fix: address code review on #27
- The empty state is about an empty library, not a brand-new Reader:
listView.Fresh becomes EmptyLibrary and moves behind the tab-specific
branches, so "No favourites yet" is no longer shadowed for a Reader whose
library happens to be empty. The action key stays put — hiding it was
never asked for.
- The owner is not a revocable Reader: their row offers no button and
POST /readers/{owner}/revoke is a 404, so the one row where the control
would sign out the tapping browser cannot be reached by a hand-rolled
POST either.
- Modify isolation is asserted in both directions, and the owner's own
sign-in through the OAuth callback is pinned to the seeded row.
- CUTOVER.md and REDEPLOY.md still grepped API_TOKEN out of .env for their
smoke tests, which the last commit deleted; both now take the acting
Reader's derived credential.
- Roster type follows the machine-fact spec (500 10-11px mono, tracked),
and PRODUCT.md names the Readers panel instead of claiming there is no
owner surface at all.
This commit is contained in:
+4
-3
@@ -231,9 +231,10 @@ Same four API checks as `DEPLOY.md` §3, plus the web UI. Set the host names onc
|
||||
```bash
|
||||
API=https://bookmark-api.violetcrown.my.id
|
||||
WEB=https://bookmark.violetcrown.my.id
|
||||
# During the grace window the retired global credential still resolves to the
|
||||
# owner; afterwards it is 401 like any other wrong credential.
|
||||
TOKEN=$(grep -E '^API_TOKEN=' .env | cut -d= -f2)
|
||||
# Your own Reader credential - derived, never stored in .env. Take it from the
|
||||
# Userscripts panel's install link after signing in, or from an installed
|
||||
# script's API_TOKEN constant.
|
||||
TOKEN=<your Reader credential>
|
||||
|
||||
curl -s $API/healthz # -> ok
|
||||
curl -s -o /dev/null -w '%{http_code}\n' $API/bookmarks # -> 401
|
||||
|
||||
Reference in New Issue
Block a user