27cf0955de
Closes #24. Child of #18; based on current main (includes Postgres, Reader table, Discord OAuth).
## What
Each Reader's userscript credential is derived from `TOKEN_KEY`, their Discord id and a token epoch (HMAC-SHA256, hex); only its SHA-256 sits in `readers.token_sha256` (new `token_epoch` column, migration 0006). One credential authenticates the script download path and the API bearer header.
- `internal/token`: derivation + hashing; the seed refreshes the owner's epoch-0 hash only before first rotation, so a restart can never resurrect a rotated-away credential
- `httpmw.Auth`/`ResolveReader`: acting Reader resolved from the credential hash, stashed in request context; the retired global `API_TOKEN` resolves to the owner until `API_TOKEN_GRACE_UNTIL` (enforced in code, logged per use) on both the bearer and script-download paths
- Userscript handler renders the bindmounted file with the resolved Reader's credential substituted for `__API_TOKEN__`; a legacy-path request during grace serves the derived credential, so installed devices self-migrate on their next update poll
- Web UI: "Userscripts" panel — session-gated install endpoints render the script directly (credential never in markup, address bar, or a redirect), confirm-gated rotation with an atomic epoch bump + hash rewrite and a reinstall warning
- Both userscripts carry `__API_TOKEN__` placeholders; the committed global-token literal is removed
## Design note
Credentials are derived rather than stored-random because the server must rebuild install URLs after restarts while the DB holds only hashes. HMAC output is high-entropy and unbrute-forceable; the AC's intent (unguessable, DB-leak-proof) is met.
## Deploy (also in DEPLOY.md)
1. Add `TOKEN_KEY` (`openssl rand -hex 32`) — required; changing it later invalidates every credential.
2. Keep `API_TOKEN` + set `API_TOKEN_GRACE_UNTIL` for the 14-day window.
3. After deploy, sign in → Userscripts → reinstall both scripts on every device. This also retires the old global credential for real — its literal survives in git history (present since 0ef5286), so rotation is what kills it.
## Verification
- Full Go suite green against real Postgres per test; userscript JS suite 45/45
- New router-level tests: per-Reader isolation (read/write/delete), grace expiry on bearer + script path, self-migrating legacy path, install serving, rotation (old cred 401/404, new cred works, install renders new credential), app page leaks no credential
- Store tests: hash lookup, token info, atomic rotation with stale-epoch rejection, rotation survives restart
- Live smoke of the built binary: grace acceptance logged, derived auth, substitution, restart resilience, stored hash = SHA-256 of derived credential
Reviewed-on: #32
Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com>
Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
90 lines
4.2 KiB
HTML
90 lines
4.2 KiB
HTML
{{define "app"}}
|
|
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
|
|
<meta name="color-scheme" content="dark light">
|
|
<title>BookmarkManager</title>
|
|
<link rel="icon" href="/static/logo.svg" type="image/svg+xml">
|
|
<link rel="stylesheet" href="/static/style.css">
|
|
<link rel="preload" href="/static/fonts/instrument-serif-400-latin.woff2" as="font" type="font/woff2" crossorigin>
|
|
{{/* Body text before meta lines: DM Sans is the biggest face and the one
|
|
most of the page is set in; the mono is small and arrives from CSS. */}}
|
|
<link rel="preload" href="/static/fonts/dm-sans-var-latin.woff2" as="font" type="font/woff2" crossorigin>
|
|
<script src="/static/htmx.min.js" defer></script>
|
|
<script src="/static/filter.js" defer></script>
|
|
</head>
|
|
<body>
|
|
{{template "icons" .}}
|
|
<div class="sheet">
|
|
<header class="topbar">
|
|
<h1 class="brand">{{template "mark" .}}<span>Bookmark<em>Manager</em></span></h1>
|
|
{{/* Plain full-page links, not htmx swaps: switching library replaces the
|
|
tab row and the chrome, which is a page, not a fragment. */}}
|
|
<nav class="libswitch" aria-label="Library">
|
|
<a href="/?tab=all" class="{{if eq .Lib "manga"}}active{{end}}"
|
|
{{if eq .Lib "manga"}}aria-current="page"{{end}}>Manga</a>
|
|
<a href="/?lib=novel&tab=all" class="{{if eq .Lib "novel"}}active{{end}}"
|
|
{{if eq .Lib "novel"}}aria-current="page"{{end}}>Novels</a>
|
|
</nav>
|
|
<form method="post" action="/logout">
|
|
<button type="submit" class="ghost">Log out</button>
|
|
</form>
|
|
</header>
|
|
|
|
{{/* Search sits above the tabs on a phone and folds into the tab row on a
|
|
wider screen — one flex container, order swapped in CSS. */}}
|
|
<div class="chrome">
|
|
<div class="searchbar">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-search"/></svg>
|
|
<input id="search" class="search" type="search" placeholder="Find a title"
|
|
autocomplete="off" aria-label="Search titles">
|
|
</div>
|
|
|
|
{{/* These are real links with real hrefs that change the URL, so they are
|
|
navigation, not an ARIA tablist — aria-current carries "which bucket am
|
|
I in" without owing a tabpanel contract we do not implement. */}}
|
|
<nav class="tabs" aria-label="Bookmark buckets">
|
|
<a href="{{.PageURL "all"}}" class="{{if eq .Tab "all"}}active{{end}}"
|
|
{{if eq .Tab "all"}}aria-current="page"{{end}}
|
|
hx-get="{{.ListURL "all"}}" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="{{.PageURL "all"}}" hx-on::after-request="setActiveTab(this)">All</a>
|
|
{{/* The one bucket novels do not have: without a poller-fed "what is out
|
|
that I have not read", the tab would only ever restate All. */}}
|
|
{{if eq .Lib "manga"}}
|
|
<a href="{{.PageURL "new"}}" class="tab-new {{if eq .Tab "new"}}active{{end}}"
|
|
{{if eq .Tab "new"}}aria-current="page"{{end}}
|
|
hx-get="{{.ListURL "new"}}" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="{{.PageURL "new"}}" hx-on::after-request="setActiveTab(this)">Updated
|
|
{{template "newcount" .}}</a>
|
|
{{end}}
|
|
<a href="{{.PageURL "fav"}}" class="{{if eq .Tab "fav"}}active{{end}}"
|
|
{{if eq .Tab "fav"}}aria-current="page"{{end}}
|
|
hx-get="{{.ListURL "fav"}}" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="{{.PageURL "fav"}}" hx-on::after-request="setActiveTab(this)">Favourites</a>
|
|
<a href="{{.PageURL "archived"}}" class="{{if eq .Tab "archived"}}active{{end}}"
|
|
{{if eq .Tab "archived"}}aria-current="page"{{end}}
|
|
hx-get="{{.ListURL "archived"}}" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="{{.PageURL "archived"}}" hx-on::after-request="setActiveTab(this)">Archived</a>
|
|
<a href="{{.PageURL "finished"}}" class="{{if eq .Tab "finished"}}active{{end}}"
|
|
{{if eq .Tab "finished"}}aria-current="page"{{end}}
|
|
hx-get="{{.ListURL "finished"}}" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="{{.PageURL "finished"}}" hx-on::after-request="setActiveTab(this)">Finished</a>
|
|
</nav>
|
|
</div>
|
|
|
|
{{template "setup" .}}
|
|
|
|
{{template "keyrow" .}}
|
|
|
|
{{template "recent" .}}
|
|
|
|
<main id="list" class="list">
|
|
{{template "list" .}}
|
|
</main>
|
|
</div>
|
|
</body>
|
|
</html>
|
|
{{end}}
|