Lightning TV Live
Changelog
A plain-English history of improvements to the viewing and match-night experience.
Current version
v1.5.0-beta.9
-
- The post-game reconciliation page now uses the readable dark match-night design throughout its run history, source snapshots, discrepancy cards, decisions and status messages instead of placing white text on white panels.
- The post-game closure page now has a clear match-night report layout with readable closure checks, safer sign-off controls and detailed aggregate viewer analytics for audience size, concurrency, watch time, playback reliability, devices, quality and engagement; staff previews and viewer identities are excluded.
- Fresh deployments now rebuild static-file references successfully before serving browser icons, preventing startup from being blocked by a missing or outdated asset manifest.
- Protected stream takeovers now keep the working device active until Amazon confirms it has been stopped, retry temporary failures safely and prevent stale players from continuing to send requests.
- Live forms and playback controls now recover after browser-security cookies refresh, sign-out has a confirmation page, Cast shutdown is safe to repeat and standard browser icons load correctly.
- Replay exports now select timestamped vMix source files before inspecting video metadata, preventing large folders of historical recordings from making the worker appear to hang.
- Automatic faceoff detection now waits for three full seconds without game-clock movement, reducing false stoppage and faceoff events caused by brief OCR pauses.
- Routing an Amazon IVS stream from its controlling browser to Google Cast now keeps the same protected viewing session instead of attempting an unnecessary AWS competing-viewer revocation that could block the television handoff.
- The live player's bottom controls now fade away after inactivity in full-screen video, leaving the picture unobstructed while keeping keyboard-focused controls available.
- Amazon IVS streams now hand protected playback to AirPlay and Google Cast without television requests being rejected by browser-origin or single-use playlist checks; ordinary in-browser viewing retains those stricter safeguards.
- Checkout now replaces a missing or deleted Stripe customer record automatically, so viewers can continue to payment after test data is refreshed or Stripe account records change.
- Clear all pending on the review queue now clears stoppages as well as shots and faceoffs, while retaining their audit history and cancelling unstarted replay jobs.
- The Lightning TV badge on a Cast television now fades away completely when the video begins, leaving the live picture unobstructed while retaining connection and error messages when needed.
- Google Cast now completes on the first television selection without mistaking the intentional laptop-to-TV handoff for competing playback, and takeover prompts no longer duplicate their message in the player corner.
- AirPlay televisions can now fetch protected Test and IVS live playlists after connecting instead of remaining on the AirPlay logo, while the handoff keeps its signed short-lived authorization and the same one-device viewing session.
- The Broadcast Control Centre protected preview now loads the complete responsive player design, keeping video controls, status messages, TV routing, playback details and retry actions correctly sized and positioned.
- The live player now uses one Play on a TV button for both Google Cast and AirPlay, enables it for authenticated staff previews, reliably connects it when the Cast service becomes ready before the player controls, lets Google's receiver picker perform final device discovery, keeps browser-bound preview links restricted, and gives match-night staff safe browser-console diagnostics when setup fails.
- A brief viewing-session connection drop now reconnects the existing protected session without restarting the player or repeatedly requesting playback authorization, and genuine retry limits show a clear wait time.
- The Open video page button now stays hidden until the video countdown reaches zero, then appears when the match page refreshes at the opening boundary.
- Production Amazon IVS workers now include the certificate-based AWS credential helper, so scheduled fixture channels can be created without match-night staff installing software inside a running container.
- All dates and times entered by staff or shown across Lightning TV now use Europe/London time, including automatic GMT and BST changes.
- Administrators can permanently delete any protected Test fixture and its fixture-bound test data even when dummy orders exist; production fixtures keep their payment and audit safeguards, dummy order and support records remain available, and the draft Terms, Privacy and Refund policies now explain this boundary.
- Broadcast Control Centre pages now retain the standard same-origin referrer policy, so revealing or rotating a contribution key no longer sends a null request origin and fails CSRF verification; the page displaying the secret remains protected by a no-referrer policy.
- Broadcast Control Centre forms now recover from a refreshed browser security cookie before submitting, while Alpha and Beta use isolated sign-in and form-protection cookies so revealing a Test contribution key cannot leave other forms failing CSRF checks.
-
- Game timelines now put the most recent event first; one five-second GameStats worker refreshes a shared event cache and pushes changed timelines to connected browsers, so viewer refreshes no longer call the external event API.
