2ef769d421
Closes #27. Guild membership is now the whole gate. `discordCallback` checks membership (and `DISCORD_REQUIRED_ROLE` when set), then `Store.EnsureReader` creates the Reader on first sight and returns the same row on every later login. The refusal returns before `EnsureReader`, so a turned-away sign-in leaves no row behind. `OWNER_DISCORD_ID` still seeds the owner, but only as the administrator — it no longer gates login. The cutover grace path goes with it: `API_TOKEN`, `API_TOKEN_GRACE_UNTIL` and the legacy branch in `httpmw.ResolveReader` are deleted, so a credential authenticates exactly one Reader or nothing. `userscript.Handler` drops its re-derivation too — the resolved path segment is already the credential. New surfaces: an empty library offers both install links (behind the tab-specific empty states, so "No favourites yet" still wins), and the owner alone gets a Readers panel with `POST /readers/{id}/revoke`. The owner's own row is not revocable — 404, not a self-logout. Isolation is asserted from both directions for read, modify and delete, and the shared-series invariant is pinned: two Readers on one series produce one series row, two independent progresses, one poll per due cycle, and one Reader's delete leaves the other's bookmark and the poll intact. Verified: `go test ./...` green; live smoke against a throwaway Postgres — empty-library state in both colour branches, roster rendering, a real revoke through the panel (target 401s next request, owner untouched), owner self-revoke refused 404, per-Reader `/u/<cred>` and bearer auth both 200 with 404 for an unknown credential. Reviewed-on: #36 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
30 lines
1.4 KiB
HTML
30 lines
1.4 KiB
HTML
{{/* The owner's Reader roster. Rendered only for the owner (listView.Owner),
|
|
and re-rendered whole as the response to a revocation so the session
|
|
counts cannot describe the state before the tap. Revocation is
|
|
confirm-gated: it signs someone out of every device at once. */}}
|
|
{{define "readers"}}
|
|
<details class="setup" id="readers">
|
|
<summary>Readers</summary>
|
|
<p class="setup-copy">Everyone who has signed in through Discord. Revoking
|
|
signs a Reader out of every device; their library and bookmarks are
|
|
untouched, and they can sign in again.</p>
|
|
<ul class="readerlist">
|
|
{{range .Readers}}
|
|
<li>
|
|
<span class="reader-id">{{.DiscordID}}</span>
|
|
<span class="reader-sessions">{{.Sessions}} session{{if ne .Sessions 1}}s{{end}}</span>
|
|
{{/* The owner's own row never offers Revoke: it is the one row where the
|
|
button would sign the tapping browser out, and the endpoint refuses
|
|
it anyway. Logout is the deliberate way to do that. */}}
|
|
{{if and .Sessions (ne .ID $.OwnerID)}}
|
|
<form hx-post="/readers/{{.ID}}/revoke" hx-target="#readers" hx-swap="outerHTML"
|
|
hx-confirm="Revoking signs this Reader out on every device immediately. Revoke?">
|
|
<button type="submit" class="ghost danger">Revoke sessions</button>
|
|
</form>
|
|
{{end}}
|
|
</li>
|
|
{{end}}
|
|
</ul>
|
|
</details>
|
|
{{end}}
|