Serve the userscript from the backend; card + loading fixes #8
Reference in New Issue
Block a user
Delete Branch "userscript-download-url"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Serves the userscript from the backend so Violentmonkey auto-updates it, plus two panel fixes.
Backend:
GET /u/{token}/manga-bookmark.user.jsThe script is read off disk per request from
USERSCRIPT_PATHand streamed back with its@versionline rewritten.Authorizationheader, and the script embedsAPI_TOKENin plain text — an open URL would hand that token to anyone who guessed it. Compare is constant-time.withAuthand outside theWEB_PASSWORDgate, so the script is installable on a deployment that never enabled the web UI.crypto/subtle,os,regexp) — no new Go dependencies.The served
@versionis derived from the file's mtime (YYYY.MM.DD.HHMM, UTC), discarding whatever the file body says. Violentmonkey only updates when the served version sorts higher than the installed one, so a body-derived version means one typo or accidental downgrade freezes updates forever. An mtime-derived version is monotonic by construction. A file with no@versionline is served byte-identical.os.Statruns beforeos.ReadFile, so a concurrent edit can only serve new content under an old stamp — which self-heals on the next poll — never the reverse.Bindmount
./userscriptis bindmounted read-only at/userscript. The script is deliberately not copied into the image: the build context stays./backend, and widening it would churn everyCOPYpath for a file the mount always supplies. Editing the file on the VPS is live on the next poll — no rebuild, no restart.git pullrestores the committed version, so a redeploy always ships the repo's script; checkout sets mtime to now, so even a rollback serves a higher version and is adopted. Without the mount the endpoint 404s and logs it; bookmark sync is unaffected.@downloadURL/@updateURLare literal URLs in the metadata block — it is parsed before any JS runs, soAPI_BASE/API_TOKENcannot be interpolated. The token was already committed in this file, so this adds no new exposure.Userscript UI
Verification
go test -count=1 ./...— ok, 7.070snode --checkclean;node --test userscript/test/logic.test.js— 14/14docker composesmoke:/healthz200, wrong token 404, script served with a stamped@version 2026.07.28.1057and both metadata URLs present;touching the file advanced the served version to2026.07.28.1100with no restart.Layout and spinner are verified on-device — there is deliberately no DOM test harness.
Reads the file per request from USERSCRIPT_PATH and rewrites its @version to an mtime-derived value, so Violentmonkey always sees a higher version after an edit regardless of what the file body claims. Also guards against ServeMux's own path-cleaning redirect turning an empty {token} segment into a 307 instead of the required 404. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>