- Protected Test fixtures now expose a separate per-game vMix or OBS contribution endpoint and serve the resulting video directly from Lightning TV without sending it through Amazon IVS or another CDN; administrators can reveal or rotate the audited input credential in the Broadcast Control Centre.
- Each fixture now has its own Off, protected Test or production IVS stream mode; imported GameStats fixtures stay on IVS, while production passes activate and deactivate with safe order and bundle guards.
- Production IVS channels are created automatically 85 minutes before face-off and are revoked, stopped and deleted after staff finish the game, so contribution credentials are isolated to the fixture.
- Entitled viewers now see a private fixture countdown until 60 minutes before face-off, the complete match page from that point, and the protected player from 40 minutes before face-off, with automatic transitions and a safe Starting shortly state.
- Broadcast administrators now have a per-game Control Centre with protected preview, schedule and channel health, vMix endpoints, audited one-time stream-key reveal and a single-use view-only viewer check.
-
- The scoreboard now compacts continuously as viewers scroll, can remain naturally partway between layouts, and expands smoothly when they scroll back.
- The live player now puts the video first with a clear floating control dock, crisp and easily distinguished volume and casting controls, keyboard shortcuts, picture-in-picture and quieter playback details, while Google Cast can reconnect, control playback and volume, continue on the TV when the controller page closes, and stop cleanly from either screen.
- Creating an IVS game now puts its £15 single-game viewing pass on sale, while Off and protected Test games keep that automatic pass unavailable; staff also store teams once and select them from the fixture form.
- The final purchase review now keeps the pass artwork, included broadcasts, account, price, live-video and device limits, policy links and secure Stripe action together in a clearer responsive checkout summary.
- Pass detail pages now give the artwork, price, included broadcasts and purchase action a clearer layout, with prominent live-video and one-device limits plus a direct link to the refund policy.
- Fixture pass pages now present the game artwork once in a clearer match-and-purchase layout, with easier-to-scan prices, inclusions and actions that stay readable with long team names and on phones.
- Clearing pending shot and faceoff reviews now completes correctly on PostgreSQL deployments instead of returning an internal server error.
- Operators can clear every pending shot and faceoff review in one confirmed action; cleared records stay in match history, provisional shot totals are corrected and unstarted replay jobs are cancelled.
- The main navigation now opens a dedicated Multi-game Passes catalogue containing season passes and opponent bundles, while individual-game passes remain with their fixture.
- The home-page game spotlight now includes the fixture graphic and scales long team names so the matchup details and main actions remain visible together on ordinary screens.
- Match-night staff can upload a 1080 × 1080 graphic to each game, and viewers see it consistently while choosing the individual-game pass, reviewing the purchase, paying through Stripe and confirming access.
- The home page now puts the live game or next scheduled broadcast in a prominent match spotlight, while Featured passes stays focused on season passes and opponent bundles instead of individual game passes.
- Pass editors can now upload square artwork for each single-game or multi-game pass; viewers see it throughout the store and Stripe Checkout uses the same thumbnail to identify the purchase.
-
- Every viewer-facing page now uses a deliberate Lightning TV layout, including redesigned game and shot lists, clearer purchase and support states, and a secure Stripe Checkout action with the official Powered by Stripe badge.
- Commerce and support staff can now open the matching Stripe payment, Checkout Session, customer and webhook event for an order directly, with raw references retained for reconciliation and tracing funds.
- Viewer investigations now begin with clear account and purchase information, then let staff choose one purchased stream to review its watch time, devices, sessions, playback attempts and browser-provided connection estimate.
- Staff now have one support and feedback dashboard for triage, assignment and private notes, and new viewer support cases notify [email protected] with delivery failures visible to staff.
- A per-viewer investigation view now shows whether streams opened, reported or estimated watch time, devices used, sessions and playback attempts alongside orders, access grants and support history.
- Blocking an account now stops its active streams, while the Terms, Refund, Privacy, Cookie and Support policies clearly explain access enforcement, refund consequences and the playback records used for support and investigations.
- Terms of Sale and the Refund policy now explain pass contents, payment, personal viewing rules, fixture changes, service failures, cancellation requests and fair full or partial refunds in plain English.
- The Cookie notice now lists the cookies and browser storage Lightning TV actually uses, while clearer Privacy, Accessibility and Support pages identify Milton Keynes Ice Hockey Club Ltd, distinguish its registered office from the public correspondence address, and explain how to get help at [email protected].
