fix: don't read Cloudflare's injected jsd script as a refusal

demonicscans.org turned JS detections on, so Cloudflare began injecting
/cdn-cgi/challenge-platform/scripts/jsd/main.js into ordinary 200 pages.
isInterstitial matched the bare /cdn-cgi/challenge-platform/ prefix, so
every real demonic series page became errChallengeHeld: two per pass
parked the Lane in the 15m refusal backoff while plain TLS was in fact
returning the full page (200, 133KB, 22 chapter anchors, verified live
2026-08-16).

Match the challenge orchestration path /cdn-cgi/challenge-platform/h/
instead — served only by the interstitial itself, stable across its
wording and locale.
This commit is contained in:
2026-08-16 21:17:10 +07:00
parent ba679223b2
commit 81631ef08f
3 changed files with 36 additions and 3 deletions
+7
View File
@@ -127,6 +127,13 @@ Guidance for OpenCode (and Claude Code) working under `backend/`. See root `AGEN
and cover work (both healing a stored source URL and filling a blank from
the series page) runs in the background so a slow CDN can't consume a
Lane's gap.
A refusal is only ever the challenge *page*: `isInterstitial` matches the
orchestration path `/cdn-cgi/challenge-platform/h/`, never the bare prefix.
Cloudflare injects `/cdn-cgi/challenge-platform/scripts/jsd/main.js` into
ordinary 200 pages once a zone turns JS detections on, which demonic did on
2026-08-16 — the prefix match then read every real demonic page as a refusal
and parked that Lane in 15m backoff while plain TLS was returning the full
series page.
Fetches use `bogdanfinn/tls-client` with Chrome profile as defence in depth
against fingerprint-based blocking; any failure log and skip. kagane, comix
and novelfull sit behind Cloudflare JavaScript challenges the TLS client