midarrlabs/midarr-server
48.8
Weak · 23 September 2026
3k
lines of production code
Elixir
primary language
5
measurements over time
What this system is
This system is a media library and streaming application built on Phoenix, designed to catalog and stream movies and TV series. It provides users with authenticated access to browse content, track viewing progress, and stream video with Chromecast support. The platform also features real-time presence tracking, push notifications, and an administrative interface for managing users and content synchronization.
How it got here
2021 — Media library and authentication overhaul
26 changes.
The project underwent a significant architectural shift, migrating the database from SQLite to PostgreSQL and upgrading to Phoenix 1.8 and Elixir 1.17. This period focused on building out a comprehensive media library with real-time presence tracking, user authentication via OAuth, and a modernized frontend using Tailwind CSS and LiveView.
2022–2024 — media browsing and streaming features
8 changes.
This period focused on expanding the user interface with new pages for browsing movies, TV shows, and people, alongside implementing search and video playback capabilities. The work also included integrating Chromecast support, refining CSS styling, and adding test coverage for authentication.
Features
Add movies index and show pages
Introduced new LiveView modules and templates for browsing and viewing individual movies. The index page provides a searchable, sortable, and paginated list of movies, while the show page displays detailed information about a specific movie, including its poster, title, year, studio, runtime, and ratings from external sources like TMDb and IMDb.
_lib/media\_server\_web/live/movies\live · high confidence
Add people listing and detail views
Users can now browse a paginated, searchable list of people and view individual profiles. The new People index page includes a search input, a sort-by dropdown (name, date, status), and a list component for displaying people. The new show page displays a person's photo, name, year, studio, and ratings (TMDB, IMDb, Rotten Tomatoes), along with a biography summary fetched asynchronously from the TMDB API.
_lib/media\_server\_web/live/people\live · high confidence
Add real-time presence tracking for room channels
The application now supports real-time presence tracking for users in the 'room:lobby' channel. A new \MediaServerWeb.Presence\ module is introduced to leverage Phoenix.Presence, and the \RoomChannel\ is updated to track users upon joining, broadcasting their online status and user ID to all connected clients. This enables features like displaying online users and their names in the room.
_lib/media\_server\web/channels · high confidence
Add support for watching movies and episodes with Chromecast integration
The watch live page now supports streaming both movies and TV episodes, preserving the user's last watched position for each. The video player includes native Chromecast support, allowing users to cast media to a connected display. The implementation handles URL parameters for both movie and episode content, updating the page title and loading appropriate poster and background images.
_lib/media\_server\_web/live/watch\live · high confidence
Add user login page with email and password fields
A new login template has been added for the user session, providing a form where users can enter their email address and password to sign in. The page includes error message display, a 'Remember me' hidden field, and a login button styled with the application's theme.
_lib/media\_server\_web/templates/user\session · high confidence
Adds database schema for media content, user progress, and background jobs
The application now supports tracking user watch progress for both movies and TV series episodes, introducing new database tables to store viewing states. Additionally, the schema includes tables for managing series metadata, individual episodes, and people (actors/directors) with their associated images. A genres table and a many-to-many mapping for movies are also added, while background job processing is enabled via the Oban library.
priv/repo/migrations · high confidence
Adds web app manifest, browser config, logo, and service worker for improved mobile and offline support
The application now includes a web app manifest (app.webmanifest) defining the app name, theme color, and icon sizes for standalone mode, alongside a browser configuration file (browserconfig.xml) for Microsoft tiles. A new SVG logo (logo.svg) is added to the static assets, and a service worker (service-worker.js) is introduced to handle push notifications. As part of this update, the previous robots.txt file was removed.
priv/static · high confidence
Automated setup of admin user, genre list, and media sync workers
The application's initial setup process has been automated. Upon first run, the system will now automatically create an admin user account using environment variables, populate a comprehensive list of media genres, and schedule background jobs to sync movies and series. This replaces the previous manual or empty seed state, ensuring the application is ready for use with essential reference data and administrative access.
priv/repo · high confidence
Consolidate user account and invitation management in Settings
The Settings page now allows users to update their own name and displays their API token. Additionally, administrators can invite new users directly from the Settings interface, where the invitation form includes fields for name, email, and password, and a list of existing users is displayed.
