64c27fe896
A Reader who bookmarks a Series nobody holds yet no longer waits out the
poll queue for its artwork: the first Bookmark to create a Series fires
Store.OnSeriesCreated, and latest.Acquirer turns that into a single
series-page fetch yielding both the Latest Chapter and the cover URL. The
bytes are fetched through the gated cover fetcher and stored
content-addressed, so the wire carries an absolute URL on this
deployment's own origin (ADR-0007) - never a third-party address and
never one that 404s.
- series.cover_address (migration 0009) splits the third-party source
address the bytes came from (series.cover) from the content address
they are stored under. A blank cover_address is what "no Cover yet"
means, so the wire field is empty until real bytes exist.
- GET /covers/{address} serves the bytes publicly and uncredentialed,
immutable-cached; the address is gated by a 64-hex pattern and
cross-checked against a pure function of itself before any filesystem
read.
- Client-sent cover values are decoded and discarded permanently: the
cover columns are absent from Upsert's INSERT and its DO UPDATE, so no
request value can reach the shared Series row (extends ADR-0003's
"ignored after creation" to "ignored always", keeps ADR-0004's flat
wire so installed userscripts keep working).
- Acquisition is asynchronous and log-and-drop: the Reader's write
neither blocks on nor fails with a third-party Site. It is bounded by
a two-slot semaphore, cancelled at shutdown, and stamps
latest_checked_at so the poller does not refetch the same page a tick
later.
- store.CoverContentType canonicalises comix's non-standard "image/jpg"
to "image/jpeg", so one image cannot land under two spellings.
- PUBLIC_BASE_URL is a new required setting; Open rejects anything that
is not an absolute http(s) origin, since a bare hostname would start
cleanly and emit addresses no browser can load.
Verified against a live backend: bookmarking a comix series produced a
280x420 JPEG served from /covers/<sha256> with the immutable cache
header, and the web UI card renders that address.
90 lines
3.0 KiB
Go
90 lines
3.0 KiB
Go
package web
|
|
|
|
import (
|
|
"bookmarkmanager/backend/internal/store"
|
|
"context"
|
|
"log"
|
|
"net/http"
|
|
"regexp"
|
|
"time"
|
|
)
|
|
|
|
// CoverFetcher retrieves one kagane cover by image id. Satisfied by
|
|
// latest.BrowserFetcher. It is nil when BROWSER_WS_URL is unset; uncached
|
|
// covers are then unavailable, while covers already stored by the backend
|
|
// remain available without a browser.
|
|
type CoverFetcher interface {
|
|
Image(ctx context.Context, imageID string) (body []byte, contentType string, err error)
|
|
}
|
|
|
|
// coverIDRe matches the request path segment that becomes part of an outbound
|
|
// URL. The proxy is session-gated, but the id still reaches a headless browser,
|
|
// so it is validated at the boundary rather than passed through.
|
|
var coverIDRe = regexp.MustCompile(`^[0-9a-f-]{36}$`)
|
|
|
|
// coverTimeout bounds one proxied cover. Shorter than the fetcher's own
|
|
// challenge budget on purpose: a browser page is waiting on this, and a cover
|
|
// that has not arrived by now is better left as a broken slot than as a request
|
|
// holding a connection open.
|
|
const coverTimeout = 20 * time.Second
|
|
|
|
// kaganeCover serves a kagane cover from the backend's own origin.
|
|
//
|
|
// kagane answers image requests with a Cloudflare challenge and
|
|
// `cross-origin-resource-policy: same-origin`, so the web UI cannot render one
|
|
// directly under any combination of referrer policy or crossorigin attribute
|
|
// (verified 2026-08-08). Fetching it through the headless browser that already
|
|
// clears the challenge, and re-serving it here, is what puts the bytes on an
|
|
// origin the page may load from.
|
|
func (h *Handler) kaganeCover(w http.ResponseWriter, r *http.Request) {
|
|
id := r.PathValue("id")
|
|
if !coverIDRe.MatchString(id) {
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
body, contentType, ok, err := h.store.GetKaganeCover(id)
|
|
if err != nil {
|
|
log.Printf("read kagane cover %s: %v", id, err)
|
|
http.Error(w, "internal error", http.StatusInternalServerError)
|
|
return
|
|
}
|
|
if ok {
|
|
writeCover(w, body, contentType)
|
|
return
|
|
}
|
|
if h.covers == nil {
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
|
|
ctx, cancel := context.WithTimeout(r.Context(), coverTimeout)
|
|
defer cancel()
|
|
body, contentType, err = h.covers.Image(ctx, id)
|
|
if err != nil {
|
|
log.Printf("kagane cover %s: %v", id, err)
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
canonical, ok := store.CoverContentType(contentType)
|
|
if !ok {
|
|
log.Printf("kagane cover %s: unexpected content type %q", id, contentType)
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
contentType = canonical
|
|
if err := h.store.PutKaganeCover(id, body, contentType); err != nil {
|
|
log.Printf("persist kagane cover %s: %v", id, err)
|
|
http.Error(w, "internal error", http.StatusInternalServerError)
|
|
return
|
|
}
|
|
writeCover(w, body, contentType)
|
|
}
|
|
|
|
// writeCover sends the bytes with a long cache life: an image id names one
|
|
// immutable rendering, so a client that has it never needs to ask again.
|
|
func writeCover(w http.ResponseWriter, body []byte, contentType string) {
|
|
w.Header().Set("Content-Type", contentType)
|
|
w.Header().Set("Cache-Control", "private, max-age=604800, immutable")
|
|
w.Write(body)
|
|
}
|