0416354c06
Serves the userscript from the backend so Violentmonkey auto-updates it, plus two panel fixes.
## Backend: `GET /u/{token}/manga-bookmark.user.js`
The script is read off disk per request from `USERSCRIPT_PATH` and streamed back with its `@version` line rewritten.
- **Token in the path, not a header.** Violentmonkey's update poll sends no `Authorization` header, and the script embeds `API_TOKEN` in plain text — an open URL would hand that token to anyone who guessed it. Compare is constant-time.
- **404, never 401**, for both a wrong token and a missing file: a prober learns nothing about whether the route exists.
- Registered outside `withAuth` and outside the `WEB_PASSWORD` gate, so the script is installable on a deployment that never enabled the web UI.
- Stdlib only (`crypto/subtle`, `os`, `regexp`) — no new Go dependencies.
**The served `@version` is derived from the file's mtime** (`YYYY.MM.DD.HHMM`, UTC), discarding whatever the file body says. Violentmonkey only updates when the served version sorts higher than the installed one, so a body-derived version means one typo or accidental downgrade freezes updates forever. An mtime-derived version is monotonic by construction. A file with no `@version` line is served byte-identical. `os.Stat` runs before `os.ReadFile`, so a concurrent edit can only serve new content under an old stamp — which self-heals on the next poll — never the reverse.
## Bindmount
`./userscript` is bindmounted read-only at `/userscript`. The script is deliberately **not** copied into the image: the build context stays `./backend`, and widening it would churn every `COPY` path for a file the mount always supplies. Editing the file on the VPS is live on the next poll — no rebuild, no restart. `git pull` restores the committed version, so a redeploy always ships the repo's script; checkout sets mtime to now, so even a rollback serves a *higher* version and is adopted. Without the mount the endpoint 404s and logs it; bookmark sync is unaffected.
`@downloadURL` / `@updateURL` are literal URLs in the metadata block — it is parsed before any JS runs, so `API_BASE`/`API_TOKEN` cannot be interpolated. The token was already committed in this file, so this adds no new exposure.
## Userscript UI
- **Card actions moved under the subtitle.** Only the cover and the title continue reading now; the subtitle and the action row are inert siblings in the text column. A thumb that misses ★ lands on nothing, and Remove is never inside a link.
- **Loading spinner** while the first fetch is in flight — the panel used to read as frozen on the first open after a cold start. It draws only when there is nothing cached to draw instead, so a populated list never flaps.
## Verification
- `go test -count=1 ./...` — ok, 7.070s
- `node --check` clean; `node --test userscript/test/logic.test.js` — 14/14
- Live `docker compose` smoke: `/healthz` 200, wrong token 404, script served with a stamped `@version 2026.07.28.1057` and both metadata URLs present; `touch`ing the file advanced the served version to `2026.07.28.1100` with no restart.
Layout and spinner are verified on-device — there is deliberately no DOM test harness.
Reviewed-on: #8
Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com>
Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
133 lines
4.2 KiB
Go
133 lines
4.2 KiB
Go
package main
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
"time"
|
|
)
|
|
|
|
// sampleScript is a stand-in for the real userscript: a metadata block with a
|
|
// @version line, plus a body that must survive the rewrite untouched.
|
|
const sampleScript = `// ==UserScript==
|
|
// @name Manga Bookmark Sync
|
|
// @version 1.5.0
|
|
// @match https://asurascans.com/*
|
|
// ==/UserScript==
|
|
(function () { "use strict"; })();
|
|
`
|
|
|
|
// writeScript drops a userscript in a temp dir with a known mtime and returns
|
|
// its path plus the version string the handler is expected to stamp.
