Closed
opened 2026-07-12 00:36:51 +02:00 by timothy
·
3 comments
No Branch/Tag Specified
main
renovate/meziantou.analyzer-3.x
release/v26.15.0-notes
fix/830-add-items-error-surface
renovate/lucene.net
renovate/cliwrap-3.x
issue-806-guard-populations
renovate/dotnet-monorepo
scratch/767b-poisoned
scratch/767b-control
release/v26.14.0-notes
release/v26.14.0
renovate/sqlitepclraw.bundle_e_sqlite3-3.x
docs/510-skill-logo-bug-policy
fix/510-watermark-resolution-policy
fix/629-verdict-classifier-falseopens
fix/609-decisions-edit-token-scope
issue-135-clear-to-none
release/v26.12.0-notes
fix/409b-lastscan-api-parity
fix/401-updatechannel-mirror-422
fix/327-playlist-rename-validation
fix/410-scancancel-log-level
fix/409-447-librariesscreen-neverscanned
fix/338-zap-exit-code
fix/367-plex-budget-message
fix/310-debom-legacy-cs
ci/604-lane-rebalance
feat/388-design-mirror
feat/247-test-ownership
feat/247-primary-action
feat/357-player-owned-playback
feat/357-jellyfin-plugin-poc
fix/289-mcp-hardening
issue58-mcp
feat/244-channels-extract
ci/auto-bump-prod-compose
feat/multi-rerun-collections-api
feat/collections-api
feat/quick-wins
feat/185-docs-part2
feat/140-collections-screen
feat/146-channel-edit
feat/147-classic-ui-link
issue22-renovate-dashboard
feat/91-cutover
feat/63-composite-create
feat/65-library-browse
feat/85-epg
feat/86-schedule-editor
feat/109-dashboard-data
feat/99-session-tracking
fix/dockerfile-node-tag
feat/59-spa-foundation
docs/59-ui-redesign-brief
feat/102-json-guide
feat/111-schedule-durations
feat/104-artwork-upload
feat/103-media-sources-api
feat/playouts-read-api
feat/108-health-api
feat/105-picker-list-endpoints
issue-97-channel-state-api
issue42-jellyfin-musicvideos
issue46-rest-api-error-contract
dependabot/nuget/ErsatzTV.FFmpeg.Tests/multi-d307a2e06f
qsv-improvements
hdr-vulkan-cuda-test
v26.15.0
v26.14.0
v26.13.0
v26.12.0
v26.11.0
v26.10.0
v26.9.0
v26.8.0
v26.7.0
blazor-final
v26.6.0
v26.5.0
v26.4.0
v26.3.1
v26.3.0
v26.2.0
v26.1.1
v26.1.0
v25.9.0
v25.8.0
v25.7.1
v25.7.0
v25.6.0
v25.5.0
v25.4.0
v25.3.1
v25.3.0
v25.2.0
v25.1.0
v0.8.8-beta
v0.8.7-beta
v0.8.6-beta
v0.8.5-beta
v0.8.4-beta
v0.8.3-beta
v0.8.2-beta
v0.8.1-beta
v0.8.0-beta
v0.7.9-beta
v0.7.8-beta
v0.7.7-beta
v0.7.6-beta
v0.7.5-beta
v0.7.4-beta
v0.7.3-beta
v0.7.2-beta
v0.7.1-beta
v0.7.0-beta
v0.6.9-beta
v0.6.8-beta
v0.6.7-beta
v0.6.6-beta
v0.6.5-beta
v0.6.4-beta
v0.6.3-beta
v0.6.2-beta
v0.6.1-beta
v0.6.0-beta
v0.5.8-beta
v0.5.7-beta
v0.5.6-beta
v0.5.5-beta
v0.5.4-beta
v0.5.3-beta
v0.5.2-beta
v0.5.1-beta
v0.5.0-beta
v0.4.5-alpha
v0.4.4-alpha
v0.4.3-alpha
v0.4.2-alpha
v0.4.1-alpha
v0.4.0-alpha
v0.3.8-alpha
v0.3.7-alpha
develop
v0.3.6-alpha
v0.3.5-alpha
v0.3.4-alpha
v0.3.3-alpha
v0.3.2-alpha
v0.3.1-alpha
v0.3.0-alpha
v0.2.5-alpha
v0.2.4-alpha
v0.2.3-alpha
v0.2.2-alpha
v0.2.1-alpha
v0.2.0-alpha
v0.1.5-alpha
v0.1.4-alpha
v0.1.3-alpha
v0.1.2-alpha
v0.1.1-alpha
v0.1.0-alpha
v0.0.62-alpha
v0.0.61-alpha
v0.0.60-alpha
v0.0.59-alpha
v0.0.58-alpha
v0.0.57-alpha
v0.0.56-alpha
v0.0.55-alpha
v0.0.54-alpha
v0.0.53-alpha
v0.0.52-alpha
v0.0.51-alpha
v0.0.50-alpha
v0.0.49-prealpha
v0.0.48-prealpha
v0.0.47-prealpha
v0.0.46-prealpha
v0.0.45-prealpha
v0.0.44-prealpha
v0.0.43-prealpha
v0.0.42-prealpha
v0.0.41-prealpha
v0.0.40-prealpha
v0.0.39-prealpha
v0.0.38-prealpha
v0.0.37-prealpha
v0.0.36-prealpha
v0.0.35-prealpha
v0.0.34-prealpha
v0.0.33-prealpha
v0.0.32-prealpha
v0.0.31-prealpha
v0.0.30-prealpha
v0.0.29-prealpha
v0.0.28-prealpha
v0.0.27-prealpha
v0.0.26-prealpha
v0.0.25-prealpha
v0.0.24-prealpha
v0.0.23-prealpha
v0.0.22-prealpha
v0.0.21-prealpha
v0.0.20-prealpha
v0.0.19-prealpha
v0.0.18-prealpha
v0.0.17-prealpha
v0.0.16-prealpha
v0.0.15-prealpha
v0.0.14-prealpha
v0.0.13-prealpha
v0.0.12-prealpha
v0.0.11-prealpha
v0.0.10-prealpha
v0.0.9-prealpha
v0.0.8-prealpha
v0.0.7-prealpha
v0.0.6-prealpha
v0.0.5-prealpha
v0.0.4-prealpha
v0.0.3-prealpha
v0.0.2-prealpha
v0.0.1-prealpha
Labels
Clear labels
ad-hoc
api
bug
ci-cd
content
dependencies
enhancement
frontend
in-progress
jellyfin
parked
priority: high
priority: low
priority: medium
review
security
One-off / ad-hoc work not tracked by a dedicated issue
REST API / HTTP endpoints
Something isn't working
Build, test, deploy pipeline
Channel content / schedules / playlists
Dependency updates (Renovate)
New feature or improvement
ChicoryTV React SPA frontend
Claimed by an active session — do not pick up
Jellyfin tuner / IPTV integration
Excluded from automatic queue pickup; work only when explicitly selected
Adversarial review finding
Security / vulnerability fix
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: timothy/ersatztv#293
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Deferred from #285 (Bundle A, PR #292).
