741b23322b
Fixes five reported symptoms across comix.to and kagane.to. Diagnosing them turned up two latent bugs underneath, both of which had to be fixed for the kagane cover work to function at all.
## Reported symptoms and their causes
| # | Symptom | Cause |
|---|---------|-------|
| 1 | comix bookmark titled `Comix - Read Comics online for free` | comix is an SPA that rewrites `document.title` on client routing but never touches the server-rendered `og:title`. The adapter read `og:title`, so a cold load stored the homepage's title. |
| 2 | next comix bookmark gets the *previous* series' title | Same cause. After an in-page hop, `og:title` still holds whatever page loaded first. |
| 3 | comix cover shows the placeholder | comix serves no `og:image` at all, so `coverFromPage()` had nothing to read. |
| 4 | kagane chapter never appears in the bookmark list | Reader URLs carry no chapter number, so it is parsed out of `og:title`. Volume-numbered series render `"<Series> - Volume <v> Chapter <n>"`, which the suffix regex did not match, so `chapterNum` came back null and nothing was recorded. |
| 5 | kagane title includes the chapter, e.g. `SP Baby - Volume 1 Chapter 1` | Same unmatched regex — the tail was never stripped. One fix covers 4 and 5. |
| 6 | kagane cover blocked in the web UI | kagane serves covers behind its Cloudflare challenge **and** with `cross-origin-resource-policy: same-origin`. No `<img>` on the UI's origin can load one even from a browser holding the clearance cookie. Hot-linking cannot be made to work. |
## What changed
**Userscript.** comix titles now come from `document.title` with the chapter page's `" - Ch.<n>"` tail stripped, and the cover is the `img` whose `alt` matches the cleaned title. comix fills `document.title` a beat *after* the URL changes — later than the nav watcher's 300 ms snapshot — so the watcher also re-detects when the `detect()` signature changes, not only when the URL does. The kagane suffix regex takes an optional `Volume <v> ` segment. All three page shapes were captured live on 2026-08-08 and pinned as regression tests.
**Cover proxy.** `Bookmark.CoverURL()` rewrites a stored kagane `og:image` to `/img/kagane/{id}`; templates render `.CoverURL` instead of `.Cover`. The endpoint is session-gated like every other UI route and fetches through the shared headless browser, which is same-origin with kagane and so satisfies both the challenge and the CORP header. Results are memoised in-process, so a cover costs one navigation per deployment lifetime. With `BROWSER_WS_URL` unset the endpoint answers 404 rather than reaching for a nil fetcher — the same degrade-to-userscript behaviour the poller already has.
The image id is matched against a UUID regex before it reaches the browser. That gate is load-bearing rather than tidiness: the cover is a stored client-supplied string, so an unvalidated one turns this endpoint into an SSRF primitive aimed at the deployment's own network. `ServeMux` path-cleans a traversal into a redirect before the handler runs, but the handler does not depend on that, and a test pins it.
## Two latent bugs found underneath
**`BrowserFetcher.run` never let a challenge solve.** It navigated, waited for `body`, read once, and closed the tab — roughly half a second end to end. The Cloudflare interstitial has a `body` too, so `WaitReady` was satisfied by the challenge page itself. This made the challenge *unclearable* rather than merely slow: an interstitial needs several seconds of a live page to solve itself and write clearance into the browser's shared cookie jar, so tearing the tab down first means every subsequent call is challenged exactly like the one before it. `run` now holds one tab and re-reads until the caller's predicate reports an answer, bounded by `challengeTimeout` and the caller's own deadline. Exhausting the budget maps back to the 403 the poller already expects, keeping a challenged site distinct from a broken transport.
**`chromedp/headless-shell` cannot clear kagane's challenge at all.** It is a stripped Chrome build and the tells are structural rather than a header: `navigator.webdriver` is true, the plugin list is empty, and the client hints are Chromium- rather than Chrome-branded. Overriding `webdriver` through CDP was tried on its own and changed nothing.
All measured 2026-08-08 from one IP against the same cover, so the comparisons are like for like:
| Browser | Result |
|---------|--------|
| `chromedp/headless-shell:stable` | never cleared (90 s) |
| `zenika/alpine-chrome` | never cleared — ships Chrome 124, old enough that Cloudflare refuses it and old enough to break chromedp's CDP structs |
| `google-chrome`, default UA | never cleared (60 s) — `--headless=new` advertises `HeadlessChrome` |
| `google-chrome`, stock UA, `TZ=UTC` | never cleared (90 s) |
| `google-chrome`, stock UA, any non-UTC `TZ` | **cleared in ~4 s** |
Both remaining tells are load-bearing, and each was tested in isolation. `chrome/` is a Debian image with `google-chrome-stable`, a UA whose version is read back out of the binary at startup (a hardcoded one would drift out of step with the `Sec-CH-UA` hints on the next Chrome update and become a fresh tell), and no `--enable-automation`.
