chore: drop asuracomic.net from the userscript, CORS allowlist and docs #97

Merged
sulthan merged 2 commits from ticket/96-drop-asuracomic into main 2026-08-12 05:53:18 +07:00
Owner

Closes #96.

What

Removes every reference that still invites a Reader onto asuracomic.net.
The domain's deep links 301 to the asurascans.com root, discarding the
path (re-checked 2026-07-25), so a page on it never yields a series document
client-side and a stored address on it never yields a series page server-side.
#95 already pinned each Site to one hostname, so the backend rejects such an
address cleanly; this is the cleanup around that.

File Change
userscript/manga-bookmark.user.js drops the @match, narrows the asura adapter to /(^|\.)asurascans\.com$/
userscript/test/logic.test.js new test pinning the narrowed host match
.env.example, docker-compose.yml origin dropped from the ALLOWED_ORIGINS default
DEPLOY.md same, and the sample list gains the two novel origins it was missing
backend/api_test.go CORS fixtures and round-trip seed move to asurascans.com
README.md, AGENTS.md notes say the host is dropped, not "stays matched"

Behaviour

  • A Reader landing on asuracomic.net gets no userscript UI. Previously the
    script loaded and could do nothing useful — the redirect had already
    discarded the path.
  • A request whose Origin is https://asuracomic.net is no longer reflected
    by a deployment using the shipped defaults.
  • No backend logic changed: the CORS rule, the address gate and the poller are
    untouched. AllowedOrigins is data, not code.

Security invariant preserved

CORS still reflects Origin only when it appears in ALLOWED_ORIGINS, with
GET,PUT,DELETE,OPTIONS and a 204 preflight — TestCORSPreflight and
TestCORSDisallowedOrigin still pin both halves, now against a live origin.
This change only removes a value from the allowlist, which is a narrowing.

Verification

  • go test ./... — full backend suite green (real Postgres per package).
  • node --test test/*.test.js — 66/66 green, up one from the new match test.

Deploy note (does not happen on merge)

The live allowlist comes from the VPS .env, not from these defaults, so the
origin must be dropped there in the same deploy. The one-off row repair for any
stored asuracomic.net address is in #96.

Closes #96. ## What Removes every reference that still invites a Reader onto `asuracomic.net`. The domain's deep links 301 to the `asurascans.com` **root**, discarding the path (re-checked 2026-07-25), so a page on it never yields a series document client-side and a stored address on it never yields a series page server-side. #95 already pinned each Site to one hostname, so the backend rejects such an address cleanly; this is the cleanup around that. | File | Change | |---|---| | `userscript/manga-bookmark.user.js` | drops the `@match`, narrows the asura adapter to `/(^\|\.)asurascans\.com$/` | | `userscript/test/logic.test.js` | new test pinning the narrowed host match | | `.env.example`, `docker-compose.yml` | origin dropped from the `ALLOWED_ORIGINS` default | | `DEPLOY.md` | same, and the sample list gains the two novel origins it was missing | | `backend/api_test.go` | CORS fixtures and round-trip seed move to `asurascans.com` | | `README.md`, `AGENTS.md` | notes say the host is dropped, not "stays matched" | ## Behaviour - A Reader landing on `asuracomic.net` gets no userscript UI. Previously the script loaded and could do nothing useful — the redirect had already discarded the path. - A request whose `Origin` is `https://asuracomic.net` is no longer reflected by a deployment using the shipped defaults. - No backend logic changed: the CORS rule, the address gate and the poller are untouched. `AllowedOrigins` is data, not code. ## Security invariant preserved CORS still reflects `Origin` only when it appears in `ALLOWED_ORIGINS`, with `GET,PUT,DELETE,OPTIONS` and a `204` preflight — `TestCORSPreflight` and `TestCORSDisallowedOrigin` still pin both halves, now against a live origin. This change only removes a value from the allowlist, which is a narrowing. ## Verification - `go test ./...` — full backend suite green (real Postgres per package). - `node --test test/*.test.js` — 66/66 green, up one from the new match test. ## Deploy note (does not happen on merge) The live allowlist comes from the VPS `.env`, not from these defaults, so the origin must be dropped there in the same deploy. The one-off row repair for any stored `asuracomic.net` address is in #96.
sulthan added 2 commits 2026-08-12 05:50:11 +07:00
The old domain's deep links 301 to the asurascans.com root, discarding the
path, so a page on it never yields a series document and a stored address on
it never yields a series page. #94 pinned each Site to one hostname, which
already rejects such an address server-side; this removes the remaining
references so nothing invites a Reader onto the dead host.

Live deploys still carry the origin in their own .env and must drop it there
too - the allowlist is read from the environment, not from these defaults.
sulthan merged commit c62c3bb07b into main 2026-08-12 05:53:18 +07:00
Sign in to join this conversation.