22bf68f12f
Final-review fix wave over the web UI branch. - sessionKey now derives from API_TOKEN and WEB_PASSWORD with a \x00 separator, so rotating the password logs every browser out too. - uiChapter only clears last_chapter_url when the number actually changes. The form is pre-filled, so a bare tap of Save resubmits the same value; that used to destroy the chapter URL silently while updated_at stayed put, degrading Continue to the series index page. - MANGA_WEB_HOST is now required by the prod override rather than falling back to manga.example.com, matching MANGA_API_HOST. - Comment fixes: static cache rationale, pruneLocked aliasing invariant, and the stale "3 routes" line in CLAUDE.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
30 lines
1.2 KiB
Bash
30 lines
1.2 KiB
Bash
# Copy to .env and fill in. Never commit the real .env.
|
|
|
|
# Long random secret shared with the userscript's API_TOKEN. Generate one:
|
|
# openssl rand -hex 32
|
|
API_TOKEN=changeme-generate-a-long-random-token
|
|
|
|
# Comma-separated origins allowed to call the API (CORS). Both Asura domains
|
|
# plus Demonic. Add/remove as the sites' hostnames change.
|
|
ALLOWED_ORIGINS=https://asuracomic.net,https://asurascans.com,https://demonicscans.org
|
|
|
|
# --- Prod override (Traefik) only ---
|
|
# Subdomain Traefik routes to this service (required by the prod override).
|
|
# MANGA_API_HOST=manga-api.example.com
|
|
# Traefik's docker network name, if not "proxy".
|
|
# PROXY_NETWORK=proxy
|
|
# Traefik HTTPS entrypoint + cert resolver names, if yours differ from these.
|
|
# TRAEFIK_ENTRYPOINT=websecure
|
|
# TRAEFIK_CERTRESOLVER=le
|
|
|
|
# --- Web UI ---
|
|
# Password for the browser UI at https://$MANGA_WEB_HOST. Leave unset to
|
|
# disable the web UI entirely (the routes are not registered at all).
|
|
# Generate one: openssl rand -base64 18
|
|
WEB_PASSWORD=
|
|
|
|
# Subdomain Traefik routes to the browser UI (required by the prod override
|
|
# whenever the web UI is enabled). The same container also answers on
|
|
# MANGA_API_HOST for the userscript's API.
|
|
MANGA_WEB_HOST=manga.example.com
|