chore: drop asuracomic.net from the userscript, CORS allowlist and docs (#96)

The old domain's deep links 301 to the asurascans.com root, discarding the
path, so a page on it never yields a series document and a stored address on
it never yields a series page. #94 pinned each Site to one hostname, which
already rejects such an address server-side; this removes the remaining
references so nothing invites a Reader onto the dead host.

Live deploys still carry the origin in their own .env and must drop it there
too - the allowlist is read from the environment, not from these defaults.
This commit is contained in:
2026-08-12 05:49:35 +07:00
parent 21615be2bd
commit 8ae98816eb
8 changed files with 29 additions and 23 deletions
+1 -1
View File
@@ -43,7 +43,7 @@ TOKEN_KEY=<paste output of: openssl rand -hex 32>
OWNER_DISCORD_ID=<discord user id>
# CORS allowlist — leave as-is unless a site changes hostname.
ALLOWED_ORIGINS=https://asuracomic.net,https://asurascans.com,https://demonicscans.org,https://comix.to,https://kagane.to
ALLOWED_ORIGINS=https://asurascans.com,https://demonicscans.org,https://comix.to,https://kagane.to,https://novelfull.com,https://lightnovelworld.net
# Required — password for the bundled Postgres container. Compose builds the
# backend's DATABASE_URL out of it and has no fallback for either.