180ee78b1f
Tracks read progress on comix.to and kagane.to alongside asura and demonic, in both the userscript and the backend. Implements `docs/superpowers/plans/2026-08-03-comix-kagane-support.md`. ## Userscript - `comix` adapter — `/title/<id>-<slug>`; only the id prefix is identity (the slug follows the title). No `og:image`, so the cover is matched by `alt`. - `kagane` adapter — reader URLs are uuids with no chapter number, so it comes out of `og:title`; anchor scanning is structurally impossible, replaced by `latestChapterFromApi` against kagane's same-origin JSON API. - `seriesId` threaded through `latestChapterFromAnchors` so comix can scope its scan to its own series and a recommendation strip cannot win the maximum. - `@match` for both hosts, panel chips, v1.6.0. ## Backend - `latestChapterFrom` cases: comix parses the SSR JSON state blob (`latestChapterUrl`, scoped to the series id); kagane parses API JSON (`chapter_no`). - Poller allowlist extended; `Poller.BrowserFetch` with `fetcherFor(site)` routes kagane to a browser fetcher. Nil means kagane is not polled at all — never a fallback to the TLS fetcher, which would only ever retrieve a challenge page. - `BrowserFetcher`: chromedp against a `headless-shell` sidecar. kagane sits behind a Cloudflare JS challenge that no TLS fingerprint clears, and the request is made inside the page rather than by replaying `cf_clearance`. - `BROWSER_WS_URL` wiring, sidecar in both compose files (no `ports:`, dedicated non-external network), Dockerfile on `golang:1.26-alpine` — chromedp requires go 1.26. - Web UI `--comix` / `--kagane` tokens in both colour branches. ## Notes for review - `series_url` is client-supplied and a headless browser is a strong SSRF primitive, so kagane's host is pinned twice: in `fetchableSeriesURL` and again in `kaganeAPIURL`. - Three chained defects found during verification made the browser path dead under Compose (sidecar flag collision, Chrome's Host-header DNS-rebinding check, the wrong chromedp option). Fixed; the compose comments record the wrong configurations too, so they don't get "simplified" back. - `ALLOWED_ORIGINS` now includes both new origins. Without it every write from comix/kagane silently fails CORS preflight, parks in the retry queue, and drops at the cap. ## Verification 221 backend tests, 32 userscript tests, static `CGO_ENABLED=0` build, both compose configs. Two gaps, both real: 1. The userscript on live pages via Violentmonkey needs a human browser profile — not run. Check: comix series page (title/cover, no chapter), comix chapter page (records the number; an *older* chapter must not regress it), comix SPA navigation without reload, kagane series page (og:image cover), kagane reader (number from `og:title`), both chips opening the right sites. 2. The kagane browser path has not completed end-to-end anywhere. Dial/navigate/fetch is confirmed, but Cloudflare 403'd headless-shell's Chrome on every attempt from the dev sandbox, and comix's poll-through-Docker was blocked by that environment's TLS interception. Both environment-dependent rather than branch defects — the first real deploy is the actual verification. Reviewed-on: #13 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
76 lines
3.4 KiB
HTML
76 lines
3.4 KiB
HTML
{{define "app"}}
|
|
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
|
|
<meta name="color-scheme" content="dark light">
|
|
<title>mangaBookmark</title>
|
|
<link rel="icon" href="/static/logo.svg" type="image/svg+xml">
|
|
<link rel="stylesheet" href="/static/style.css">
|
|
<link rel="preload" href="/static/fonts/instrument-serif-400-latin.woff2" as="font" type="font/woff2" crossorigin>
|
|
{{/* Body text before meta lines: DM Sans is the biggest face and the one
|
|
most of the page is set in; the mono is small and arrives from CSS. */}}
|
|
<link rel="preload" href="/static/fonts/dm-sans-var-latin.woff2" as="font" type="font/woff2" crossorigin>
|
|
<script src="/static/htmx.min.js" defer></script>
|
|
<script src="/static/filter.js" defer></script>
|
|
</head>
|
|
<body>
|
|
{{template "icons" .}}
|
|
<div class="sheet">
|
|
<header class="topbar">
|
|
<h1 class="brand">{{template "mark" .}}<span>manga<em>Bookmark</em></span></h1>
|
|
<form method="post" action="/logout">
|
|
<button type="submit" class="ghost">Log out</button>
|
|
</form>
|
|
</header>
|
|
|
|
{{/* Search sits above the tabs on a phone and folds into the tab row on a
|
|
wider screen — one flex container, order swapped in CSS. */}}
|
|
<div class="chrome">
|
|
<div class="searchbar">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-search"/></svg>
|
|
<input id="search" class="search" type="search" placeholder="Find a title"
|
|
autocomplete="off" aria-label="Search titles">
|
|
</div>
|
|
|
|
{{/* These are real links with real hrefs that change the URL, so they are
|
|
navigation, not an ARIA tablist — aria-current carries "which bucket am
|
|
I in" without owing a tabpanel contract we do not implement. */}}
|
|
<nav class="tabs" aria-label="Bookmark buckets">
|
|
<a href="/?tab=all" class="{{if eq .Tab "all"}}active{{end}}"
|
|
{{if eq .Tab "all"}}aria-current="page"{{end}}
|
|
hx-get="/ui/list?tab=all" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="/?tab=all" hx-on::after-request="setActiveTab(this)">All</a>
|
|
<a href="/?tab=new" class="tab-new {{if eq .Tab "new"}}active{{end}}"
|
|
{{if eq .Tab "new"}}aria-current="page"{{end}}
|
|
hx-get="/ui/list?tab=new" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="/?tab=new" hx-on::after-request="setActiveTab(this)">Updated
|
|
{{template "newcount" .}}</a>
|
|
<a href="/?tab=fav" class="{{if eq .Tab "fav"}}active{{end}}"
|
|
{{if eq .Tab "fav"}}aria-current="page"{{end}}
|
|
hx-get="/ui/list?tab=fav" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="/?tab=fav" hx-on::after-request="setActiveTab(this)">Favourites</a>
|
|
<a href="/?tab=archived" class="{{if eq .Tab "archived"}}active{{end}}"
|
|
{{if eq .Tab "archived"}}aria-current="page"{{end}}
|
|
hx-get="/ui/list?tab=archived" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="/?tab=archived" hx-on::after-request="setActiveTab(this)">Archived</a>
|
|
<a href="/?tab=finished" class="{{if eq .Tab "finished"}}active{{end}}"
|
|
{{if eq .Tab "finished"}}aria-current="page"{{end}}
|
|
hx-get="/ui/list?tab=finished" hx-target="#list" hx-swap="innerHTML"
|
|
hx-push-url="/?tab=finished" hx-on::after-request="setActiveTab(this)">Finished</a>
|
|
</nav>
|
|
</div>
|
|
|
|
{{template "keyrow" .}}
|
|
|
|
{{template "recent" .}}
|
|
|
|
<main id="list" class="list">
|
|
{{template "list" .}}
|
|
</main>
|
|
</div>
|
|
</body>
|
|
</html>
|
|
{{end}}
|