docs(skill): correct the ersatztv skill for the fork — it described upstream #549

Merged
timothy merged 1 commits from docs/skill-etv-refresh into main 2026-07-21 20:51:48 +02:00
Owner

fixes #548

The ersatztv skill still described archived upstream v26.3.0, in ways that would actively misdirect a session rather than merely being vague:

  • "ErsatzTV uses MediatR + Blazor (not REST for mutations)" — Blazor was removed in #91 phase (b).
  • "No REST CRUD for channels/collections/schedules — must use SQLite DB directly" — false since /api/v1, which has full write paths. A session trusting this would stop the container and hand-edit SQLite for something an endpoint does safely.
  • The ghcr.io/ersatztv/ersatztv image, and /api/health "returns Blazor HTML".

A skill is loaded by name, so nothing surfaces its staleness — it reads as current.

Adds what this session had to work out by hand while driving the API for #536's prod verification:

  • The api.key file is root-owned 0600 and an unsudo'd read fails silently — empty header → a 401 body that parses as a dict → a naive script reports "0 channels" rather than an auth error. That happened here, and the empty result looked like a real answer.
  • Settings are at /api/v1/settings/ffmpeg / settings/logging, not ffmpeg/settings.
  • Test is port 8410, plus the service-scoped manual refresh for validating before the 03:00 auto-update — scoping matters, a bare up -d recreates everything else in the compose project.
  • Two measurement traps recorded alongside: OCI labels are inherited from the linuxserver base image and lie about what is running (compare .Image to the registry Docker-Content-Digest), and container log brackets are local time while docker logs -t is UTC, so --since mis-slices.

Endpoint lists now defer to docs/endpoint-index.md rather than being re-maintained in the skill — a hand-copied list is precisely what drifted.

Not claimed: the unversioned /api/* list further down is left as-is with a "verify against docs/endpoint-index.md" warning. I did not exercise those endpoints this session, so I won't assert they're correct.

Docs-only, single file, no server-state effect — independent review skipped per the process.independent-review-rubric exemption, stated here rather than left silent.

fixes #548 The `ersatztv` skill still described **archived upstream v26.3.0**, in ways that would actively misdirect a session rather than merely being vague: - *"ErsatzTV uses **MediatR + Blazor** (not REST for mutations)"* — Blazor was removed in #91 phase (b). - *"**No REST CRUD for channels/collections/schedules** — must use SQLite DB directly"* — false since `/api/v1`, which has full write paths. A session trusting this would stop the container and hand-edit SQLite for something an endpoint does safely. - The `ghcr.io/ersatztv/ersatztv` image, and `/api/health` "returns Blazor HTML". A skill is loaded by name, so nothing surfaces its staleness — it reads as current. Adds what this session had to work out by hand while driving the API for #536's prod verification: - **The api.key file is root-owned `0600` and an unsudo'd read fails *silently*** — empty header → a 401 body that parses as a dict → a naive script reports **"0 channels"** rather than an auth error. That happened here, and the empty result looked like a real answer. - Settings are at `/api/v1/settings/ffmpeg` / `settings/logging`, **not** `ffmpeg/settings`. - Test is port 8410, plus the **service-scoped** manual refresh for validating before the 03:00 auto-update — scoping matters, a bare `up -d` recreates everything else in the compose project. - Two measurement traps recorded alongside: OCI labels are inherited from the linuxserver base image and lie about what is running (compare `.Image` to the registry `Docker-Content-Digest`), and container log brackets are local time while `docker logs -t` is UTC, so `--since` mis-slices. Endpoint lists now defer to `docs/endpoint-index.md` rather than being re-maintained in the skill — a hand-copied list is precisely what drifted. **Not claimed:** the unversioned `/api/*` list further down is left as-is with a "verify against `docs/endpoint-index.md`" warning. I did not exercise those endpoints this session, so I won't assert they're correct. Docs-only, single file, no server-state effect — independent review skipped per the `process.independent-review-rubric` exemption, stated here rather than left silent.
timothy added 1 commit 2026-07-21 20:50:15 +02:00
docs(skill): correct the ersatztv skill for the fork — it described upstream
PR Gates / CI image pin matches docker/ci (pull_request) Successful in 11s
PR Gates / Docs update reminder (pull_request) Successful in 13s
PR Gates / decisions lifecycle (pull_request) Successful in 22s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 29s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 30s
Build ErsatzTV Image / Functional E2E (curl contracts) (pull_request) Successful in 24s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 23s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 13s
86fe69d7fb
The skill still described archived upstream v26.3.0: "MediatR + Blazor (not
REST for mutations)", "No REST CRUD for channels/collections/schedules —
must use SQLite DB directly", and the ghcr.io image. All false for this
fork — Blazor was removed in #91b and /api/v1 has full write paths. A
session trusting it would hand-edit SQLite for something the API does.

Also adds what this session had to discover by hand while driving the API:
the key is root-owned so an unsudo'd read fails SILENTLY (empty header ->
401 body that parses as a dict -> a naive script reports "0 channels"
rather than an auth error); settings live at /api/v1/settings/ffmpeg, not
ffmpeg/settings; test is port 8410 and the service-scoped manual refresh
command for validating before the 03:00 auto-update.

Two measurement traps recorded with them: OCI labels are inherited from the
linuxserver base image and lie about what is running (compare .Image to the
registry Docker-Content-Digest), and container log brackets are local time
while `docker logs -t` is UTC, so --since windows mis-slice.

Endpoint lists now defer to docs/endpoint-index.md rather than being
re-maintained here, since a hand-copied list is what drifted in the first
place.
timothy merged commit c05fdd3be1 into main 2026-07-21 20:51:48 +02:00
timothy deleted branch docs/skill-etv-refresh 2026-07-21 20:51:48 +02:00
Sign in to join this conversation.