### The timezone tell: UTC, not a country mismatch
The first pass concluded the zone had to match the egress IP's country. Re-measuring against the actual deployment case shows that was wrong, and the correction is in `1552dd1`.
The original inference read the host's `/etc/timezone` (`Asia/Bangkok`) and assumed a Thai egress. It isn't — this host egresses from an Indonesian IP. `Asia/Bangkok` cleared not because it matched a country but because it simply isn't UTC, and the two share +07, which hid the distinction. Same container, same Indonesian IP:
| `TZ` | Result |
|------|--------|
| `UTC` | never cleared (60 s, **twice**) |
| `Asia/Jakarta` | cleared in 4 s |
| `America/New_York` | cleared in 4 s |
`America/New_York` matches neither the country nor the offset nor the hemisphere and clears just as fast. A UTC clock is itself the bot signal — Cloudflare scores it as the datacenter default — and any real zone satisfies the check. `BROWSER_TZ` therefore needs a plausible zone, not a geolocated one, and a deployment that changes region need not keep it in sync.
One sharp edge remains: the usual `-v /etc/localtime:/etc/localtime:ro` does **not** work. Chrome resolves the zone through ICU, which takes the name from that path's symlink target and ignores the file's contents, so glibc reports the host zone while Chrome still reports UTC. `/etc/timezone` carries the name and is mounted instead.
Chrome also binds its DevTools port to loopback and silently ignores `--remote-debugging-address`, which is why headless-shell fronted it with socat. This image does the same, so it stays a drop-in: the compose service keeps the `headless-shell` name and its pinned address, and `BROWSER_WS_URL` is unchanged.
## Verification
```
go test ./... all packages ok
node --test 37 + 12 pass, 0 fail
SMOKE_BROWSER_WS_URL=... go test -run TestSmokeKagane ./internal/latest
TestSmokeKaganeImage PASS (5.29s) fetched 56710 bytes of image/webp
TestSmokeKaganeGet PASS (1.17s) status=200, real chapter-list JSON
```
The smoke test ran against the exact compose configuration — built image, empty `BROWSER_TZ`, `/etc/timezone` mounted, cold profile — hitting real kagane.to. It skips unless `SMOKE_BROWSER_WS_URL` names a sidecar, so `go test ./...` stays hermetic and Docker-only.
A red smoke run means the challenge is not clearing from that IP, which is a live, time-varying fact to re-check rather than necessarily a defect.
## Security invariants
- Auth unchanged. `/img/kagane/{id}` is session-gated by `requireSession`, the same guard as every other UI route.
- Outbound fetch gated: the id is UUID-validated before it reaches the browser, keeping the existing rule that a client-supplied string never selects a fetch target unchecked.
- No new secrets, no new logging of credentials, no change to CORS, sessions, or crypto.
- Templates still escape everything; `.CoverURL` returns a plain string and is not wrapped in `template.HTML`/`URL`.
- One new dependency-free image (`chrome/`) built from Debian plus Google's own apt repo; no new Go modules.
## Deploying
Needs `docker compose build headless-shell`.
**A UTC host must set `BROWSER_TZ`, or kagane silently stops working.** With it unset the sidecar falls back to the host's `/etc/timezone`; on a UTC server that yields UTC, which is the one value that never clears. Any real zone works — `BROWSER_TZ=Asia/Jakarta` for the current deployment. `.env.example` now documents this; it previously did not mention the knob at all.
Only the browser sidecar reads `BROWSER_TZ`. The backend keeps its UTC clock, and stored timestamps are unix ms, so nothing else shifts.
## Deliberately not done
Retry/backoff around the cover proxy, and a panel-side cover fix. The panel renders no covers, and covers cache in-process after the first fetch. Worth adding if kagane starts rate-limiting.
## Correction after review of the deployment case
`1552dd1` was added after the branch was first pushed: the deployment host runs UTC with an Indonesian egress IP, which prompted re-measuring the timezone claim and falsifying it. The earlier commits' reasoning is left intact rather than rebased away, so the diagnostic trail — including the wrong turn and what disproved it — stays readable.
