c55a7fda36b40aece3193fc2da42ed90aefdb317
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 7s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 5m15s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 6m15s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Build ErsatzTV Image / Docs update reminder (push) Has been skipped
Build ErsatzTV Image / Build & test (.NET) (push) Successful in 8m13s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (push) Successful in 9m43s
Build ErsatzTV Image / Build & push image (amd64) (push) Has been cancelled
Posture-independent safe hardening from the #197 cold API security review (the clear-cut fixes that don't depend on the fail-closed/CORS/versioning posture design, which is tracked separately): - ApiKeyAuthorizationFilter: compare X-Api-Key with CryptographicOperations.FixedTimeEquals instead of ordinal string.Equals (removes the response-timing oracle on the write key). [S10] - PlayoutController: clamp pageNum/pageSize on GET /api/playouts and /api/playouts/{id}/items to Math.Clamp(_, 1, 100), matching the documented api-conventions §1 convention every other paged endpoint already follows — these two were passing the raw value straight to EF Take(). [S8] - SecurityHeadersMiddleware: emit X-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin on every response (nosniff backstops the artwork content-type MIME-sniffing risk). CSP/HSTS deferred to the #197 posture design (CSP needs SPA validation; HSTS is proxy/TLS-owned). [S10] Refs #197. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
feat(api): optimistic-concurrency contract for replace-all PUTs — PR1 infra + Block reference (#253)
feat(api): optimistic-concurrency contract for replace-all PUTs — PR1 infra + Block reference (#253)
ErsatzTV
ErsatzTV lets you transform your media library into a personalized, live TV experience - complete with EPG, channel scheduling, and seamless streaming to all your devices. Rediscover your content, your way.
How It Works
- Install ErsatzTV: Download and set up the server on your system.
- Add Your Media: Connect your media libraries and collections.
- Create Channels: Design and schedule your own live channels.
- Stream Anywhere: Watch on any device with IPTV and EPG support.
Key Features
- Custom channels: Create and schedule your own live TV channels.
- IPTV & EPG: Stream with IPTV and Electronic Program Guide support.
- Hardware Transcoding: High-performance streaming with hardware acceleration (NVENC, QSV, VAAPI, AMF, VideoToolbox)
- Media Server Integration: Connect Plex, Jellyfin, Emby and more.
- Music & Subtitles: Mix music videos and enjoy subtitle support.
- Open Source: Free, open, and community-driven project.
Documentation
Documentation is available at ersatztv.org.
License
This project is inspired by pseudotv-plex and the dizquetv fork and is released under the zlib license.
