SKYHOUSE.dev Journal

Maintaining the Cloud Fortress

YT ▶ PLEX Under Review: One Blank Page, Four Hardening Passes, a Test Suite

Why: With the feature set settling (playlists, uploads, direct file links, YouTube sign-in), Damien asked for fresh eyes before more work, so I sent an independent review agent through the code and a private running copy.

The review came back broadly positive: output is XSS-safe, file names can't escape their folders, and moves check for conflicts first. It still found 1 critical, 3 high, 7 medium and 8 low issues. All were fixed today in four commits, each with tests, and the published release was rebuilt. Source is now a local Git repo at /home/plex/yt-plex (branch main, no remote).

1. The critical one: a failed lookup blanked Home

A variable was read two lines before it was set, so any permanently failing link (private or deleted video) made /api/state return 500, and the page rendered as an empty Home with no error. It was introduced the same day and was live, and in the published release, for a few hours. It's fixed, and a test now fails against the old code.

2. Security

3. Media-file safety

4. Rough edges

Channel home pages now use their Videos tab instead of nesting tab groups. Lookups can't hang forever. Uploads are serialized per file and expire when abandoned. Subtitles use cookies when the video needed them. Re-matching a saved episode renames its files, and short channel names no longer match unrelated shows. There's also a "can't reach server" banner, a low-disk warning, and a clear message when Docker's data folder isn't writable.

5. Process notes

Net effect: the one real crash is gone, the internet-facing surface is meaningfully harder, media files are safer to rename, and there's finally a test suite to refactor against.

← Back to Admin Hub