Reviewed-on: #37
Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com>
Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
146 lines
7.5 KiB
HTML
146 lines
7.5 KiB
HTML
{{define "card"}}
|
|
{{/* One sheet per series. is-new turns the title crimson over an ember rule;
|
|
is-dim sinks archived and finished rows into italic grey. */}}
|
|
<article class="card{{if eq .Status "reading"}}{{if .HasNewChapter}} is-new{{end}}{{else}} is-dim{{end}}"
|
|
id="card-{{.Key}}" data-title="{{.Title}}">
|
|
<div class="row">
|
|
<a class="cover" href="{{.ContinueURL}}" target="_blank" rel="noopener noreferrer"
|
|
tabindex="-1" aria-hidden="true">
|
|
{{if .CoverURL}}<img src="{{.CoverURL}}" alt="" loading="lazy">
|
|
{{/* aria-hidden on the cover link is not enough — Chromium still exposes
|
|
the letter because the link is programmatically focusable — so the
|
|
monogram carries its own, same as the recent strip's. */}}
|
|
{{else}}<span class="monogram" aria-hidden="true">{{.Initial}}</span>{{end}}
|
|
{{if and (eq .Status "reading") .HasNewChapter}}<span class="foot-rule"></span>
|
|
{{else if .Favorite}}<span class="foot-rule brass"></span>{{end}}
|
|
</a>
|
|
<div class="body">
|
|
<div class="title-line">
|
|
<h3 class="title">{{.Title}}</h3>
|
|
{{if .Favorite}}
|
|
<svg class="fav-mark" viewBox="0 0 24 24" aria-label="Favourite" role="img"><use href="#i-star-on"/></svg>
|
|
{{end}}
|
|
</div>
|
|
<p class="meta">
|
|
<span class="site-{{.Site}}">{{.Site}}</span>
|
|
<span class="sep">/</span>
|
|
<span class="chapter">{{.DisplayChapter}}</span>
|
|
{{if and (eq .Status "reading") .HasNewChapter}}
|
|
<span class="sep">/</span>
|
|
<span class="new-chapter">{{.DisplayLatest}} out</span>
|
|
{{end}}
|
|
{{if eq .Status "archived"}}
|
|
<span class="sep">/</span>
|
|
<span class="state">archived</span>
|
|
{{else if eq .Status "finished"}}
|
|
<span class="sep">/</span>
|
|
<span class="state"><svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-check"/></svg>finished</span>
|
|
{{end}}
|
|
</p>
|
|
</div>
|
|
<div class="actions">
|
|
<a class="play" href="{{.ContinueURL}}" target="_blank" rel="noopener noreferrer"
|
|
title="Continue reading" aria-label="Continue reading">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-play"/></svg>
|
|
</a>
|
|
<button class="fav{{if .Favorite}} on{{end}}"
|
|
title="{{if .Favorite}}Remove from favourites{{else}}Add to favourites{{end}}"
|
|
aria-label="Toggle favourite"
|
|
hx-post="/ui/bookmarks/{{.Key}}/favorite"
|
|
hx-target="[id='card-{{.Key}}']" hx-swap="outerHTML"
|
|
hx-indicator="[id='card-{{.Key}}']" hx-disabled-elt="this">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-star{{if .Favorite}}-on{{end}}"/></svg>
|
|
</button>
|
|
<button class="pencil" title="Set chapter" aria-label="Set chapter"
|
|
onclick="toggleChapterForm('{{.Key}}')">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-pencil"/></svg>
|
|
</button>
|
|
{{/* Restore is a reversal, so it fires straight away; every move *out* of
|
|
the list (archive, finish, remove) goes through a confirm row. */}}
|
|
{{if eq .Status "reading"}}
|
|
<button class="lifecycle box" title="Archive" aria-label="Archive"
|
|
aria-expanded="false" aria-controls="confirm-archive-{{.Key}}"
|
|
onclick="toggleConfirmRow('{{.Key}}', 'archive')">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-box"/></svg>
|
|
</button>
|
|
{{else}}
|
|
<button class="lifecycle restore" title="Restore to reading" aria-label="Restore to reading"
|
|
hx-post="/ui/bookmarks/{{.Key}}/status" hx-vals='{"status":"reading"}'
|
|
hx-target="[id='card-{{.Key}}']" hx-swap="outerHTML"
|
|
hx-indicator="[id='card-{{.Key}}']" hx-disabled-elt="this">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-undo"/></svg>
|
|
</button>
|
|
{{end}}
|
|
{{if ne .Status "finished"}}
|
|
<button class="lifecycle finish" title="Mark finished" aria-label="Mark finished"
|
|
aria-expanded="false" aria-controls="confirm-finish-{{.Key}}"
|
|
onclick="toggleConfirmRow('{{.Key}}', 'finish')">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-check"/></svg>
|
|
</button>
|
|
{{end}}
|
|
<button class="lifecycle remove" title="Remove" aria-label="Remove"
|
|
aria-expanded="false" aria-controls="confirm-remove-{{.Key}}"
|
|
onclick="toggleConfirmRow('{{.Key}}', 'remove')">
|
|
<svg viewBox="0 0 24 24" aria-hidden="true"><use href="#i-trash"/></svg>
|
|
</button>
|
|
</div>
|
|
</div>
|
|
<form class="chapter-form" id="chapter-form-{{.Key}}" hidden
|
|
hx-post="/ui/bookmarks/{{.Key}}/chapter"
|
|
hx-target="[id='card-{{.Key}}']" hx-swap="outerHTML"
|
|
hx-indicator="[id='card-{{.Key}}']" hx-disabled-elt="input, button">
|
|
{{/* The field holds your progress; "Latest known" is the published chapter.
