fix: keep MANGA_WEB_HOST unset in .env.example and make no-op saves inert

Re-review of the fix wave found the .env.example edit defeated the fix
it belonged to: shipping MANGA_WEB_HOST=manga.example.com re-supplied
the value that ${MANGA_WEB_HOST:?} exists to reject, so a fresh
`cp .env.example .env` started fine and Traefik published the UI router
on a domain the operator does not own. Left commented, matching
MANGA_API_HOST; DEPLOY.md 1 now lists it among the required variables.

Also:
- uiChapter leaves last_chapter too, not only last_chapter_url, when the
  submitted number is unchanged. It used to rewrite the display string
  ("45.0" to "45") behind a frozen updated_at.
- Design spec 4.2 documents the two-secret key derivation.
- Corrected the pruneLocked aliasing rationale and the stale
  sessionKeyPurpose comment.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-26 03:27:31 +07:00
parent 22bf68f12f
commit edae491161
6 changed files with 41 additions and 23 deletions
+11 -8
View File
@@ -254,12 +254,15 @@ func (h *webHandler) uiFavorite(w http.ResponseWriter, r *http.Request) {
// uiChapter forces the read chapter to a value the user typed.
//
// When that value actually changes the number, it also clears last_chapter_url:
// that URL points at the chapter actually read, and once the number is forced
// elsewhere it would send the reader backwards. ContinueURL then falls back to
// the series page, which is always right. Resubmitting the same number — the
// form is pre-filled, so a bare tap of Save is an easy accidental submit —
// leaves last_chapter_url untouched instead of destroying it for no reason.
// Writing the number also clears last_chapter_url: that URL points at the
// chapter actually read, and once the number is forced elsewhere it would send
// the reader backwards. ContinueURL then falls back to the series page, which
// is always right.
//
// A submit that does not change the number touches nothing. The form is
// pre-filled, so a bare tap of Save is an easy accidental submit; it must not
// destroy last_chapter_url, nor rewrite the last_chapter display string ("45.0"
// to "45") behind a frozen updated_at.
func (h *webHandler) uiChapter(w http.ResponseWriter, r *http.Request) {
b, ok := h.loadForMutation(w, r)
if !ok {
@@ -278,9 +281,9 @@ func (h *webHandler) uiChapter(w http.ResponseWriter, r *http.Request) {
if num != b.LastChapterNum {
b.LastChapterURL = ""
b.LastChapter = raw
b.LastChapterNum = num
}
b.LastChapter = raw
b.LastChapterNum = num
b.UpdatedAt = time.Now().UnixMilli()
h.saveAndRenderCard(w, b)
}