Final-review fix wave over the web UI branch.
- sessionKey now derives from API_TOKEN and WEB_PASSWORD with a \x00
separator, so rotating the password logs every browser out too.
- uiChapter only clears last_chapter_url when the number actually
changes. The form is pre-filled, so a bare tap of Save resubmits the
same value; that used to destroy the chapter URL silently while
updated_at stayed put, degrading Continue to the series index page.
- MANGA_WEB_HOST is now required by the prod override rather than
falling back to manga.example.com, matching MANGA_API_HOST.
- Comment fixes: static cache rationale, pruneLocked aliasing
invariant, and the stale "3 routes" line in CLAUDE.md.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Fix backend/Dockerfile to COPY templates/ and static/ (the go:embed
assets from Tasks 5-7) alongside *.go, plus backend/.dockerignore which
was silently excluding both directories from the build context — the
Dockerfile fix alone still failed the build. Wire WEB_PASSWORD through
docker-compose.yml, add a second Traefik router (mangaweb) plus explicit
service labels on both routers in docker-compose.prod.yml, and document
the new variables and deploy steps in .env.example, DEPLOY.md, and
CLAUDE.md.
Documents why updated_at moves only on reading progress and why PUT therefore
returns the stored row, why "latest chapter" is found from the browser rather
than the backend, and its limits — a bookmark is as current as its last check,
and nothing here can be instant.
Also corrects two stale claims: asurascans.com is the current domain, and
asuracomic.net deep links now 301 to its root rather than the matching path.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Ignore graphify-out/ (local graph data) and document query/update
workflow in CLAUDE.md for future codebase questions.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>