|
|
func writeScript(t *testing.T, body string) (path, wantVersion string) {
|
|
t.Helper()
|
|
path = filepath.Join(t.TempDir(), "manga-bookmark.user.js")
|
|
if err := os.WriteFile(path, []byte(body), 0o644); err != nil {
|
|
t.Fatalf("write script: %v", err)
|
|
}
|
|
mod := time.Date(2026, 7, 28, 16, 42, 0, 0, time.UTC)
|
|
if err := os.Chtimes(path, mod, mod); err != nil {
|
|
t.Fatalf("chtimes: %v", err)
|
|
}
|
|
return path, "2026.07.28.1642"
|
|
}
|
|
|
|
func newUserscriptServer(t *testing.T, path string) http.Handler {
|
|
t.Helper()
|
|
store, err := OpenStore(filepath.Join(t.TempDir(), "test.db"))
|
|
if err != nil {
|
|
t.Fatalf("OpenStore: %v", err)
|
|
}
|
|
t.Cleanup(func() { store.Close() })
|
|
cfg := testConfig()
|
|
cfg.UserscriptPath = path
|
|
return newRouter(store, cfg)
|
|
}
|
|
|
|
func getScript(t *testing.T, srv http.Handler, token string) *httptest.ResponseRecorder {
|
|
t.Helper()
|
|
rr := httptest.NewRecorder()
|
|
srv.ServeHTTP(rr, httptest.NewRequest(http.MethodGet, "/u/"+token+"/manga-bookmark.user.js", nil))
|
|
return rr
|
|
}
|
|
|
|
func TestUserscriptServedWithStampedVersion(t *testing.T) {
|
|
path, wantVersion := writeScript(t, sampleScript)
|
|
rr := getScript(t, newUserscriptServer(t, path), testToken)
|
|
|
|
if rr.Code != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200", rr.Code)
|
|
}
|
|
if ct := rr.Header().Get("Content-Type"); !strings.HasPrefix(ct, "text/javascript") {
|
|
t.Errorf("Content-Type = %q, want text/javascript", ct)
|
|
}
|
|
if cc := rr.Header().Get("Cache-Control"); cc != "no-cache" {
|
|
t.Errorf("Cache-Control = %q, want no-cache", cc)
|
|
}
|
|
body := rr.Body.String()
|
|
if !strings.Contains(body, "// @version "+wantVersion) {
|
|
t.Errorf("body has no stamped version %q:\n%s", wantVersion, body)
|
|
}
|
|
if strings.Contains(body, "1.5.0") {
|
|
t.Errorf("body still carries the file's own version:\n%s", body)
|
|
}
|
|
// Everything outside the @version line is served verbatim.
|
|
if !strings.Contains(body, `(function () { "use strict"; })();`) {
|
|
t.Errorf("body was altered beyond the version line:\n%s", body)
|
|
}
|
|
if !strings.Contains(body, "// @name Manga Bookmark Sync") {
|
|
t.Errorf("metadata block was altered:\n%s", body)
|
|
}
|
|
}
|
|
|
|
func TestUserscriptWrongTokenIs404(t *testing.T) {
|
|
path, _ := writeScript(t, sampleScript)
|
|
srv := newUserscriptServer(t, path)
|
|
for _, tok := range []string{"wrong", "", testToken + "x", testToken[:3]} {
|
|
if got := getScript(t, srv, tok).Code; got != http.StatusNotFound {
|
|
t.Errorf("token %q: status = %d, want 404", tok, got)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestUserscriptMissingFileIs404(t *testing.T) {
|
|
srv := newUserscriptServer(t, filepath.Join(t.TempDir(), "absent.user.js"))
|
|
if got := getScript(t, srv, testToken).Code; got != http.StatusNotFound {
|
|
t.Fatalf("status = %d, want 404", got)
|
|
}
|
|
}
|
|
|
|
func TestUserscriptWithoutVersionLineServedUnmodified(t *testing.T) {
|
|
const noVersion = "// ==UserScript==\n// @name x\n// ==/UserScript==\nconsole.log(1);\n"
|
|
path, _ := writeScript(t, noVersion)
|
|
rr := getScript(t, newUserscriptServer(t, path), testToken)
|
|
|
|
if rr.Code != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200", rr.Code)
|
|
}
|
|
if rr.Body.String() != noVersion {
|
|
t.Fatalf("body = %q, want it unmodified", rr.Body.String())
|
|
}
|
|
}
|
|
|
|
// The endpoint must work on a deployment that never set WEB_PASSWORD, since
|
|
// the web routes are not registered at all in that case.
|
|
func TestUserscriptServedWithWebUIDisabled(t *testing.T) {
|
|
path, _ := writeScript(t, sampleScript)
|
|
store, err := OpenStore(filepath.Join(t.TempDir(), "nopass.db"))
|
|
if err != nil {
|
|
t.Fatalf("OpenStore: %v", err)
|
|
}
|
|
t.Cleanup(func() { store.Close() })
|
|
cfg := testConfig()
|
|
cfg.WebPassword = ""
|
|
cfg.UserscriptPath = path
|
|
|
|
if got := getScript(t, newRouter(store, cfg), testToken).Code; got != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200", got)
|
|
}
|
|
}
|