_lib/media\_server\_web/live/settings\live · high confidence
Enable real-time presence tracking and push notifications
The application now tracks online users in real-time using Phoenix Presence, displaying a green indicator on active user profiles. Additionally, the app registers a service worker and implements push notification subscriptions for media follow actions, allowing users to receive push alerts. The legacy topbar vendor file has been removed in favor of the npm-managed 'topbar' package.
assets/js · high confidence
Introduce Home page with recent movie additions
The home page now displays a 'Recent additions' section that lists the latest movies. The LiveView controller fetches the 10 most recent movies and passes them to a poster list component, while also assigning the current user's name for a personalized welcome header.
_lib/media\_server\_web/live/home\live · high confidence
Introduce dedicated Series index and show pages
The series section now has its own dedicated LiveView templates and controllers. Users can browse a paginated, searchable, and sortable list of TV shows on the index page, and view individual series details with season and episode listings on the show page.
_lib/media\_server\_web/live/series\live · high confidence
Introduce search functionality for movies and series
Added a new search page at /search that allows users to search for both movies and series simultaneously. The implementation includes a search input field that triggers an asynchronous query to the backend, returning results for both content types which are then rendered using the existing ListPostersComponent.
_lib/media\_server\_web/live/search\live · high confidence
Introduce user authentication and API token management
The accounts module now includes a User schema with email, name, password, and admin status fields, along with changesets for registration and name updates. A new UserToken schema supports session and API token generation, verification, and storage. The UserNotifier sends invitation emails containing account details and API tokens. This establishes the foundation for user authentication, session management, and API access.
_lib/media\server/accounts · high confidence
Introduces new API controllers for media content and user authentication
The update adds dedicated controllers to expose media metadata and user sessions. New endpoints are introduced for browsing and retrieving movies, series, seasons, and episodes, as well as a search function that queries both movies and series. A streaming controller is added to handle video playback for movies and episodes. Additionally, the system now supports user authentication via a session controller and OAuth callback, along with a webhook controller to handle external event notifications for media updates.
_lib/media\_server\web/controllers · high confidence
New sidebar navigation and list components for media browsing
The application now features a new left-side navigation bar that provides direct links to Movies, TV Shows, People, and Search, alongside a section for upcoming releases. Additionally, new components have been introduced to render lists of movie posters and TV show screenshots, each with specific styling and interactive behaviors for browsing content.
_lib/media\_server\web/components · high confidence
Behavioural changes
Add verified routes and static path configuration
The application now uses Phoenix's verified routes feature, which provides compile-time checks for route helpers and improves type safety. Additionally, the static asset paths are explicitly configured to include assets, fonts, images, and various icon files, ensuring these resources are correctly served.
lib · high confidence
Added handlers for media index resets and user events
New action modules (Movie, Series, User) have been introduced to handle internal system events. For movies and series, the system now resets the respective indexes when content is added or deleted, ensuring the media library stays synchronized. Additionally, the User module now handles registration and navigation events, logging navigation parameters for tracking purposes.
_lib/media\_server\web/actions · high confidence
Adds user authentication, OAuth integration, and structured navigation for media content
The application now supports user authentication via OAuth, with new modules handling the OAuth flow and token verification. A user navigation hook tracks the current user's path, and the router is restructured to protect routes requiring authentication. Additionally, the default Phoenix welcome page is removed and replaced with live views for browsing movies, series, and people, alongside corresponding API endpoints.
_lib/media\_server\web · high confidence
Configuration updates for production, testing, and new integrations
The application's configuration has been updated to support new features and improve reliability. Production environments now use Sendgrid for email delivery instead of the previous default, and the application is configured to disable origin checking for easier deployment. Development and test environments have been adjusted: the database pool size is increased to 10, and test database connections now use environment variables for flexibility. Additionally, configurations for Tailwind CSS, Oban (background jobs), TMDb API, and Flop (pagination) have been added to support new application capabilities.
config · high confidence
Enable Tailwind CSS with line-clamp support
The project now includes a Tailwind CSS configuration file that scans JavaScript and Elixir template files for class usage. This setup enables the @tailwindcss/line-clamp plugin, allowing users to apply line-clamping utility classes in their templates.
assets · medium confidence
Migrate database backend from SQLite to PostgreSQL
The application's data layer has been switched from SQLite to PostgreSQL, enabling a more robust and scalable database solution for the new media library features. This change is reflected in the repository configuration and is supported by the addition of numerous new Ecto schemas (such as Movies, Series, Episodes, and Genres) that leverage the new database capabilities.
