SergeantPanda
7083c512be
security: Fixed path traversal vulnerability in file uploads. The M3U account upload (apps/m3u/api_views.py), logo upload (apps/channels/api_views.py), and backup upload (apps/backups/api_views.py) all used the uploaded filename directly without sanitization. os.path.join() discards all preceding components when it encounters an absolute path segment, and pathlib's / operator behaves identically; a relative ../ sequence also escapes via OS path resolution at open() time. All three upload paths now strip directory components via Path(name).name and validate the resolved path remains within the intended upload directory. Exploiting any of these required admin credentials.
2026-04-09 21:32:36 -05:00
SergeantPanda
1d4603dadd
Enhancement: Optimize profile expiration handling and update task naming for clarity
2026-03-15 12:42:34 -05:00
Nicholas Gerrer
858c81f826
perf: use bulk_create with update_conflicts for group settings save
...
Replace N+1 update_or_create() loop with bulk_create(update_conflicts=True)
wrapped in transaction.atomic(). On large M3U accounts with many groups,
the previous approach issued individual DB queries per group/category,
which could take minutes on slower hardware like Synology NAS devices.
2026-02-26 01:21:26 -05:00
SergeantPanda
890992a9f9
feat(scheduling): add cron builder and refactor scheduling components ( Closes #165 )
...
Add cron expression support for M3U and EPG refreshes with interactive
builder modal and quick reference examples. Refactor backup scheduling
to use shared ScheduleInput component for consistency.
- New CronBuilder modal with preset buttons and custom field editors
- Info popover with common cron expression examples
- Shared ScheduleInput component for interval/cron toggle
2026-02-12 18:08:13 -06:00
SergeantPanda
5364123745
- Swagger/OpenAPI Migration: Migrated from drf-yasg (OpenAPI 2.0) to drf-spectacular (OpenAPI 3.0) for API documentation. This provides:
...
- Native Bearer token authentication support in Swagger UI - users can now enter just the JWT token and the "Bearer " prefix is automatically added
- Modern OpenAPI 3.0 specification compliance
- Better auto-generation of request/response schemas
- Improved documentation accuracy with serializer introspection
2026-01-27 13:33:33 -06:00
SergeantPanda
2b58d7d46e
Enhancement: Ensure "Uncategorized" categories and relations exist for VOD accounts. This improves content management for movies and series without assigned categories. Closes #627
2025-11-25 17:14:51 -06:00
SergeantPanda
da245c409a
Bug fix: Backend now notifies frontend when a new playlist is creating. This should fix where accounts will sometimes only show fetching groups after a new account is added.
2025-10-07 09:55:35 -05:00
SergeantPanda
84c752761a
Ability to refresh account info from account info modal and provide notification on results.
2025-09-09 18:15:33 -05:00
SergeantPanda
6f6c28ca7c
Convert custom_properties to jsonb in the backend.
2025-09-02 09:41:51 -05:00
dekzter
11bc2e57a9
optimized vod parsing, added in vod category filtering, added UI individual tabs for movies vs series VOD category filters
2025-08-25 14:37:20 -04:00
dekzter
a19bd14a84
added vod category filtering
2025-08-22 16:59:00 -04:00
SergeantPanda
2903773c86
Merge branch 'dev' of https://github.com/Dispatcharr/Dispatcharr into vod-relationtest
2025-08-19 12:39:21 -05:00
SergeantPanda
bcebcadfaa
Add ability to scan for vods during m3u refresh.
2025-08-02 12:01:26 -05:00
dekzter
ead76fe661
first run at m3u filtering
2025-08-01 15:02:43 -04:00
SergeantPanda
a5f7a88ba0
Add option to force dummy epg.
2025-07-17 16:54:37 -05:00
SergeantPanda
ea81cfb1af
Add auto channel sync settings to ChannelGroupM3UAccount and update related components
...
- Introduced `auto_channel_sync` and `auto_sync_channel_start` fields in the ChannelGroupM3UAccount model.
- Added API endpoint to update M3U group settings.
- Updated M3UGroupFilter component to manage auto sync settings.
- Enhanced M3URefreshNotification and M3U components for better user guidance.
- Created a Celery task for automatic channel synchronization after M3U refresh.
2025-07-13 15:59:25 -05:00
dekzter
3f445607e0
looooots of updates for user-management, initial commit of access control
2025-05-31 18:01:46 -04:00
dekzter
e979113935
merged in dev
2025-05-21 15:24:30 -04:00
SergeantPanda
1087568de7
Fix bug when using file upload for m3u and not being able to set "Use Default"
2025-05-21 14:22:01 -05:00
dekzter
74d58515d0
user management, user levels, user level channel access
2025-05-18 11:19:34 -04:00
SergeantPanda
e63a66bf57
Change status to disabled when epg or m3u disabled. Change to idle when enabled.
2025-05-07 13:50:10 -05:00
SergeantPanda
b713b516b4
Convert m3u accounts to a similar format to epg for status updates. Renamed DB field last_error to last_message so we can use it for more messaging. Migration to change updated_at field to not be updated everytime the m3u changes. It should only update the updated_at when we successfully update the m3u.
2025-05-04 17:51:57 -05:00
dekzter
091d9a6823
immediately prompt for group filtering when using an XC account
2025-05-01 11:22:38 -04:00
dekzter
839abd281c
m3u file upload fixed, hdhr support profiles now, i don't remember what I did to the UI anymore
2025-04-07 20:49:42 -04:00
dekzter
354cd84c88
filesystem watch and process of m3u and epg
2025-04-06 15:58:55 -04:00
dekzter
319481f7d1
fixed m3u accounts not saving
2025-04-03 13:00:14 -04:00
dekzter
d6e05445f3
m3u group filters
2025-03-22 09:56:00 -04:00
kappa118
57432748a4
added m3u profile support
2025-02-28 14:08:05 -05:00
kappa118
04080a5f2b
attempting to get profiles to work properly
2025-02-28 09:47:40 -05:00
kappa118
53836fdac3
first run at m3u profiles
2025-02-27 22:05:41 -05:00
Dispatcharr
1fb7a0c9eb
Alpha v3
...
Added user agents
Added Stream Profiles
Added new API calls
2025-02-21 15:31:59 -06:00
Dispatcharr
8edb743ebd
Initial commit
2025-02-18 11:14:09 -06:00