fix: keep MANGA_WEB_HOST unset in .env.example and make no-op saves inert

Re-review of the fix wave found the .env.example edit defeated the fix
it belonged to: shipping MANGA_WEB_HOST=manga.example.com re-supplied
the value that ${MANGA_WEB_HOST:?} exists to reject, so a fresh
`cp .env.example .env` started fine and Traefik published the UI router
on a domain the operator does not own. Left commented, matching
MANGA_API_HOST; DEPLOY.md 1 now lists it among the required variables.

Also:
- uiChapter leaves last_chapter too, not only last_chapter_url, when the
  submitted number is unchanged. It used to rewrite the display string
  ("45.0" to "45") behind a frozen updated_at.
- Design spec 4.2 documents the two-secret key derivation.
- Corrected the pruneLocked aliasing rationale and the stale
  sessionKeyPurpose comment.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-26 03:27:31 +07:00
parent 22bf68f12f
commit edae491161
6 changed files with 41 additions and 23 deletions
+6 -4
View File
@@ -23,7 +23,9 @@ ALLOWED_ORIGINS=https://asuracomic.net,https://asurascans.com,https://demonicsca
# Generate one: openssl rand -base64 18
WEB_PASSWORD=
# Subdomain Traefik routes to the browser UI (required by the prod override
# whenever the web UI is enabled). The same container also answers on
# MANGA_API_HOST for the userscript's API.
MANGA_WEB_HOST=manga.example.com
# Subdomain Traefik routes to the browser UI (required by the prod override,
# whether or not WEB_PASSWORD is set). Left commented on purpose: an example
# value here would be a silent wrong-hostname fallback, and Traefik would
# publish the UI router on a domain you do not own. The same container also
# answers on MANGA_API_HOST for the userscript's API.
# MANGA_WEB_HOST=manga.example.com