0fdb2841b72f0cded9879f99faffd6a770832c63
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 7s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 4m17s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 5m22s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Cold adversarial review of PR #292 = MERGEABLE-WITH-NITS (no BLOCKER/HIGH). Addresses: - M1: ApiKeyProvider's never-empty invariant was untested. Add ApiKeyProviderTests covering WriteKey precedence, load-existing, empty-file regenerate, generate+persist, 0600 mode, and still-usable-key-when-persist-fails. ResolveKey extracted to an internal seam taking the key path (InternalsVisibleTo ErsatzTV.Tests). - L2: write-then-chmod race — the key was briefly world-readable. Persist now creates the file 0600 atomically via FileStreamOptions.UnixCreateMode (then re-asserts). - L3: a transient read error on an EXISTING key file silently regenerated + clobbered it (invalidating every client key). ResolveKey now rethrows on an unreadable existing file (fail loud) and only regenerates when the file is absent or empty. L4 (LocalhostOnly XFF-spoof under default trust-all) and N5 (length oracle on a fixed-width key) accepted as documented/cosmetic. Refs #197 #280 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
security(#197): fail-closed API auth, sensitive-read tier, CORS/ForwardedHeaders lockdown (Bundle A)
feat(api): optimistic-concurrency contract for replace-all PUTs — PR1 infra + Block reference (#253)
feat(api): optimistic-concurrency contract for replace-all PUTs — PR1 infra + Block reference (#253)
ErsatzTV
ErsatzTV lets you transform your media library into a personalized, live TV experience - complete with EPG, channel scheduling, and seamless streaming to all your devices. Rediscover your content, your way.
How It Works
- Install ErsatzTV: Download and set up the server on your system.
- Add Your Media: Connect your media libraries and collections.
- Create Channels: Design and schedule your own live channels.
- Stream Anywhere: Watch on any device with IPTV and EPG support.
Key Features
- Custom channels: Create and schedule your own live TV channels.
- IPTV & EPG: Stream with IPTV and Electronic Program Guide support.
- Hardware Transcoding: High-performance streaming with hardware acceleration (NVENC, QSV, VAAPI, AMF, VideoToolbox)
- Media Server Integration: Connect Plex, Jellyfin, Emby and more.
- Music & Subtitles: Mix music videos and enjoy subtitle support.
- Open Source: Free, open, and community-driven project.
Documentation
Documentation is available at ersatztv.org.
License
This project is inspired by pseudotv-plex and the dizquetv fork and is released under the zlib license.