_lib/media\server · high confidence
Migrate from Milligram CSS framework to Tailwind CSS
The application's styling has been updated to use Tailwind CSS instead of the previous Milligram framework. This change replaces the default Phoenix starter styles with Tailwind's utility-first approach, which significantly alters the visual appearance and layout of the user interface, including the header, hero section, and form elements.
assets/css · high confidence
Redesigned site layout and header structure
The application's layout templates have been significantly restructured. The root template now includes a full set of browser icons, a web manifest, and a script to pass the current user's ID to the client-side JavaScript. The live template has been updated to render a new navigation component and a styled main content area, while the app template has been simplified to remove the previous header and alert structures.
_lib/media\_server\web/templates/layout · high confidence
Renames PageView to UserSessionView and adds LiveComponent support to LayoutView
The \PageView\ module has been renamed to \UserSessionView\ to better reflect its purpose in handling user session data. Additionally, the \LayoutView\ module has been updated to include \Phoenix.LiveComponent\, enabling the layout to leverage live component features for improved interactivity and state management within the media server's web interface.
_lib/media\_server\web/views · medium confidence
Updated development environment and build configuration
The development and production build environments have been modernized. The Dockerfile now uses Elixir 1.17 with OTP 26, and the build process includes Node 22 for asset compilation. The docker-compose.yml has been updated to include health checks for all services, and the entry point script (entry.sh) now waits for the database to be ready before running migrations and starting the server. Additionally, a new entry-local.sh script has been added to handle local development setup, including seeding the database with sample data for Radarr and Sonarr.
(repo-wide) · high confidence
Test coverage
Add token verification tests; Added live view tests for home, movies, series, settings, and video playback; Added test coverage for MediaServer core modules; Added test coverage for media server web controllers; Added test support infrastructure for user authentication and mock services; Added tests for seed data and mock server setup; Added unit tests for the RoomChannel.
Dependencies
Upgrade to Phoenix 1.8 and Elixir 1.17
The project has been upgraded to Phoenix 1.8 and Elixir 1.17, bringing the application to version 5.0.0. This update includes a broad range of dependency updates, such as Ecto 3.13.2, Postgrex 0.21.1, and Phoenix Live View 1.1.3. Additionally, new dependencies like Oban, Flop, and Oapi\_tmdb have been added, while unused dependencies such as Scrivener and Gettext have been removed. The build process for assets has also been updated to use Tailwind CSS for minification.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 47 → 49 (+1.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (+0.4)
- Architecture 97 → 84 (-12.6)
- Maturity 49 → 48 (-2.0)
- Readiness 38 → 55 (+17.3)
- Security 40 → 56 (+16.3)
- Accessibility 40 (new)
Resolved (45)
- Change coupling: show.ex ↔ index.ex (lib/media_server_web/live/movies_live/show.ex)
- Coverage not included — suite not readable by the collector
- Critical IaC: DS-0031 (Dockerfile)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (lib/media_server_web/controllers/movies_controller.ex)
- Duplicated block (11 lines × 2) (lib/media_server_web/live/watch_live/index.ex)
- Duplicated block (12 lines × 2) (lib/media_server_web/live/series_live/show.ex)
- Duplicated block (13 lines × 2) (lib/media_server_web/controllers/episodes_controller.ex)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (assets/package-lock.json)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (assets/package-lock.json)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (assets/package-lock.json)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- …and 25 more
New (84)
- Critical IaC: DS-0031 (Dockerfile)
- Critical IaC: DS-0031 (Dockerfile)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (lib/media_server_web/controllers/movies_controller.ex)
- Duplicated block (11 lines × 2) (lib/media_server_web/live/series_live/show.ex)
- Duplicated block (13 lines × 2) (lib/media_server_web/controllers/episodes_controller.ex)
- Duplicated block (13–14 lines × 2) (lib/media_server_web/live/watch_live/index.ex)
- High CVE: [GHSA redacted] (assets/package-lock.json)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (assets/package-lock.json)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (assets/package-lock.json)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (assets/package-lock.json)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- …and 64 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
midarrlabs/midarr-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 66c3c04c71d64c72fac4a480d957694c1774ff30 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.