
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@xiboplayer/pwa
Advanced tools
Lightweight PWA Xibo digital signage player built on the @xiboplayer SDK. Part of the SDK monorepo at packages/pwa/.
capturePage()DEBUG, INFO, WARNING, ERROR, NONE (via URL param or CMS settings; log levels only affect verbosity, not overlays)All keyboard shortcuts and mouse hover are disabled by default for secure kiosk operation. Enable them via controls in the host player's config.json (Electron or Chromium). The config is injected into localStorage by @xiboplayer/proxy.
| Key | Group | Action |
|---|---|---|
D | debugOverlays | Toggle download progress overlay |
T | debugOverlays | Toggle timeline overlay (click-to-skip supported) |
S | setupKey | Toggle CMS setup screen |
V | videoControls | Toggle native <video> controls |
→ / PageDown | playbackControl | Skip to next layout |
← / PageUp | playbackControl | Skip to previous layout |
Space | playbackControl | Pause / resume playback |
R | playbackControl | Revert to scheduled layout |
| Media keys | playbackControl | Next/prev/pause/play (MediaSession API) |
By default, new displays must be manually authorized by a CMS administrator. To skip this step and have the player authorize itself automatically, provide OAuth2 API credentials — either via the setup page or via config.json provisioning in the Electron/Chromium shells.
After the player registers with the CMS (via XMDS RegisterDisplay), it uses the CMS REST API with an OAuth2 client_credentials flow to:
/api/authorize/access_tokenGET /api/display?hardwareKey=...PUT /api/display/{id}/authoriseIf auto-authorize fails (wrong credentials, missing scope, CMS unreachable), the player silently falls back to manual authorization — the CMS administrator sees the display as "Awaiting approval".
client_credentialsdisplays scope — this is required for the player to find and authorize itselfWithout the displays scope enabled, the API will return 403 Forbidden and auto-authorize will not work.
In the setup page, expand "Auto-authorize via API (optional)" and enter the Client ID and Client Secret. These are saved to localStorage alongside the CMS configuration.
When using the Electron or Chromium shells, add the credentials to config.json:
{
"cmsUrl": "https://your-cms.example.com",
"cmsKey": "your-cms-key",
"displayName": "Lobby Display",
"apiClientId": "your-client-id",
"apiClientSecret": "your-client-secret"
}
Three toggleable overlays provide real-time insight into player operation without leaving the playback screen. All are disabled by default — enable controls.keyboard.debugOverlays in the host player's config.json, then press the corresponding key to toggle. Overlays are independent of log level — DEBUG logging does not enable overlays.
T)Shows the upcoming schedule as a scrollable list (up to 8 entries visible):
▶ marker and blue left border19:25–19:31 #362 6m 15s)[def] tag on default/fallback layouts (no campaign scheduled)OFFLINE badge when the player has lost CMS connectivity+N badge appears next to a layout when N other layouts were scheduled for the same time slot but suppressed by a higher-priority campaign. Hover over it to see which layouts were hidden and their priorities (e.g. Also scheduled: #366 (p0), #362 (p0))R to return to normal schedule playbackD)Shows real-time media download progress:
Useful during initial deployment or after a purgeAll command to monitor how quickly content is being cached.
V)Toggles native browser <video> controls on all video elements currently in the DOM. Shows play/pause, seek bar, volume, and fullscreen buttons on each video widget — helpful for debugging video playback issues, checking codec info, or manually seeking within a video.
The Service Worker (sw-pwa.js) provides:
The PWA can be served from:
dist/ to a path under the CMS web server (e.g. https://your-cms.example.com/player/pwa/) to avoid CORS@xiboplayer/proxy to serve the PWA and proxy CMS requests (used by Electron and Chromium shells)pnpm install
pnpm run build
pnpm run dev
pnpm link ../xiboplayer/packages/{utils,cache,renderer,schedule,xmds,xmr,core,stats,settings}
cd ../xiboplayer-electron && npx electron . --dev --no-kiosk
cd ../xiboplayer-chromium && ./xiboplayer/launch-kiosk.sh --no-kiosk
Playwright tests in playwright-tests/ run against a live CMS with scheduled layouts — not for CI.
PWA_URL=https://your-cms.example.com/player/pwa/ npx playwright test
Apache-2.0
FAQs
Lightweight PWA xiboplayer with RendererLite
We found that @xiboplayer/pwa demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.