GET /api/search/all-items(SearchController,QuerySearchIndexAllItems) returns every matching item id with no paging. #285 called for paging/capping it. It was deferred from Bundle A because it feeds the SPA "add all to collection/playlist" flow (web/src/media/addTo/), which materializes the full id set before calling the add endpoints — a naive hard cap would silently truncate "add all".Why not urgent: the original S10 concern was unauthenticated unbounded exposure; that is now closed — the endpoint is gated by read-gating (
Api:RequireKeyForReadsdefault true, #282). The residual is DoS-hardening against an authenticated caller with a very broad query.Fix options: (a) coordinated pagination — page the endpoint AND teach the SPA add-all flow to iterate pages; or (b) a generous safety cap (e.g. configurable
Search:AllItemsMaxResults) with a documented truncation signal the SPA surfaces. Prefer (a).Triage: backlog (Phase-3 / #197 follow-up). Not a gate.
Resolved via option (a) (operator-confirmed) in PR #442.
Done-when
🔗 Session bundle — security hardening: #293, #376. Both are endpoint-hardening; work together. (Backlog-grooming 2026-07-17.)
Claiming (Claude Code / Opus 4.8 orchestrator session).
Selection trace — arc frontier empty (all six arc items closed); tier-2 (open milestones) exhausted for pickup: #383 is the Auto-Tune DetailPanel epic container (children #384/#385/#386 all closed), #425 + #176 are
in-progress(live parallel sessions), #395 is gated on open #381 (goldens). Tier-3 review pool empty: noreview-labeled issue open, and all fiveersatztvreviewer audits (adversarial-reviewer #20–#24) have posted deliverables. Nopriority: highissues exist. Fell through topriority: medium, lowest eligible number → #293. Verified directly:state open, deps[](unblocked), notin-progress; bundle sibling #376 already closed so this is now standalone (no collision with #425/#176).Plan (design-first, per repo rules): recon
SearchController.QuerySearchIndexAllItems+ the SPA add-all flow (web/src/media/addTo/) to pin the exact contract, decide between the issue's option (a) coordinated pagination vs (b) generous safety cap with a truncation signal, record the decision indocs/decisions.md, then implement backend + SPA + tests + live-E2E + OpenAPI regen + docs. No code until the design decision is recorded.Closed by PR #442 (merged to
main).What was done — paginated
GET /api/v1/search/all-items(was ten index searches atlimit: 0= every hit, so a broad authenticated query materialized the whole index into one response). Design option (a) full pagination (operator-confirmed): optionalpageNum/pageSize(clampedpageSize1–1000,pageNum0–2_000_000), an additive per-kindTotalson the response, and the SPA add-all flow (getAllSearchItemIds) pages to completeness instead of a single unbounded fetch.Root cause (why it existed): the endpoint was built for the SPA's "add all" convenience and passed
limit: 0toISearchIndex.Searchto fetch every id in one shot — fine when read-gating blocked anonymous callers, but it left unbounded per-request work for an authenticated broad query once #282 closed the anon hole. Fix threads a realskip/limit(native Lucene support) and returns per-kindTotalCountso the client can page.Files changed:
SearchController.SearchAllItems,QuerySearchIndexAllItems(Handler),SearchResultAllItemsViewModel,SearchResultAllItemsResponseModel+ newSearchResultAllItemsTotalsResponseModel;web/src/api/search.ts(+SearchScreen.addAll); controller/handler/SPA tests;docs/decisions.md,docs/api-conventions.md§5; regenerated OpenAPI trio.Deferred / follow-up: the add POST still accepts the full merged id set in one body — bounding that surface is out of scope here and tracked under the add-path idempotency work (#308). No new issues filed.
Docs updated:
decisions.md(2026-07-18 #293) +api-conventions.md§5.Review: two cold-context adversarial passes → MERGEABLE; both LOW findings (pageNum overflow, missing-totals under-fetch) fixed in-diff. CI green on the merged head.