Skip to content

2.3 Recordings Library, Security Hardening

Choose a tag to compare

@co-te co-te released this 06 Sep 21:01
· 1 commit to main since this release
f67cb7e

What's New

Web UI

  • Full UI redesign — new look, faster, lighter (single HTML file, no external requests, no build step)
  • New Recordings library view: browse, preview, download, favorite, archive, and delete finished recordings
  • Real-time log viewer now works during and after recordings (fixed empty logs caused by yt-dlp silencing)
  • Fixed avatar initials rendering on top of channel avatars
  • Added GitHub Issues link in Settings → System for bug reports
  • Dark/light theme, mobile layout improvements, guest account prompt shows only once

Security

  • Optional password protection: once an account is created, the entire API requires login (PBKDF2-hashed, session cookies, same-origin CSRF protection)
  • Account management endpoints no longer reachable without authentication
  • SSRF guards on channel URLs, webhook URLs, and DNS resolution (non-blocking)
  • Blocked dangerous yt-dlp flags in user-supplied extra args (--exec, --postprocessor-args, downloader overrides, etc.)
  • Channel credentials are never exported in config backups

Reliability

  • No more duplicate/zombie recordings — startup sweep kills recorder processes left behind by a crashed or hard-stopped instance
  • Stop/kill/delete operations now wait for the process tree to fully die before releasing the recording slot
  • Graceful shutdown drains active recordings before writing final state
  • Fixed a race where force-killing a recording could let the monitor start a second one on the same channel
  • DST-safe recording filenames (UTC timestamps prevent overwrite collisions)

Fixes & Improvements

  • Live recording logs fixed — yt-dlp's --print flag was silencing all output; ffmpeg progress is now visible
  • --fixup scoped to output format (force only for MP4, warn for MKV/TS)
  • Malformed HTTP Range headers no longer crash preview; tail ranges (bytes=-N) handled correctly
  • Login rate limiting no longer blocks the event loop; returns 429 with Retry-After
  • Blocking DNS lookups moved off the event loop
  • record_on_add setting is now functional (global auto-record master switch)
  • Cookies manager UI works end-to-end (upload, list, delete, assign globally)
  • Bumped python-multipart to 0.0.18 (security advisory)

Docker

  • WireProxy VPN sidecar is now optional — start with docker compose --profile vpn up -d (no wg0.conf required for normal use)