Skip to content

Repository files navigation

SamoTech IPTV Player

Build Security Stars Forks Issues Flutter Dart Visitors

A provider-agnostic Flutter IPTV media-player project for Android, iOS, Windows, macOS, Linux, and Web, with evidence-bounded provider protocols and media playback capabilities.

What it is

SamoTech IPTV Player is the active Flutter/Dart migration of the original Python/PySide6/libVLC application. The legacy implementation remains protected as a behavioral reference.

The Flutter application uses a feature-first architecture with Riverpod state management, Drift persistence, secure-storage boundaries, provider-aware resolution, and media_kit/libmpv as the native playback candidate.

Features and protocols

The application preserves IPTV-specific provider behavior rather than reducing all inputs to a generic HTTP client.

The architecture covers provider registration and switching, Xtream server/account/expiration data, Live TV, VOD, Series, EPG/XMLTV, M3U/M3U8/HLS classification, MAG/Stalker evidence-bounded flows, library/history surfaces, diagnostics, buffering and recovery contracts, subtitles as a documented boundary, and platform-aware backend selection.

M3U is treated as a playlist/container input, not as HLS. Xtream and MAG/Stalker are provider/control-plane protocols. Resolved media is classified independently.

Web RTSP, RTMP, RTP, UDP, and SRT remain explicitly unsupported in the current evidence matrix, and no IPTV proxy, credential-forwarding service, open CORS relay, or SSRF-prone stream relay is included.

Playback engine and evidence boundary

Native playback uses media_kit, media_kit_video, and media_kit_libs_video with libmpv/FFmpeg-based native libraries. Web HLS uses the vendored hls.js path.

Historical evidence includes controlled Web HLS decoded frames and bounded Linux synthetic media_kit/libmpv playback. These are not universal platform or real-provider claims.

Wave 8 ended with NOT_COMPLETE — STOP_CONDITION_INVOKED because the environment lacked /dev/kvm or a runnable Android target, an authorized IPTV provider/source, and physical/approved observable audio.

Phase 9 does not override those runtime limitations. The distinction remains:

BUILD ≠ ARTIFACT ≠ RELEASE ≠ RUNTIME ≠ DEVICE ≠ IPTV ACCEPTANCE

Platform status

Platform Build Runtime Signing Distribution
Android BUILD_AVAILABLE NOT_VERIFIED; no runnable Android target in the environment BLOCKED_EXTERNAL Not published
Web BUILD_AVAILABLE NOT_VERIFIED for IPTV playback NOT_APPLICABLE Not published
Windows BUILD_AVAILABLE NOT_VERIFIED BLOCKED_EXTERNAL Not published
Linux BUILD_AVAILABLE NOT_VERIFIED for release artifact; bounded synthetic Linux runtime exists historically BLOCKED_EXTERNAL Not published
macOS BUILD_AVAILABLE NOT_VERIFIED UNSIGNED; notarization unavailable Not published
iOS BUILD_AVAILABLE NOT_VERIFIED BLOCKED_EXTERNAL — Apple signing/distribution credentials Not published

BUILD_AVAILABLE does not mean RUNTIME_VERIFIED, DEVICE_VERIFIED, or IPTV_PLAYBACK_VERIFIED.

Security and privacy

Provider usernames, passwords, tokens, MAC identities, cookies, authorization headers, signed URLs, and resolved stream URLs are sensitive.

The project avoids credentials in source and test fixtures, sanitizes diagnostics, rejects credential-bearing stream URLs, and does not collect IPTV credentials through visitor or user-tracking systems.

Visitor visibility is project-level and anonymous through the documented badge source.

Before publication, the release pipeline runs formatting, analysis, tests, secret scanning, dependency review, CodeQL workflow analysis, artifact validation, checksums, and license/evidence checks.

Native media binary license provenance remains an explicit release prerequisite.

Documentation

Topic Document
Platform release matrix docs/evidence/release-platform-matrix.md
Release artifacts docs/evidence/release-artifacts.md
Badge and visitor sources docs/evidence/release-badges.md
Release workflow docs/RELEASE_PIPELINE.md
Feature parity docs/FLUTTER_FEATURE_PARITY_MATRIX.md
Playback backend decision docs/PLAYBACK_BACKEND_DECISION.md
Migration Todo docs/FLUTTER_MIGRATION_TODO.md
Changelog CHANGELOG.md
Third-party notices THIRD_PARTY_NOTICES.md

Contributing and testing

Contributions should preserve the existing IPTV core and its evidence boundaries.

Before submitting a change, run the local gate from docs/RELEASE_PIPELINE.md, keep protocol resolution outside widgets, avoid credential-bearing logs, and update evidence when behavior or platform claims change.

Do not convert build success, HTTP success, manifest parsing, or synthetic fixtures into runtime acceptance claims.

Roadmap

The next legitimate release-engineering steps are to validate the final hosted checkpoint, authorize a semantic-version release decision, resolve native media license/source-offer materials, and attach validated artifacts to a GitHub Release.

Real-provider IPTV playback, Android runtime, physical audio, signing, notarization, store publication, and additional platform runtime acceptance remain independently classified and require their own evidence.

License

This project is distributed under the MIT License.

Third-party notices and native media licensing limitations are recorded in THIRD_PARTY_NOTICES.md.

About

Samo IPTV Player

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages