Skip to content

fix: add backend onboarding and safe switching - #46

Merged
christopherklint97 merged 1 commit into
mainfrom
fix/backend-onboarding
Sep 21, 2026
Merged

christopherklint97 merged 1 commit into
mainfrom
fix/backend-onboarding

Conversation

@christopherklint97

Copy link
Copy Markdown
Owner

Problem

The Apps2Samsung widget for StreamVault was built with a private build-machine backend URL (http://10.1.0.200:3002). Users could enter Xtream credentials, but the widget could not reach a StreamVault backend and only reported Failed to fetch.

Changes

  • stop deriving public widget backend URLs from the builder's LAN address
  • retain explicit VITE_SERVER_URL / VITE_SERVER_IP support for controlled builds
  • add backend-first Settings onboarding for local Tizen widgets
  • support optional STREAMVAULT_AUTH_TOKEN during remote and same-origin onboarding
  • probe candidate backends without forwarding the active backend's token
  • commit backend switches transactionally only after status, config, and program bootstrap succeeds
  • preserve the active backend when a candidate connection fails
  • replace opaque browser network failures with an actionable StreamVault backend error
  • guard backend-scoped requests, polling, recording mutations, and ABA races by generation
  • stop active HTML5, mpegts.js, and Tizen AVPlay playback when changing backends
  • reset backend-scoped views, recordings, favorites, recent items, and watch progress when backend identity changes
  • prevent the PWA service worker from caching bootstrap and authenticated recording endpoints
  • fix early Tizen logging for JSON-encoded runtime backend URLs
  • document the separate StreamVault backend requirement and token workflow

The broken Apps2Samsung package was separately retired in Apps2Samsung/tizen-community-packages#43.

Verification

  • npm audit --omit=dev
  • npm test — 40 files, 212 tests
  • npm run lint
  • npm run typecheck
  • npm run build
  • npm run build:tizen5
  • generated artifact scan — no embedded private backend URL
  • cd server && npm test — 29 files, 172 tests
  • cd server && npm run typecheck
  • cd server && npm run audit:prod
  • docker build -t streamvault:issue37-final .
  • independent final review — no findings

Risk

A successful switch to a different backend URL clears client-side favorites, recent items, and watch progress because channel identifiers are backend-specific. Reconnecting to the same backend preserves them.

Closes #37

@christopherklint97
christopherklint97 merged commit 347988c into main Sep 21, 2026
3 checks passed
@christopherklint97
christopherklint97 deleted the fix/backend-onboarding branch September 21, 2026 12:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cannot add provider

1 participant