Offer the userscripts as a download for mobile Violentmonkey (#26) #35
Reference in New Issue
Block a user
Delete Branch "fix/mobile-userscript-download"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Violentmonkey on mobile Chromium does not intercept navigation to a
.user.jsURL, so the Install link only renders the script as text — the owner hit this on their phone after the cutover.?download=1on the same session-gated install endpoint setsContent-Disposition: attachment, so the file saves and can be added from Violentmonkey's own menu. The setup panel gains two Download links and a line of copy.The plain Install link stays inline deliberately: the updater polls the
/u/path and an attachment disposition there would break auto-update.TestInstallServesScriptWithCredentialnow asserts both halves, and that the downloaded copy still carries the Reader's own credential.No CSS change —
.setup-linksalready wraps; verified rendered at a 390px viewport.go test ./...green.The login gate called GET /guilds/{guild}/members/{user} — the Guild resource's Get Guild Member, which wants a Bot token and the application present in the guild. Handed a user Bearer token it answers 401, which discordMember reports as an error, so every sign-in rendered "Discord sign-in is unavailable right now" and nobody could get in. The endpoint guilds.members.read actually grants is Get Current User Guild Member, GET /users/@me/guilds/{guild}/member. Same single-guild question, same privacy property, and it takes the token we hold. #18 flagged this as verified from Discord's documentation but never from a live flow; it was wrong. The stub mirrored the implementation, so the suite could not see it. It now serves the OAuth path and answers the bot path 401 the way Discord does — without that, a regression falls through to 404 and reads as an ordinary "not a member" refusal instead of failing.