ebc7a546c5
Adds a password-gated browser UI for the bookmark list, served by the same Go
binary and container as the userscript API.
## What
- `GET /` — list page, or the login page when there is no session (200, no redirect).
- `POST /login`, `POST /logout` — stateless HMAC session cookie, 60-day Max-Age.
- `GET /ui/list?tab=all|fav`, `POST /ui/bookmarks/{key}/favorite`,
`POST /ui/bookmarks/{key}/chapter`, `DELETE /ui/bookmarks/{key}` — htmx fragments.
- `GET /static/*` — embedded `style.css`, `htmx.min.js`, `filter.js`.
Mobile-first dark CSS, 2–3 column grid at ≥900px, "Continue reading" strip of the
five most recent series, NEW badge, client-side title search, no build step.
## Stack
Go `html/template` + htmx 2.0.4 (vendored, 50 KB) + plain CSS. No npm, no bundler.
Templates and assets are `go:embed`-ed, so `CGO_ENABLED=0` and the distroless
image still hold.
## Auth
`WEB_PASSWORD` gates the UI; unset means the web routes are never registered and
`/` returns 404. Session cookie is `HttpOnly`, `SameSite=Lax`, `Secure` when the
request is HTTPS. The signing key derives from `API_TOKEN` + `WEB_PASSWORD`, so
rotating either logs every browser out. Login is rate-limited to 10 failures per
20 minutes per client IP, keyed on the **rightmost** `X-Forwarded-For` entry
(Traefik appends the observed peer, so the leftmost is client-spoofable). CGNAT
lockout is a known, accepted limitation — the window self-heals.
## Invariants preserved
- A session cookie never authenticates `/bookmarks*`. That API stays JSON +
bearer token, unchanged, as does the userscript.
- `Store.Upsert` is byte-for-byte unmodified. Every UI write goes
read-modify-write through the new `Store.Get`, so the conditional-`updated_at`
rule (favouriting must not reorder the list, a chapter override must) lives in
exactly one function.
## Deployment
`docker-compose.prod.yml` gains a second Traefik router on `MANGA_WEB_HOST`
pointing at the same service — one container, one certificate resolver, no second
service. Both `MANGA_API_HOST` and `MANGA_WEB_HOST` are required (`:?`), with no
example fallback in `.env.example`: a placeholder there would make Traefik
silently publish the UI on a domain you do not own. Needs a DNS A/AAAA record for
`manga.<domain>`. See `DEPLOY.md` §1b.
## Docs
- Design: `docs/superpowers/specs/2026-07-25-web-ui-design.md`
- Plan: `plans/2026-07-25-web-ui-implementation-plan.md`
## Verification
`gofmt` clean, `go vet`, `go test -race ./...`, `CGO_ENABLED=0 go build`, a real
`docker build` + curl smoke test, and a Playwright pass covering login
reject/accept, favourite-without-reorder, chapter edit, delete-with-confirm,
search, tab switch + back button, 390px with no horizontal overflow, and zero JS
console errors.
Reviewed-on: #1
Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com>
Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
189 lines
6.0 KiB
Go
189 lines
6.0 KiB
Go
package main
|
|
|
|
import (
|
|
"crypto/hmac"
|
|
"crypto/sha256"
|
|
"crypto/subtle"
|
|
"encoding/base64"
|
|
"net"
|
|
"net/http"
|
|
"strconv"
|
|
"strings"
|
|
"sync"
|
|
"time"
|
|
)
|
|
|
|
const (
|
|
sessionCookieName = "mangabm_session"
|
|
// 60 days: long enough that a phone stays logged in between reading spells.
|
|
sessionTTL = 60 * 24 * time.Hour
|
|
// Domain separation, so the session key can never collide with any other
|
|
// use of the secrets it is derived from. Changing this string logs
|
|
// everyone out.
|
|
sessionKeyPurpose = "mangabm-web-session-v1"
|
|
)
|
|
|
|
// sessionKey derives the cookie-signing key from both secrets. Sessions are
|
|
// stateless — there is no session table — so rotating either API_TOKEN or
|
|
// WEB_PASSWORD invalidates every outstanding cookie at once. The \x00
|
|
// separator prevents the concatenation ambiguity a bare apiToken+webPassword
|
|
// would have (e.g. "ab"+"c" colliding with "a"+"bc").
|
|
func sessionKey(apiToken, webPassword string) []byte {
|
|
sum := sha256.Sum256([]byte(apiToken + "\x00" + webPassword + sessionKeyPurpose))
|
|
return sum[:]
|
|
}
|
|
|
|
// signSession encodes "<expiryMs>.<base64url HMAC(expiryMs)>".
|
|
func signSession(key []byte, expiryMs int64) string {
|
|
payload := strconv.FormatInt(expiryMs, 10)
|
|
return payload + "." + sessionMAC(key, payload)
|
|
}
|
|
|
|
func sessionMAC(key []byte, payload string) string {
|
|
mac := hmac.New(sha256.New, key)
|
|
mac.Write([]byte(payload))
|
|
return base64.RawURLEncoding.EncodeToString(mac.Sum(nil))
|
|
}
|
|
|
|
// verifySession checks shape, then expiry, then the signature — in that order.
|
|
// The signature comparison is constant-time; the checks before it only look at
|
|
// data the holder already supplied, so their timing leaks nothing.
|
|
func verifySession(key []byte, value string, nowMs int64) bool {
|
|
payload, sig, ok := strings.Cut(value, ".")
