chore: drop asuracomic.net from the userscript, CORS allowlist and docs #97
Reference in New Issue
Block a user
Delete Branch "ticket/96-drop-asuracomic"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #96.
What
Removes every reference that still invites a Reader onto
asuracomic.net.The domain's deep links 301 to the
asurascans.comroot, discarding thepath (re-checked 2026-07-25), so a page on it never yields a series document
client-side and a stored address on it never yields a series page server-side.
#95 already pinned each Site to one hostname, so the backend rejects such an
address cleanly; this is the cleanup around that.
userscript/manga-bookmark.user.js@match, narrows the asura adapter to/(^|\.)asurascans\.com$/userscript/test/logic.test.js.env.example,docker-compose.ymlALLOWED_ORIGINSdefaultDEPLOY.mdbackend/api_test.goasurascans.comREADME.md,AGENTS.mdBehaviour
asuracomic.netgets no userscript UI. Previously thescript loaded and could do nothing useful — the redirect had already
discarded the path.
Originishttps://asuracomic.netis no longer reflectedby a deployment using the shipped defaults.
untouched.
AllowedOriginsis data, not code.Security invariant preserved
CORS still reflects
Originonly when it appears inALLOWED_ORIGINS, withGET,PUT,DELETE,OPTIONSand a204preflight —TestCORSPreflightandTestCORSDisallowedOriginstill pin both halves, now against a live origin.This change only removes a value from the allowlist, which is a narrowing.
Verification
go test ./...— full backend suite green (real Postgres per package).node --test test/*.test.js— 66/66 green, up one from the new match test.Deploy note (does not happen on merge)
The live allowlist comes from the VPS
.env, not from these defaults, so theorigin must be dropped there in the same deploy. The one-off row repair for any
stored
asuracomic.netaddress is in #96.