chore: drop asuracomic.net from the userscript, CORS allowlist and docs (#97)
Closes #96. ## What Removes every reference that still invites a Reader onto `asuracomic.net`. The domain's deep links 301 to the `asurascans.com` **root**, discarding the path (re-checked 2026-07-25), so a page on it never yields a series document client-side and a stored address on it never yields a series page server-side. #95 already pinned each Site to one hostname, so the backend rejects such an address cleanly; this is the cleanup around that. | File | Change | |---|---| | `userscript/manga-bookmark.user.js` | drops the `@match`, narrows the asura adapter to `/(^\|\.)asurascans\.com$/` | | `userscript/test/logic.test.js` | new test pinning the narrowed host match | | `.env.example`, `docker-compose.yml` | origin dropped from the `ALLOWED_ORIGINS` default | | `DEPLOY.md` | same, and the sample list gains the two novel origins it was missing | | `backend/api_test.go` | CORS fixtures and round-trip seed move to `asurascans.com` | | `README.md`, `AGENTS.md` | notes say the host is dropped, not "stays matched" | ## Behaviour - A Reader landing on `asuracomic.net` gets no userscript UI. Previously the script loaded and could do nothing useful — the redirect had already discarded the path. - A request whose `Origin` is `https://asuracomic.net` is no longer reflected by a deployment using the shipped defaults. - No backend logic changed: the CORS rule, the address gate and the poller are untouched. `AllowedOrigins` is data, not code. ## Security invariant preserved CORS still reflects `Origin` only when it appears in `ALLOWED_ORIGINS`, with `GET,PUT,DELETE,OPTIONS` and a `204` preflight — `TestCORSPreflight` and `TestCORSDisallowedOrigin` still pin both halves, now against a live origin. This change only removes a value from the allowlist, which is a narrowing. ## Verification - `go test ./...` — full backend suite green (real Postgres per package). - `node --test test/*.test.js` — 66/66 green, up one from the new match test. ## Deploy note (does not happen on merge) The live allowlist comes from the VPS `.env`, not from these defaults, so the origin must be dropped there in the same deploy. The one-off row repair for any stored `asuracomic.net` address is in #96. Reviewed-on: #97 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
This commit was merged in pull request #97.
This commit is contained in:
+22
-22
@@ -35,9 +35,9 @@
|
||||
"semantic_hash": "4a94ac85bad6bce330d085bcc0ae3ffd"
|
||||
},
|
||||
"userscript/manga-bookmark.user.js": {
|
||||
"mtime": 1786363889.5678573,
|
||||
"ast_hash": "de4abcf9e0f099fb82b630d443db739f",
|
||||
"semantic_hash": "de4abcf9e0f099fb82b630d443db739f"
|
||||
"mtime": 1786488438.9080842,
|
||||
"ast_hash": "1f8bcddd3632d709f058a8401af8f127",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
".agents/skills/find-skills/SKILL.md": {
|
||||
"mtime": 1784884338.760326,
|
||||
@@ -140,19 +140,19 @@
|
||||
"semantic_hash": "3a08979e4603aae5c32a58d5b6c39765"
|
||||
},
|
||||
"CLAUDE.md": {
|
||||
"mtime": 1786446007.0443642,
|
||||
"ast_hash": "8f79ab45cb9c6466da7c4b65f0bceadf",
|
||||
"mtime": 1786488493.5922732,
|
||||
"ast_hash": "7362a25f37333a2a6a55a5aeccf9b0cb",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
"DEPLOY.md": {
|
||||
"mtime": 1786363889.552731,
|
||||
"ast_hash": "7fa7bb75239f8ad3798e44c12dce374c",
|
||||
"semantic_hash": "7fa7bb75239f8ad3798e44c12dce374c"
|
||||
"mtime": 1786488464.5532806,
|
||||
"ast_hash": "2b7b537aa1c0954400c19acc4b634029",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
"README.md": {
|
||||
"mtime": 1786363889.552731,
|
||||
"ast_hash": "bb33ecb93e23c8f039049aec75217263",
|
||||
"semantic_hash": "bb33ecb93e23c8f039049aec75217263"
|
||||
"mtime": 1786488487.8305292,
|
||||
"ast_hash": "9d6be8aa8a2946c23ad48d8f2864b5ca",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
"docker-compose.prod.yml": {
|
||||
"mtime": 1786292465.8305523,
|
||||
@@ -160,9 +160,9 @@
|
||||
"semantic_hash": "0751998a532297b8ac507a01ec48dc31"
|
||||
},
|
||||
"docker-compose.yml": {
|
||||
"mtime": 1786363889.5678573,
|
||||
"ast_hash": "d9a58147a573517afa4603b41cf55ca8",
|
||||
"semantic_hash": "d9a58147a573517afa4603b41cf55ca8"
|
||||
"mtime": 1786488450.3508112,
|
||||
"ast_hash": "124fd581bf0a662ff15012abfdb40a92",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
".claude/settings.json": {
|
||||
"mtime": 1784951973.1869545,
|
||||
@@ -200,14 +200,14 @@
|
||||
"semantic_hash": "e69a8340a371579ca3ea689660f7d7bd"
|
||||
},
|
||||
"AGENTS.md": {
|
||||
"mtime": 1786446007.0443642,
|
||||
"ast_hash": "8f79ab45cb9c6466da7c4b65f0bceadf",
|
||||
"mtime": 1786488493.5922732,
|
||||
"ast_hash": "7362a25f37333a2a6a55a5aeccf9b0cb",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
"userscript/test/logic.test.js": {
|
||||
"mtime": 1786363889.5716388,
|
||||
"ast_hash": "03b5c6c93786c55ac771fd79fd4a75bb",
|
||||
"semantic_hash": "03b5c6c93786c55ac771fd79fd4a75bb"
|
||||
"mtime": 1786488563.581765,
|
||||
"ast_hash": "80d512bfe6fa8b847f3ba6169c321a74",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
".claude/skills/testing-the-userscript/SKILL.md": {
|
||||
"mtime": 1786363889.5489495,
|
||||
@@ -225,9 +225,9 @@
|
||||
"semantic_hash": "421cd7e57f02d4b467f120ca6ddd7b6a"
|
||||
},
|
||||
"backend/api_test.go": {
|
||||
"mtime": 1786363889.552731,
|
||||
"ast_hash": "3fbe8423060efbc34517901dce44e9b5",
|
||||
"semantic_hash": "3fbe8423060efbc34517901dce44e9b5"
|
||||
"mtime": 1786488480.637822,
|
||||
"ast_hash": "8e4b9293bc2e45ee3f42027315594fd5",
|
||||
"semantic_hash": ""
|
||||
},
|
||||
"backend/cover_test.go": {
|
||||
"mtime": 1786363889.552731,
|
||||
|
||||
Reference in New Issue
Block a user