Define Cover and record hosting its bytes (#47) #64
Reference in New Issue
Block a user
Delete Branch "docs/cover-ownership"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Defines Cover in the glossary and records ADR-0007, the decision behind #47's fix.
Why these two files, and why now
CONTEXT.mdnamed Cover inside the Series entry — "facts true regardless of who is reading — title, cover, Latest Chapter" — but never said what one is. That gap is the bug. Nothing in the model distinguished "an address on a Site" from "an image a Reader's browser can display", so both clients were left to work it out independently, and one of them got it wrong. kagane serves covers withcross-origin-resource-policy: same-origin, the web UI rewrote them to a proxy in its templates, the JSON API did not, and the panel rendered a broken-image glyph. The new entry closes the ambiguity: an address no client can load is not a Cover, it is a missing one.ADR-0007 records what follows from that — the backend fetches, stores and serves every Site's cover bytes — plus the alternatives that were rejected and, more importantly, the two places this deliberately departs from existing precedent:
fetchableSeriesURLsets the allowlist precedent forseries_url, and covers do not follow it. Cover hosts are CDNs that move independently of their Site — demonicscans serves its covers fromreadermc.org— so an allowlist would stop producing Covers the day a Site switched CDN, and that failure would look exactly like #47. The resolve-then-classify step is what actually stops the SSRF.<img>cannot send a bearer token, and it cannot be given one either: the panel's shadow root ismode: "open", so the host page's JavaScript can read anysrcthe script sets.Both are security-adjacent departures, which is precisely why they are written down rather than left in a commit message.
Scope
Documentation only — no code, no schema, no behaviour. The implementation is #56–#63.
Why this should merge promptly rather than sit
All eight implementation tickets cite
docs/adr/0007-backend-hosts-cover-bytes.mdas the authority for decisions they must not relitigate, and they are written in the vocabulary this glossary entry defines. An agent picking up #56 reads both frommain. Until this lands they get a 404 and either invent a rationale or stall — so this PR gates the tickets, not the other way round.Related: #47 (bug), #55 (spec), #54 (deferred admin refetch).