|
|
if !ok {
|
|
return false
|
|
}
|
|
expiry, err := strconv.ParseInt(payload, 10, 64)
|
|
if err != nil || expiry <= nowMs {
|
|
return false
|
|
}
|
|
want := sessionMAC(key, payload)
|
|
return subtle.ConstantTimeCompare([]byte(sig), []byte(want)) == 1
|
|
}
|
|
|
|
// isHTTPS reports whether the browser's connection is encrypted. Behind Traefik
|
|
// the Go server itself speaks plain HTTP, so the forwarded header is the only
|
|
// signal; without this check the Secure cookie would never be set in
|
|
// production, and setting it unconditionally would break http://localhost dev.
|
|
func isHTTPS(r *http.Request) bool {
|
|
return r.TLS != nil || r.Header.Get("X-Forwarded-Proto") == "https"
|
|
}
|
|
|
|
func setSessionCookie(w http.ResponseWriter, r *http.Request, key []byte) {
|
|
http.SetCookie(w, &http.Cookie{
|
|
Name: sessionCookieName,
|
|
Value: signSession(key, time.Now().Add(sessionTTL).UnixMilli()),
|
|
Path: "/",
|
|
MaxAge: int(sessionTTL / time.Second),
|
|
HttpOnly: true,
|
|
Secure: isHTTPS(r),
|
|
SameSite: http.SameSiteLaxMode,
|
|
})
|
|
}
|
|
|
|
func clearSessionCookie(w http.ResponseWriter, r *http.Request) {
|
|
http.SetCookie(w, &http.Cookie{
|
|
Name: sessionCookieName,
|
|
Value: "",
|
|
Path: "/",
|
|
MaxAge: -1,
|
|
HttpOnly: true,
|
|
Secure: isHTTPS(r),
|
|
SameSite: http.SameSiteLaxMode,
|
|
})
|
|
}
|
|
|
|
const (
|
|
loginMaxFailures = 10
|
|
loginWindow = 20 * time.Minute
|
|
)
|
|
|
|
// clientIP returns the address the reverse proxy actually observed.
|
|
//
|
|
// Traefik appends the peer address to whatever X-Forwarded-For the client sent,
|
|
// so the leftmost entry is attacker-controlled and the rightmost is not. Go's
|
|
// Header.Get would only read the first header line, which a client can preempt
|
|
// by sending its own; Values covers every line so the true last hop is found.
|
|
// RemoteAddr is useless behind the proxy — it is always the Traefik container —
|
|
// so it serves only as the direct-connection fallback for local development.
|
|
func clientIP(r *http.Request) string {
|
|
if vals := r.Header.Values("X-Forwarded-For"); len(vals) > 0 {
|
|
hops := strings.Split(vals[len(vals)-1], ",")
|
|
if ip := strings.TrimSpace(hops[len(hops)-1]); ip != "" {
|
|
return ip
|
|
}
|
|
}
|
|
host, _, err := net.SplitHostPort(r.RemoteAddr)
|
|
if err != nil {
|
|
return r.RemoteAddr
|
|
}
|
|
return host
|
|
}
|
|
|
|
// loginLimiter throttles password guessing: loginMaxFailures failures inside a
|
|
// rolling loginWindow blocks further attempts from that IP until the oldest one
|
|
// ages out. There is no permanent ban and no unlock step.
|
|
//
|
|
// Behind carrier-grade NAT this budget is shared with every other subscriber on
|
|
// the same public address, so a stranger can lock the owner out for up to one
|
|
// window. That is accepted: the block self-heals, and ten attempts is generous
|
|
// for a mistyped password.
|
|
//
|
|
// State is in memory and per-process, so a restart clears it. Entries are
|
|
// pruned lazily on access; for a single-user deployment the map cannot grow
|
|
// past the handful of addresses that ever attempt a login.
|
|
type loginLimiter struct {
|
|
mu sync.Mutex
|
|
failures map[string][]time.Time
|
|
}
|
|
|
|
func newLoginLimiter() *loginLimiter {
|
|
return &loginLimiter{failures: make(map[string][]time.Time)}
|
|
}
|
|
|
|
// retryAfter returns how long ip must wait, or zero when it may try now.
|
|
func (l *loginLimiter) retryAfter(ip string, now time.Time) time.Duration {
|
|
l.mu.Lock()
|
|
defer l.mu.Unlock()
|
|
|
|
recent := l.pruneLocked(ip, now)
|
|
if len(recent) < loginMaxFailures {
|
|
return 0
|
|
}
|
|
return recent[0].Add(loginWindow).Sub(now)
|
|
}
|
|
|
|
func (l *loginLimiter) fail(ip string, now time.Time) {
|
|
l.mu.Lock()
|
|
defer l.mu.Unlock()
|
|
l.failures[ip] = append(l.pruneLocked(ip, now), now)
|
|
}
|
|
|
|
func (l *loginLimiter) reset(ip string) {
|
|
l.mu.Lock()
|
|
defer l.mu.Unlock()
|
|
delete(l.failures, ip)
|
|
}
|
|
|
|
// pruneLocked drops attempts older than the window and returns what is left.
|
|
// The caller must hold l.mu.
|
|
func (l *loginLimiter) pruneLocked(ip string, now time.Time) []time.Time {
|
|
cutoff := now.Add(-loginWindow)
|
|
// In-place filter: kept reuses the backing array of the slice being
|
|
// ranged over. Safe to alias because append writes at index len(kept),
|
|
// which is always <= the range index i, and element i is read before
|
|
// that write — the write cursor can never overtake the read cursor.
|
|
kept := l.failures[ip][:0]
|
|
for _, at := range l.failures[ip] {
|
|
if at.After(cutoff) {
|
|
kept = append(kept, at)
|
|
}
|
|
}
|
|
if len(kept) == 0 {
|
|
delete(l.failures, ip)
|
|
return nil
|
|
}
|
|
l.failures[ip] = kept
|
|
return kept
|
|
}
|