feat: bindmount userscript and point Violentmonkey at the backend

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-28 17:50:39 +07:00
parent 9280542b33
commit 4a0950e1ca
5 changed files with 50 additions and 0 deletions
+37
View File
@@ -218,3 +218,40 @@ SQLite data persists in the named volume `bookmarks-data` across rebuilds.
| `compose ... config` errors about `API_TOKEN` | Run compose from the dir with `.env`, or export the vars. |
Backend config reference and endpoint list: see `README.md`.
---
## Installing / updating the userscript
The backend serves the script itself, so Violentmonkey can auto-update it.
Install once, on the phone (Cromite + Violentmonkey):
```
https://manga-api.<your-domain>/u/<API_TOKEN>/manga-bookmark.user.js
```
Open that URL in Cromite; Violentmonkey offers to install it. The token is in
the path because Violentmonkey's update poll sends no `Authorization` header,
and the script embeds `API_TOKEN` in plain text — an open URL would leak it. A
wrong token answers 404.
Updating, without a redeploy:
```bash
vi userscript/manga-bookmark.user.js # on the VPS, in this checkout
```
`./userscript` is bindmounted read-only into the container and read fresh on
every request, so the edit is live immediately. The served `@version` is derived
from the file's mtime (`YYYY.MM.DD.HHMM`, UTC), not from the `@version` in the
file, so any edit outranks the installed copy and Violentmonkey pulls it on its
next check. The `@version` in the repo is a human marker only.
Updating via redeploy: `git pull` overwrites the file with the committed
version, which is the intended behaviour — a deploy always ships the repo's
script. Note that `git pull` sets mtime to checkout time, so even a rollback
serves a *higher* version and is adopted.
If the mount is missing, the endpoint answers 404 and logs it; bookmark sync is
unaffected.