Clarify persisted cover handling
This commit is contained in:
+6
-6
@@ -136,12 +136,12 @@ Guidance for OpenCode (and Claude Code) working under `backend/`. See root `AGEN
|
||||
behind the same challenge as its pages and with
|
||||
`cross-origin-resource-policy: same-origin`, so no `<img>` on the web UI's
|
||||
origin can load one — not even from a browser holding the clearance cookie
|
||||
(verified 2026-08-08). `Bookmark.CoverURL` rewrites a stored kagane
|
||||
`og:image` to `/img/kagane/{id}`, served by `internal/web/cover.go` through
|
||||
`latest.BrowserFetcher.Image` and memoised in-process. The templates render
|
||||
`.CoverURL`, never `.Cover`. The id is matched against a UUID regex before it
|
||||
reaches the browser: the stored value is client-supplied, so an unchecked one
|
||||
is an SSRF primitive pointed at the deployment's own network.
|
||||
`og:image` to `/img/kagane/{id}`. `internal/web/cover.go` reads the persistent
|
||||
`covers` table first, then fetches a miss through `latest.BrowserFetcher.Image`.
|
||||
The templates render `.CoverURL`, never `.Cover`. The id is matched against a
|
||||
UUID regex before it reaches the browser: the stored value is client-supplied,
|
||||
so an unchecked one is an SSRF primitive pointed at the deployment's own
|
||||
network.
|
||||
- **Web UI also owns:** session-gated `GET /install/{manga,novel}-bookmark.user.js`
|
||||
(renders the bindmounted script with the acting Reader's derived credential
|
||||
substituted in — the credential never appears in page markup, the address
|
||||
|
||||
Reference in New Issue
Block a user