fix(player): mpv draws all Linux video, and no longer runs text from a URL
Security (DR-298, DR-299): - The pinned libmpv crate's Mpv::command joins its arguments and calls mpv_command_string, which parses `;` as a command separator. Stream URLs carry server-controlled ids and TranscodingUrl, and a download's file:// path carries its track title, so a crafted title could run any mpv command, `run` included. Every call now goes through mpv_command::command, an argv built for mpv_command. The same parse broke loadfile for every downloaded title containing a space. - mpv's tls-verify defaults to no, and its URLs carry the ApiKey. Every handle is now hardened with tls-verify=yes and ytdl=no before its first loadfile, and fails construction if it cannot be. Linux video (DR-235 phase 1): - native_video::enabled() is unconditional on Linux; the JELLYTAU_NATIVE_VIDEO opt-in is retired. No platform reports a webview video fallback, so the Settings switch no longer appears. Windows keeps the webview element until mpv reaches it (DR-237). - The Linux device profile is unchanged (still h264, DR-234), so this ships the configuration that was tested under the env var.
This commit is contained in:
@@ -2912,16 +2912,15 @@ export type PlaybackCapabilities = {
|
||||
*/
|
||||
usesWebviewAudio: boolean;
|
||||
/**
|
||||
* True when video can be rendered by a native surface composited *behind*
|
||||
* a transparent webview. Android only: ExoPlayer draws into a SurfaceView
|
||||
* beneath the WebView. Linux cannot do this (WebKitGTK/Wayland
|
||||
* compositing), so it stays on the HTML5 element.
|
||||
* True when video is rendered by a native surface composited *behind* a
|
||||
* transparent webview: ExoPlayer's SurfaceView on Android, mpv's GL area on
|
||||
* Linux.
|
||||
*/
|
||||
supportsNativeVideo: boolean;
|
||||
/**
|
||||
* True when the user may send video to the webview element instead of the
|
||||
* native renderer — the frontend offers the switch only then, and honours
|
||||
* the stored preference only then. See [`webview_video_fallback`].
|
||||
* the stored preference only then. False on every platform since DR-235.
|
||||
*/
|
||||
webviewVideoFallback: boolean }
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user