* Rebrand MMTL to MeBox across codebase and assets
Rename the project display name, Go module path, environment variable
prefix (MEBOX_*), Docker image references, and UI branding from MMTL/mmtl
to MeBox/mebox. Replace logo assets with the new MeBox icon and keep
legacy SQLite migration support for existing mmtl.db deployments.
Co-authored-by: truewhile <truewhile@users.noreply.github.com>
* Fix logo icons: use cube-only crop without truncated text
Previous icon generation cropped too much of the source image, including
partial MeBox wordmark text that was cut off in square icon containers.
Regenerate logo-64/192/512, favicon, and SVG from cube-only region.
Co-authored-by: truewhile <truewhile@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: truewhile <truewhile@users.noreply.github.com>
- Add BootCloudLibraries() to auto-scan all cloud libraries on startup
- Delay 3s to avoid conflict with system init, scan without auto-scrape
- Enable CORS for /api/cloud/play/* and /api/img to support 3rd-party players
- Fixes issue where each user triggers separate cloud library scans
- Fixes issue where Infuse/Emby apps cannot play cloud resources
Three regressions reported on third-party clients and the web UI:
- Third-party clients (Emby/Jellyfin) dropped login / could not play /
could not refresh the library, roughly hourly. The Emby
AuthenticateByName response returned the 60-minute access token, but
Emby clients have no refresh mechanism and reuse the AccessToken until
logout. Issue a long-lived (30d) token for the Emby compat layer via
AuthService.IssueEmbyToken so device sessions persist.
- Web could be thrown back to login under load: /auth/refresh was inside
the IP rate-limited /auth group, so multiple users/tabs behind one
reverse-proxy/NAT IP exhausted the budget and refresh failed -> logout.
Only login/register are rate-limited now (raised to 30/min for shared
IPs); refresh is excluded (already protected by a one-time refresh token).
- Posters/images stopped displaying on the web home and other pages
(refresh did not help). The SSRF/path hardening (a) blocked the image
proxy whenever a hostname *resolved* to a private IP, which happens
under GFW DNS poisoning of public CDNs like image.tmdb.org, and (b)
restricted local image reads to data/cache/movies/tv/anime dirs only,
dropping sidecar posters stored under arbitrary per-library roots to a
placeholder. isPrivateHost now only blocks literal private/loopback IPs
(real SSRF vectors) and ImageProxy also allows reads under configured
library roots.
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- Add isPrivateHost() to block image proxy requests to loopback/private/
link-local IPs (SSRF mitigation)
- Add isAllowedLocalPath() to restrict local file reads to configured
data/cache/media directories only
- CORS middleware now takes debug flag; wildcard only when debug=true,
production omits headers (same-origin enforced)
- Add per-IP sliding-window rate limiter (10 req/min) on login/register
and Emby AuthenticateByName endpoints
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Backend
- service/ffprobe.go: thin ffprobe wrapper, parses duration / resolution /
codecs into a typed ProbeResult. 30s per-file timeout.
- service/tmdb.go: minimal TMDb provider (search/movie). Disabled when no
api key; supports tmdb_api_proxy / tmdb_image_proxy overrides for users
behind a firewall.
- service/scraper.go: filename cleaner (handles bracketed tags, scene
noise tokens, year extraction), per-row + per-library enrichment with a
4 RPS throttle and WS hub progress events. Unit-tested.
- service/scanner.go: now invokes ffprobe per file and kicks the TMDb
scraper in the background once a library scan finishes.
- service/transcoder.go: per-media ffmpeg HLS job manager; outputs
index.m3u8 + seg_NNNNN.ts under cache/hls/<id>; cancels jobs on
shutdown; publishes 'transcode' WS events.
- service/stream.go: serves HLS playlist (with 30s wait-for-ready) and
.ts segments with path-traversal protection. Adds Probe() helper used
by the admin 'reprobe' button.
- service/image_proxy.go: cached, host-allow-listed reverse proxy for
TMDb / Bangumi / Douban / Fanart / TheTVDB images so the SPA never
hits a CORS or GFW issue.
- service/playback.go: history upsert, favourites toggle, playlist CRUD
+ ordered items. RecentHistory joins with model.Media in one extra
query so the home page can render a 'Continue Watching' row.
- handler/streaming.go + handler/playback.go: REST endpoints for HLS,
image proxy, scrape (one + library), reprobe, history, favourites,
playlists.
- handler/handler.go: registers /api/hls/:id/{index.m3u8,:seg}, /api/img,
/api/history, /api/favourites/:id, /api/playlists/* with proper
auth/admin guards.
Frontend
- api/client.ts: imageURL() helper; hlsURL() endpoint; reuses the JWT in
a query parameter for <video src> and <img src>.
- api/playback.ts: typed helpers for history, favourites, playlists.
- components/MediaCard.tsx: optional 'progress' prop renders a thin
bottom progress bar, used by the new Continue Watching row.
- pages/HomePage.tsx: two rows (Continue Watching + Recently Added);
falls back to the empty-state hint when both are empty.
- pages/PlayerPage.tsx: hls.js (lazy-imported) with auto-fallback to
direct play; ?mode=hls|direct query toggle; resume position written
every 10s while playing.
- pages/MediaDetailPage.tsx: heart toggle + admin 'rescrape' / 'reprobe'
buttons + dedicated 'HLS 转码播放' CTA.
- pages/FavouritesPage.tsx, PlaylistsPage.tsx, PlaylistDetailPage.tsx:
new screens.
- components/Layout.tsx + App.tsx: sidebar links for Favourites and
Playlists; routes are now lazily code-split via React.lazy + Suspense
so the initial bundle stays at ~243 KB / 82 KB gzipped (hls.js is
fetched only on first HLS playback).
Verified: go build, go vet, go test (incl. CleanQuery cases) all pass;
frontend tsc -b && vite build emits 9 route chunks plus a deferred hls
chunk.