From 91090d4b2f682015c03e36fd8d20e4ddd18f3423 Mon Sep 17 00:00:00 2001 From: Sulthan Zaki Date: Tue, 28 Jul 2026 18:05:09 +0700 Subject: [PATCH] docs: document the userscript endpoint and its metadata lines Co-Authored-By: Claude Opus 5 --- DEPLOY.md | 9 +++++++++ README.md | 1 + 2 files changed, 10 insertions(+) diff --git a/DEPLOY.md b/DEPLOY.md index d698cc7..98bb97f 100644 --- a/DEPLOY.md +++ b/DEPLOY.md @@ -166,6 +166,12 @@ const API_TOKEN = ""; The token sits in the userscript's isolated world — the manga sites' JS can't read it. +Also edit the `@downloadURL`/`@updateURL` metadata lines near the top of the +file — they ship hardcoded to this deployment's domain and token, so a +deployer who skips them ends up auto-updating from someone else's backend. +See "Installing / updating the userscript" below for how those two lines are +used. + --- ## 5. Install on Bromite @@ -224,6 +230,9 @@ Backend config reference and endpoint list: see `README.md`. ## Installing / updating the userscript The backend serves the script itself, so Violentmonkey can auto-update it. +Complements §4 above — that step points `API_BASE`/`API_TOKEN` at your +backend; this one points `@downloadURL`/`@updateURL` at the same place so +auto-updates come from it too. Install once, on the phone (Cromite + Violentmonkey): diff --git a/README.md b/README.md index b0aa729..1e6a83a 100644 --- a/README.md +++ b/README.md @@ -37,6 +37,7 @@ Bromite userscript (isolated world, Shadow DOM UI, localStorage cache) | `PUT` | `/bookmarks/{key}` | Bearer | Upsert one series; returns the row as stored. | | `DELETE` | `/bookmarks/{key}` | Bearer | Remove one. | | `GET` | `/healthz` | none | `200 ok`. | +| `GET` | `/u/{token}/manga-bookmark.user.js` | token in path | Serves the userscript with an mtime-derived `@version`. | `key` is `:` — e.g. `asura:trash-of-the-counts-family-f886a8af` or `demonic:Infinite-Level-Up-in-Murim`. Sync is last-write-wins.