Serve the userscript from the backend; card + loading fixes #8

Merged
sulthan merged 6 commits from userscript-download-url into main 2026-07-28 18:28:28 +07:00

6 Commits

Author SHA1 Message Date
sulthan 16e7dce814 docs: add testing-the-userscript project skill
Documents the Node stub harness in userscript/test/logic.test.js: the four
globals it installs, why document.body is left undefined, the module.exports
test hook, and what is deliberately not testable (no DOM harness).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-28 18:13:13 +07:00
sulthan 91090d4b2f docs: document the userscript endpoint and its metadata lines
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-28 18:05:09 +07:00
sulthan d8fa9b651c fix(userscript): show a spinner while the first fetch is in flight
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-28 17:57:49 +07:00
sulthan d2916d4403 fix(userscript): put card actions under the subtitle
Only the cover and title continue reading now; the action row is a sibling
of the subtitle inside the text column instead of a full-width row below
the whole card.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-28 17:54:49 +07:00
sulthan 4a0950e1ca feat: bindmount userscript and point Violentmonkey at the backend
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-28 17:50:39 +07:00
sulthan 9280542b33 feat(backend): serve userscript at token-protected path
Reads the file per request from USERSCRIPT_PATH and rewrites its @version
to an mtime-derived value, so Violentmonkey always sees a higher version
after an edit regardless of what the file body claims. Also guards against
ServeMux's own path-cleaning redirect turning an empty {token} segment into
a 307 instead of the required 404.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-28 17:45:59 +07:00