fix: address code review on #27

- The empty state is about an empty library, not a brand-new Reader:
  listView.Fresh becomes EmptyLibrary and moves behind the tab-specific
  branches, so "No favourites yet" is no longer shadowed for a Reader whose
  library happens to be empty. The action key stays put — hiding it was
  never asked for.
- The owner is not a revocable Reader: their row offers no button and
  POST /readers/{owner}/revoke is a 404, so the one row where the control
  would sign out the tapping browser cannot be reached by a hand-rolled
  POST either.
- Modify isolation is asserted in both directions, and the owner's own
  sign-in through the OAuth callback is pinned to the seeded row.
- CUTOVER.md and REDEPLOY.md still grepped API_TOKEN out of .env for their
  smoke tests, which the last commit deleted; both now take the acting
  Reader's derived credential.
- Roster type follows the machine-fact spec (500 10-11px mono, tracked),
  and PRODUCT.md names the Readers panel instead of claiming there is no
  owner surface at all.
This commit is contained in:
2026-08-08 20:14:21 +07:00
parent b0bf6fe770
commit f4f6c9c9e9
10 changed files with 115 additions and 40 deletions
+4 -3
View File
@@ -231,9 +231,10 @@ Same four API checks as `DEPLOY.md` §3, plus the web UI. Set the host names onc
```bash
API=https://bookmark-api.violetcrown.my.id
WEB=https://bookmark.violetcrown.my.id
# During the grace window the retired global credential still resolves to the
# owner; afterwards it is 401 like any other wrong credential.
TOKEN=$(grep -E '^API_TOKEN=' .env | cut -d= -f2)
# Your own Reader credential - derived, never stored in .env. Take it from the
# Userscripts panel's install link after signing in, or from an installed
# script's API_TOKEN constant.
TOKEN=<your Reader credential>
curl -s $API/healthz # -> ok
curl -s -o /dev/null -w '%{http_code}\n' $API/bookmarks # -> 401