0416354c06
Serves the userscript from the backend so Violentmonkey auto-updates it, plus two panel fixes.
## Backend: `GET /u/{token}/manga-bookmark.user.js`
The script is read off disk per request from `USERSCRIPT_PATH` and streamed back with its `@version` line rewritten.
- **Token in the path, not a header.** Violentmonkey's update poll sends no `Authorization` header, and the script embeds `API_TOKEN` in plain text — an open URL would hand that token to anyone who guessed it. Compare is constant-time.
- **404, never 401**, for both a wrong token and a missing file: a prober learns nothing about whether the route exists.
- Registered outside `withAuth` and outside the `WEB_PASSWORD` gate, so the script is installable on a deployment that never enabled the web UI.
- Stdlib only (`crypto/subtle`, `os`, `regexp`) — no new Go dependencies.
**The served `@version` is derived from the file's mtime** (`YYYY.MM.DD.HHMM`, UTC), discarding whatever the file body says. Violentmonkey only updates when the served version sorts higher than the installed one, so a body-derived version means one typo or accidental downgrade freezes updates forever. An mtime-derived version is monotonic by construction. A file with no `@version` line is served byte-identical. `os.Stat` runs before `os.ReadFile`, so a concurrent edit can only serve new content under an old stamp — which self-heals on the next poll — never the reverse.
## Bindmount
`./userscript` is bindmounted read-only at `/userscript`. The script is deliberately **not** copied into the image: the build context stays `./backend`, and widening it would churn every `COPY` path for a file the mount always supplies. Editing the file on the VPS is live on the next poll — no rebuild, no restart. `git pull` restores the committed version, so a redeploy always ships the repo's script; checkout sets mtime to now, so even a rollback serves a *higher* version and is adopted. Without the mount the endpoint 404s and logs it; bookmark sync is unaffected.
`@downloadURL` / `@updateURL` are literal URLs in the metadata block — it is parsed before any JS runs, so `API_BASE`/`API_TOKEN` cannot be interpolated. The token was already committed in this file, so this adds no new exposure.
## Userscript UI
- **Card actions moved under the subtitle.** Only the cover and the title continue reading now; the subtitle and the action row are inert siblings in the text column. A thumb that misses ★ lands on nothing, and Remove is never inside a link.
- **Loading spinner** while the first fetch is in flight — the panel used to read as frozen on the first open after a cold start. It draws only when there is nothing cached to draw instead, so a populated list never flaps.
## Verification
- `go test -count=1 ./...` — ok, 7.070s
- `node --check` clean; `node --test userscript/test/logic.test.js` — 14/14
- Live `docker compose` smoke: `/healthz` 200, wrong token 404, script served with a stamped `@version 2026.07.28.1057` and both metadata URLs present; `touch`ing the file advanced the served version to `2026.07.28.1100` with no restart.
Layout and spinner are verified on-device — there is deliberately no DOM test harness.
Reviewed-on: #8
Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com>
Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
61 lines
2.1 KiB
Go
61 lines
2.1 KiB
Go
package main
|
|
|
|
import (
|
|
"crypto/subtle"
|
|
"log"
|
|
"net/http"
|
|
"os"
|
|
"regexp"
|
|
"time"
|
|
)
|
|
|
|
// versionLine matches the userscript metadata block's @version directive.
|
|
var versionLine = regexp.MustCompile(`(?m)^// @version[ \t]+.*$`)
|
|
|
|
// stampVersion replaces the served @version with one derived from the file's
|
|
// mtime, discarding whatever the file body says.
|
|
//
|
|
// Violentmonkey only updates when the served version sorts higher than the
|
|
// installed one. Deriving it from the body means one accidental downgrade or
|
|
// typo freezes updates forever; an mtime-derived version is monotonic by
|
|
// construction, so any later write always outranks any earlier one.
|
|
//
|
|
// A file with no @version line is returned untouched: such a script never
|
|
// auto-updates anyway, and inventing a metadata block is not this handler's job.
|
|
func stampVersion(src []byte, mod time.Time) []byte {
|
|
return versionLine.ReplaceAll(src, []byte("// @version "+mod.UTC().Format("2006.01.02.1504")))
|
|
}
|
|
|
|
// userscriptHandler serves the userscript to Violentmonkey's updater.
|
|
//
|
|
// The token lives in the path because the update poll sends no Authorization
|
|
// header, and the file embeds API_TOKEN in plain text, so an open path would
|
|
// hand that token to anyone who guessed the URL. A mismatch answers 404 rather
|
|
// than 401: a prober learns nothing about whether the route exists.
|
|
//
|
|
// The file is read per request — that is what lets a bindmounted copy be edited
|
|
// on the host without a restart. It is ~50 KB and polled about once a day.
|
|
func userscriptHandler(token, path string) http.HandlerFunc {
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
|
if subtle.ConstantTimeCompare([]byte(r.PathValue("token")), []byte(token)) != 1 {
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
info, err := os.Stat(path)
|
|
if err != nil {
|
|
log.Printf("userscript: stat %s: %v", path, err)
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
src, err := os.ReadFile(path)
|
|
if err != nil {
|
|
log.Printf("userscript: read %s: %v", path, err)
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
w.Header().Set("Content-Type", "text/javascript; charset=utf-8")
|
|
w.Header().Set("Cache-Control", "no-cache")
|
|
w.Write(stampVersion(src, info.ModTime()))
|
|
}
|
|
}
|