|
|
Those are different numbers whenever this form is worth opening, so the
|
|
label names the field and the latest sits after it as context. */}}
|
|
<label class="hint" for="chapter-{{.Key}}">Chapter you're on</label>
|
|
<div class="field">
|
|
{{/* max is a fat-finger guard, not a real ceiling — no series is near it. */}}
|
|
<input id="chapter-{{.Key}}" name="chapter" type="number" step="0.1" min="0" max="9999"
|
|
value="{{.LastChapterNum}}" required>
|
|
<button type="submit">Save</button>
|
|
</div>
|
|
{{if .LatestChapter}}<p class="hint">Latest known: {{.DisplayLatest}}</p>{{end}}
|
|
</form>
|
|
{{/* One confirm row per way a series leaves the list. aria-live announces the
|
|
step to a screen reader, which otherwise gets no word that the tap
|
|
opened a second question. */}}
|
|
{{if eq .Status "reading"}}
|
|
<div class="confirm-row calm" id="confirm-archive-{{.Key}}" role="group" aria-live="polite" hidden>
|
|
<span>Archive this?</span>
|
|
<div>
|
|
<button class="go"
|
|
hx-post="/ui/bookmarks/{{.Key}}/status" hx-vals='{"status":"archived"}'
|
|
hx-target="[id='card-{{.Key}}']" hx-swap="outerHTML"
|
|
hx-indicator="[id='card-{{.Key}}']" hx-disabled-elt="this">Archive</button>
|
|
<button type="button" onclick="toggleConfirmRow('{{.Key}}', 'archive')">Cancel</button>
|
|
</div>
|
|
</div>
|
|
{{end}}
|
|
{{if ne .Status "finished"}}
|
|
<div class="confirm-row calm" id="confirm-finish-{{.Key}}" role="group" aria-live="polite" hidden>
|
|
<span>Mark finished?</span>
|
|
<div>
|
|
<button class="go"
|
|
hx-post="/ui/bookmarks/{{.Key}}/status" hx-vals='{"status":"finished"}'
|
|
hx-target="[id='card-{{.Key}}']" hx-swap="outerHTML"
|
|
hx-indicator="[id='card-{{.Key}}']" hx-disabled-elt="this">Finish</button>
|
|
<button type="button" onclick="toggleConfirmRow('{{.Key}}', 'finish')">Cancel</button>
|
|
</div>
|
|
</div>
|
|
{{end}}
|
|
<div class="confirm-row" id="confirm-remove-{{.Key}}" role="group" aria-live="polite" hidden>
|
|
<span>Remove “{{.Title}}”? Chapter progress is lost.</span>
|
|
<div>
|
|
<button class="danger-solid"
|
|
hx-delete="/ui/bookmarks/{{.Key}}"
|
|
hx-target="[id='card-{{.Key}}']" hx-swap="outerHTML"
|
|
hx-indicator="[id='card-{{.Key}}']" hx-disabled-elt="this">Remove</button>
|
|
<button type="button" onclick="toggleConfirmRow('{{.Key}}', 'remove')">Cancel</button>
|
|
</div>
|
|
</div>
|
|
{{/* role=status announces a failed write; without it the tap just looks
|
|
ignored to a screen reader. */}}
|
|
<p class="error-inline" role="status" hidden></p>
|
|
</article>
|
|
{{end}}
|