Cinder pass across /admin, the login gate, and the library's a11y floor

Uncommitted work from three design runs on this branch, against one design
system: docs/design-system.md is updated to match the CSS, not the reverse.

Library (Reader-facing):
- .chrome sticks at top: 0. Search and the tab row were unreachable three
  screens into a 300-item library, which is exactly where they earn their
  keep; everything above them still scrolls away on purpose.
- One :focus-visible ring (2px --paper) on the nine controls that defined
  none and fell back to the UA blue. .searchbar keeps its border recolour as
  a resting cue but no longer stands in for a ring.
- Mono labels lift 10px -> 11px everywhere. The brief names night reading and
  glare as the usage scene; 10px small-caps was where taste overrode it.
- A card in flight past 2s says "Saving..." and carries aria-busy. htmx sets
  neither, so the wait up to its 15s timeout was silent in both channels.
- Titles clamp at 3 lines; .is-new .title takes width: fit-content, or
  -webkit-box stretches the ember underline past the text it sizes to.

/admin:
- Overview routes into Lanes when a lane is unhealthy, prefixes each figure
  with its column word on the phone layout that drops the thead, labels state
  cells for a screen reader, and has an empty state where the sites table
  assumed rows.
- The admin shell picks up the library's chrome: htmx 15s timeout, the shared
  #notice slot, #sr-announce, filter.js. admin.css follows the same pass.
- admin_render_test.go and card_render_test.go render the templates directly,
  so markup regressions in either surface fail without a browser.

Login:
- DISCORD_GUILD_NAME (optional) names the community on the login screen and
  in the refusal message, so a stranger knows which Discord to ask for an
  invite. Unset degrades to a generic label; neither form names the guild id.

Handlers:
- maxChapterNum (9999) bounds both typed-chapter paths. uiChapter and
  adminSeriesCorrectLatest each parsed a float64 with no ceiling, so a
  hand-rolled POST stored 1e308 and every later reader of that row inherited
  it. Matches the max on the card's chapter input.

