Cinder pass across /admin, the login gate, and the library's a11y floor (#177)

One commit (`af07314`), three strands of browser-UI work against one design system. `docs/design-system.md` was updated to match the CSS, not the reverse.

## Library (Reader-facing)

Findings came out of a two-axis design review of the library surface; the fixes are the P1/P2 set plus the cheap P3s.

- **`.chrome` sticks at `top: 0`.** Search and the tab row were unreachable three screens into a 300-item library — exactly where they earn their keep. Everything above them (`.topbar`, `.keyrow`, `.recent`) still scrolls away on purpose: another 150px of permanent chrome on an 844px phone costs more than re-scrolling for an icon reminder.
- **One `:focus-visible` ring** (`2px solid var(--paper)`, offset 2px) on the nine controls that defined none and fell back to the UA blue — a colour tuned for neither branch of this palette. `.searchbar` keeps its `:focus-within` border recolour as a resting cue but no longer stands in for the ring.
- **Mono labels lift 10px → 11px** everywhere (nine rules). PRODUCT.md names night reading and glare as the usage scene; 10px small-caps was the one place taste overrode the brief. 11px is now a documented floor.
- **A card in flight past 2s says `Saving…` and carries `aria-busy`.** htmx sets neither, so the wait — up to its own 15s timeout, and this app is used on a phone in dead zones — was silent in both the visual and the assistive channel. Deliberately `--mute`, not `--ember`: ember means "new chapter" and nothing else.
- **Titles clamp at 3 lines**; `.is-new .title` takes `width: fit-content`, or `-webkit-box` stretches the ember underline past the text it is supposed to be sized to.
- `.libswitch a` reaches a real 44px under `(pointer: coarse)` — padding plus an 11px line landed at 43.

## /admin

- Overview routes into Lanes when a lane is unhealthy, prefixes each figure with its column word on the phone layout that drops the `thead`, labels state cells for a screen reader, and has an empty state where the sites table previously assumed rows.
- The admin shell picks up the library's chrome: htmx 15s timeout, the shared `#notice` slot, `#sr-announce`, `filter.js`.
- `admin_render_test.go` and `card_render_test.go` render the templates directly, so markup regressions in either surface fail without a browser.

## Login

`DISCORD_GUILD_NAME` (optional) names the community on the login screen and in the refusal message, so a stranger knows which Discord to ask for an invite. Unset degrades to a generic label. Neither form names the numeric guild id — that was never actionable, and the gate still reveals nothing about whether a given guild exists.

## Handlers

`maxChapterNum` (9999) now bounds **both** typed-chapter paths. `uiChapter` and `adminSeriesCorrectLatest` each parsed a `float64` with no ceiling, so a hand-rolled POST stored `1e308` and every later reader of that row — the poller's `HasNewChapter` comparison, the display string — inherited it. Matches the `max` on the card's chapter input. The API PUT path is deliberately untouched: it carries the userscripts' own scraped numbers, not typed input.

## Verification

- `cd backend && go test ./...` green (Docker-backed `pgtest`). `TestChapterOverrideRejectsBadInput` gained `"10000"` and `"1e5"` — both parse fine as `float64`, so they only fail if the bound exists.
- Visual: 390×844 dark + light, 1000px and 1440px (`zoom: 1.2`) desktop, against the real templates + real CSS. Measured `chromeTop = 0` at `scrollY 950`, `2px solid rgb(242,236,229)` rings, `content: "Saving…"` at `opacity: 1` after 2.4s, `aria-busy` `true` during / cleared after, `libswitchH = 44` in a `hasTouch` context, no horizontal overflow at either width.
- `detect.mjs` on `templates/`: `[]`, exit 0.

## Note on shape

The three strands landed as one commit because `admin_series.go` and `style.css` each carry hunks from more than one of them; splitting cleanly would have needed hunk-level surgery. Say the word if you want it split before merge.

Reviewed-on: #177
Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com>
Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
This commit was merged in pull request #177.
This commit is contained in:
2026-08-27 23:09:42 +07:00
committed by sulthan
parent cddd16bcdc
commit 3a83161b1c
32 changed files with 1567 additions and 237 deletions
+72
View File
@@ -0,0 +1,72 @@
package web
import (
"html/template"
"strings"
"testing"
"bookmarkmanager/backend/internal/store"
)
// The card carries two guarantees a browser can break that Go cannot see, so
// they are asserted on the rendered markup:
//
// - the monogram is unconditional. A cover that 404s or a request the phone
// drops leaves an <img> with no bytes, and the letter underneath it is the
// only thing between that and the browser's broken-image glyph in a 93px
// slot. Rendering it only when Cover is empty covers the wrong failure.
// - the chapter field does not refuse its own value. It is pre-filled from
// LastChapterNum, which the API accepts as any float, so a step that
// quantises the field makes a series read to 1200.25 unsavable without
// first editing a number the reader did not want to change.
func TestCardRenderKeepsCoverFallbackAndAcceptsFractionalChapter(t *testing.T) {
tmpl, err := template.ParseFS(templateFS, "templates/*.html")
if err != nil {
t.Fatalf("ParseFS: %v", err)
}
b := store.Bookmark{
Key: "asura:x", Site: "asura", Title: "Chronicles", Status: store.StatusReading,
Cover: "https://bookmarks.test/covers/abc", LastChapter: "Chapter 1200.25",
LastChapterNum: 1200.25,
}
var out strings.Builder
if err := tmpl.ExecuteTemplate(&out, "card", b); err != nil {
t.Fatalf("ExecuteTemplate: %v", err)
}
got := out.String()
if !strings.Contains(got, `class="monogram"`) {
t.Error("a card with a cover rendered no monogram: a failed image has no fallback")
}
if !strings.Contains(got, `step="any"`) {
t.Error(`chapter input is not step="any": a fractional pre-filled value is unsavable`)
}
if !strings.Contains(got, `value="1200.25"`) {
t.Errorf("chapter input is not pre-filled with the stored progress:\n%s", got)
}
}
// Every failing request must land somewhere visible. A card's own writes report
// into its .error-inline; a tab switch and a credential rotation have no card,
// and #notice is the only slot filter.js can fall back to — without it in the
// shell they fail silently. The tab's own active-state move is guarded on the
// response, or a failed switch underlines a bucket the list is not showing.
func TestAppShellCarriesFailureNoticeAndGuardsTabState(t *testing.T) {
tmpl, err := template.ParseFS(templateFS, "templates/*.html")
if err != nil {
t.Fatalf("ParseFS: %v", err)
}
var out strings.Builder
view := listView{Lib: store.KindManga, Tab: "all"}
if err := tmpl.ExecuteTemplate(&out, "app", view); err != nil {
t.Fatalf("ExecuteTemplate: %v", err)
}
got := out.String()
if !strings.Contains(got, `id="notice"`) {
t.Error("no #notice in the shell: a failure with no card to sit in reports nowhere")
}
if strings.Contains(got, `hx-on::after-request="setActiveTab(this)"`) {
t.Error("a tab moves its active state unconditionally: a failed switch underlines the wrong bucket")
}
}