanged }: { onChanged?: (o: ViaplayOverview) = onChange={(e) => setNewSession(e.target.value)} rows={2} disabled={busy} - placeholder="session-cookie waarde" + placeholder="session-waarde uit ingelogde browsersessie" style={{ fontFamily: "monospace", fontSize: "0.8rem" }} /> @@ -459,17 +457,17 @@ export function ViaplayPanel({ onChanged }: { onChanged?: (o: ViaplayOverview) = onChange={(e) => setNewAccessToken(e.target.value)} rows={2} disabled={busy} - placeholder="eyJ…" + placeholder="access token" style={{ fontFamily: "monospace", fontSize: "0.8rem" }} />
@@ -602,12 +600,12 @@ export function ViaplayPanel({ onChanged }: { onChanged?: (o: ViaplayOverview) = ) ) : ( - nog niet compleet (account + cookies) + nog niet compleet (account + sessie-tokens) )} {settings?.lastSyncAt && ( <>
- Laatste EPG-sync: {new Date(settings.lastSyncAt).toLocaleString("nl-NL")} + Laatste agenda-sync: {new Date(settings.lastSyncAt).toLocaleString("nl-NL")} {summary && ( <> {" "} diff --git a/apps/admin-ui/src/components/Nav.tsx b/apps/admin-ui/src/components/Nav.tsx index c5fa4fd..30ad2a9 100644 --- a/apps/admin-ui/src/components/Nav.tsx +++ b/apps/admin-ui/src/components/Nav.tsx @@ -14,7 +14,7 @@ const desktopLinks = [ { href: "/downloads", label: "Downloads" }, { href: "/streams", label: "Streams" }, { href: "/live-lists", label: "Live-lijsten" }, - { href: "/drm", label: "DRM" }, + { href: "/drm", label: "Licenties" }, { href: "/scripts", label: "Scripts" }, { href: "/viewers", label: "Gebruikers" }, { href: "/settings", label: "Instellingen" }, diff --git a/apps/ios/README.md b/apps/ios/README.md index 0d6e300..98241e0 100644 --- a/apps/ios/README.md +++ b/apps/ios/README.md @@ -26,7 +26,7 @@ In Xcode: - Systeem-PiP via VLCKit (`VLCPictureInPictureDrawable`) - PiP-knop in de speler + automatisch bij app naar achtergrond tijdens afspelen -- ClearKey/DASH blijft via lokale `ClearKeyDashProxy` → plain DASH in VLC +- Encrypted DASH via lokale stream-proxy → VLC --- diff --git a/apps/master-api/scripts/viaplay_cdm.py b/apps/master-api/scripts/viaplay_cdm.py index 10e83b9..01bfd3e 100644 --- a/apps/master-api/scripts/viaplay_cdm.py +++ b/apps/master-api/scripts/viaplay_cdm.py @@ -1,5 +1,5 @@ #!/usr/bin/env python3 -"""Viaplay Widevine helper (theplatform ModularDrm). Requires: pip install pywidevine requests""" +"""Viaplay license helper for ModularDrm. Requires: pip install pywidevine requests""" import json import sys diff --git a/apps/master-api/src/viaplay/settings.ts b/apps/master-api/src/viaplay/settings.ts index 2149463..b579a09 100644 --- a/apps/master-api/src/viaplay/settings.ts +++ b/apps/master-api/src/viaplay/settings.ts @@ -334,7 +334,7 @@ export async function probeViaplayAccounts(sessionSecret: string, accountId?: st if (!creds.session || !creds.accessToken) { account.healthStatus = "dead"; account.healthCheckedAt = now; - account.healthError = "Geen session/accessToken — plak cookies uit de browser"; + account.healthError = "Geen sessie/access-token — voeg tokens toe uit een ingelogde browsersessie"; continue; } if (!account.deviceId) account.deviceId = creds.deviceId; @@ -390,7 +390,7 @@ export async function loadViaplaySettings(sessionSecret: string): Promise