go test ./... green.
This commit is contained in:
2026-08-27 23:05:40 +07:00
parent cddd16bcdc
commit af07314bb6
32 changed files with 1567 additions and 237 deletions
+60 -13
View File
@@ -3,6 +3,7 @@ package web
import (
"context"
"embed"
"fmt"
"html/template"
"io/fs"
"log"
@@ -29,6 +30,14 @@ var staticFS embed.FS
// RecentCount is how many series the "Continue reading" strip shows.
const RecentCount = 5
// maxChapterNum bounds a chapter number a Reader or the owner types. The
// number reaches the store as a float64, so without a ceiling a hand-rolled
// POST stores 1e308 and every later reader of that row — the poller's
// HasNewChapter comparison, the display string — inherits it. Matches the
// `max` on the card's chapter input; no real series is within three orders of
// magnitude of it.
const maxChapterNum = 9999
// Handler serves the browser UI: full pages at / and htmx fragments at /ui/.
// It is a separate handler from api.Handler because the two speak different
// representations (HTML versus JSON) to different clients under different auth.
@@ -109,7 +118,8 @@ func (v listView) ListURL(tab string) string {
// loginView is what the login template receives.
type loginView struct {
Error string
Error string
GuildName string
}
// New parses every template up front so a broken one kills the process at
@@ -243,7 +253,7 @@ func (h *Handler) render(w http.ResponseWriter, status int, name string, data an
func (h *Handler) index(w http.ResponseWriter, r *http.Request) {
readerID, ok := h.sessionReader(r)
if !ok {
h.render(w, http.StatusOK, "login", loginView{})
h.render(w, http.StatusOK, "login", loginView{GuildName: h.discord.GuildName})
return
}
view, err := h.buildListView(readerID, libOf(r.URL.Query().Get("lib")), r.URL.Query().Get("tab"))
@@ -418,12 +428,20 @@ func (h *Handler) refreshChrome(w http.ResponseWriter, r *http.Request) {
}
h.writeChromeOOB(w, view)
}
// writeAnnounceOOB appends a visually-hidden live region update out-of-band,
// so a successful mutation announces itself without moving focus.
func (h *Handler) writeAnnounceOOB(w http.ResponseWriter, msg string) {
fmt.Fprintf(w, `<div id="sr-announce" class="sr-only" role="status" aria-live="polite" aria-atomic="true" hx-swap-oob="true">%s</div>`, template.HTMLEscapeString(msg))
}
func (h *Handler) writeNoticeOOB(w http.ResponseWriter, msg string) {
fmt.Fprintf(w, `<p id="notice" class="notice" hx-swap-oob="true">%s</p>`, template.HTMLEscapeString(msg))
}
// renderLogin renders the login page with an error message, for refused or
// failed sign-ins. Every message is author-written text — nothing Discord
// supplied is ever interpolated into a page.
func (h *Handler) renderLogin(w http.ResponseWriter, status int, msg string) {
h.render(w, status, "login", loginView{Error: msg})
h.render(w, status, "login", loginView{Error: msg, GuildName: h.discord.GuildName})
}
// logout revokes the session row and clears the cookie in one step: the next
@@ -488,7 +506,14 @@ func (h *Handler) uiFavorite(w http.ResponseWriter, r *http.Request) {
}
b.Favorite = !b.Favorite
b.UpdatedAt = time.Now().UnixMilli()
msg := ""
if b.Favorite {
msg = fmt.Sprintf("Added %s to favourites", b.Title)
} else {
msg = fmt.Sprintf("Removed %s from favourites", b.Title)
}
h.saveAndRenderCard(w, r, b)
h.writeAnnounceOOB(w, msg)
}
// uiStatus moves a bookmark between the two lifecycle buckets. Finished is not
@@ -514,7 +539,14 @@ func (h *Handler) uiStatus(w http.ResponseWriter, r *http.Request) {
return
}
b.UpdatedAt = time.Now().UnixMilli()
msg := ""
if b.Status == store.StatusArchived {
msg = fmt.Sprintf("Archived %s", b.Title)
} else {
msg = fmt.Sprintf("Restored %s", b.Title)
}
h.saveAndRenderCard(w, r, b)
h.writeAnnounceOOB(w, msg)
}
// uiChapter forces the read chapter to a value the user typed.
@@ -539,8 +571,8 @@ func (h *Handler) uiChapter(w http.ResponseWriter, r *http.Request) {
}
raw := strings.TrimSpace(r.PostFormValue("chapter"))
num, err := strconv.ParseFloat(raw, 64)
if err != nil || num < 0 || math.IsNaN(num) || math.IsInf(num, 0) {
http.Error(w, "chapter must be a non-negative number", http.StatusBadRequest)
if err != nil || num < 0 || num > maxChapterNum || math.IsNaN(num) || math.IsInf(num, 0) {
http.Error(w, "chapter must be a non-negative number below 10000", http.StatusBadRequest)
return
}
@@ -550,27 +582,42 @@ func (h *Handler) uiChapter(w http.ResponseWriter, r *http.Request) {
b.LastChapterNum = num
}
b.UpdatedAt = time.Now().UnixMilli()
msg := fmt.Sprintf("Updated %s to chapter %s", b.Title, raw)
h.saveAndRenderCard(w, r, b)
h.writeAnnounceOOB(w, msg)
}
// uiDelete removes the row and answers with an empty body, which htmx swaps in
// place of the card — removing it from the page.
func (h *Handler) uiDelete(w http.ResponseWriter, r *http.Request) {
key := r.PathValue("key")
if key == "" {
http.Error(w, "missing key", http.StatusBadRequest)
b, ok := h.loadForMutation(w, r)
if !ok {
return
}
if err := h.store.Delete(readerOf(r), key); err != nil {
log.Printf("ui delete %q: %v", key, err)
if err := h.store.Delete(readerOf(r), b.Key); err != nil {
log.Printf("ui delete %q: %v", b.Key, err)
http.Error(w, "internal error", http.StatusInternalServerError)
return
}
w.Header().Set("Content-Type", "text/html; charset=utf-8")
w.WriteHeader(http.StatusOK)
// The empty body is what removes the card; the chrome still has to be told
// the library got smaller.
h.refreshChrome(w, r)
msg := fmt.Sprintf("Removed %s", b.Title)
h.writeAnnounceOOB(w, msg)
h.writeNoticeOOB(w, msg)
view, err := h.buildListView(readerOf(r), currentLib(r), currentTab(r))
if err != nil {
log.Printf("ui chrome: %v", err)
return
}
h.writeChromeOOB(w, view)
if len(view.Items) == 0 {
fmt.Fprint(w, `<main id="list" class="list" tabindex="-1" hx-swap-oob="true">`)
if err := h.tmpl.ExecuteTemplate(w, "list", view); err != nil {
log.Printf("render list oob: %v", err)
return
}
fmt.Fprint(w, `</main>`)
}
}
// installUserscript renders the bindmounted script with the acting Reader's