chore: drop asuracomic.net from the userscript, CORS allowlist and docs (#96)

The old domain's deep links 301 to the asurascans.com root, discarding the
path, so a page on it never yields a series document and a stored address on
it never yields a series page. #94 pinned each Site to one hostname, which
already rejects such an address server-side; this removes the remaining
references so nothing invites a Reader onto the dead host.

Live deploys still carry the origin in their own .env and must drop it there
too - the allowlist is read from the environment, not from these defaults.
This commit is contained in:
2026-08-12 05:49:35 +07:00
parent 21615be2bd
commit 8ae98816eb
8 changed files with 29 additions and 23 deletions
+8
View File
@@ -120,6 +120,14 @@ test("asura.detect returns other for non-series paths", () => {
assert.equal(asura.detect(loc("https://asurascans.com/bookmarks")).type, "other");
});
test("asura.matches accepts only asurascans.com", () => {
assert.equal(asura.matches({ hostname: "asurascans.com" }), true);
assert.equal(asura.matches({ hostname: "www.asurascans.com" }), true);
// Dead domain: deep links 301 to the asurascans.com root, discarding the path.
assert.equal(asura.matches({ hostname: "asuracomic.net" }), false);
assert.equal(asura.matches({ hostname: "asurascans.com.evil.example" }), false);
});
test("asura.latestChapterFromAnchors takes the highest and skips the First Chapter shortcut", () => {
const best = asura.latestChapterFromAnchors([
{ href: "/comics/solo-leveling-059befe1/chapter/1", text: "Chapter 1" },