- Footer links now keep clear spacing, wrap cleanly on narrow phones and provide larger touch targets without causing horizontal scrolling.
- New accounts must separately accept the Terms of Sale and acknowledge the Privacy Notice, while an unticked optional choice controls marketing email and can be changed later from Account with a versioned audit history.
- Account holders can now read a detailed privacy notice and securely download a machine-readable copy of their account, purchase, access, playback, feedback and support data after confirming their password.
- Stripe Checkout can present GBP catalogue prices in local currencies, calculate registered taxes, collect billing addresses and terms consent, while orders preserve billing, tax, presentment and policy snapshots for support and reconciliation.
- Viewers can read versioned Terms, Privacy, Cookie, Refund, Accessibility and Support pages and open a trackable support case linked to an order.
- Fixture times now carry UTC timestamps and render in each viewer's device time zone, with an explicit Europe/London fallback.
- Protected playback stores an opaque Amazon IVS viewer identity and fails a takeover closed if the previous IVS viewer session cannot be revoked.
- Safari viewers can hand the same protected session to native AirPlay with a fresh HLS authorization, with the expected latency change explained on screen.
- A hosted Google Cast sender and receiver exchange short-lived authorization, keep the TV heartbeat alive independently of the phone and stop when the linked viewing session ends.
- Playback attempts, startup time, buffering, delivered quality and revocation outcomes now feed a paid-beta service-level dashboard for operators.
- The Beta stack exposes worker data services only on the rink LAN, while ingress and database protection remain with the separately managed systems.
- Shared-cache request limits protect sign-in, checkout, playback and telemetry, while staff and commerce administrators can be required to use TOTP verification and one-use recovery codes.
- A nonce-based Content Security Policy now limits scripts, media, connections, forms and frames to the application and the approved IVS, Stripe and Cast services.
- Paid-beta readiness now fails when tax or legal approval, IVS revocation, casting, MFA, Redis rate limits, email-domain evidence, external status or alerting is missing, and CI runs the full suite on SQLite and PostgreSQL with dependency, code and secret scans.
-
- Verification, password-reset and purchase-confirmation messages now use a branded Lightning TV HTML design while retaining a plain-text version for every mailbox.
- Commerce staff now work from separate overview, pass, order, reliability and settings pages instead of one crowded operations screen.
- Email verification links now complete correctly on PostgreSQL, and requesting a replacement makes every older unused link invalid.
- Automatic clock tracking no longer disconnects the OCR feed when PostgreSQL checks an awaiting faceoff with no linked event.
- Alpha and Beta email delivery now requires an authenticated mail service and records delivery errors for staff, avoiding silent verification-email failures.
-
- Viewers can buy a broadcast pass through Stripe's test-mode Checkout using card and eligible Apple Pay or Google Pay wallets, with access granted automatically only after a verified payment event.
- Stripe event replay is safe: duplicate deliveries cannot create another order, entitlement, or audit grant, while staff can reconcile missed updates and handle cancellations or partial and full refunds.
- A new Stream & Commerce Administrator role can manage broadcasts, passes, payments and viewer access without entering match statistics, analytics, health, logs, debug tools or general user administration.
- Every new or imported game now receives its own draft viewing pass automatically, ready for an administrator to price and place on sale.
- Stripe Checkout now uses the account's dashboard-managed payment methods without sending an unsupported session option, so test checkouts start correctly on existing Stripe API versions.
- Commerce staff now have a polished operations dashboard showing sales, refunds, orders, viewer access, webhook health, and viewing-pass performance for every game.
- Lightning TV now presents fixtures and live-only passes as its primary viewer journey, with single-game, season and opponent-bundle options leading directly from discovery to purchase and playback.
- Viewers verify their email before payment, review every fixture and term in a pass, and see access appear automatically while the site safely waits for Stripe's verified confirmation.
- Orders preserve the exact broadcasts and product details offered at checkout, while overlapping passes keep valid access if a different purchase is later refunded.
- My Passes brings live, upcoming and finished fixtures together with purchase history, and the live video player now leads the match page while scores, events and supporter features remain available alongside it.
- Commerce staff can safely expand a season or opponent pass for existing purchasers after reviewing the impact, with every added fixture and access grant recorded for audit.
- A recovery worker reconciles delayed Stripe updates and retries purchase emails, while operator service notices and clearer delayed or unavailable states keep viewers informed during incidents.