b0bf6fe770
Guild membership is now the whole gate: discordCallback checks membership
(and DISCORD_REQUIRED_ROLE when set), then Store.EnsureReader creates the
Reader on first sight and returns the same row on every later login. The
refusal returns before EnsureReader, so nothing is created as a side
effect of being turned away. OWNER_DISCORD_ID keeps seeding the owner, but
only as the administrator — it no longer gates sign-in.
The cutover grace path is gone with it: API_TOKEN, API_TOKEN_GRACE_UNTIL
and the legacy branch in httpmw.ResolveReader are deleted, so a credential
authenticates exactly one Reader or nothing. That also lets
userscript.Handler drop the re-derivation — the resolved path segment is
already the credential to substitute.
New surfaces: an empty library offers both install links instead of
describing a filter (listView.Fresh, which also hides the action key it has
nothing to name), and the owner alone gets a Readers panel with
POST /readers/{id}/revoke (404 for anyone else) to sign a Reader out
everywhere.
Isolation is asserted from both directions rather than by counting one
Reader's rows, and the shared-series invariant is pinned: two Readers on
one series produce one series row, two independent progresses, one poll
per due cycle, and one Reader's delete leaves the other's bookmark and the
poll intact.
93 lines
4.6 KiB
Bash
93 lines
4.6 KiB
Bash
# Copy to .env and fill in. Never commit the real .env.
|
|
|
|
# Secret every Reader's userscript credential is derived from (issue #24):
|
|
# the backend rebuilds install URLs from it, and only SHA-256 hashes of the
|
|
# credentials ever touch the database. Generate one:
|
|
# openssl rand -hex 32
|
|
TOKEN_KEY=changeme-generate-a-long-random-token
|
|
|
|
# The owner's Discord user ID — seeded at startup as the first Reader, the
|
|
# administrator (the only one who can revoke another Reader's sessions), and
|
|
# the owner of every bookmark that predates registration. Discord snowflake,
|
|
# e.g. 1046923170000000000.
|
|
OWNER_DISCORD_ID=changeme-your-discord-user-id
|
|
|
|
# Comma-separated origins allowed to call the API (CORS). Both Asura domains
|
|
# plus Demonic, Comix, Kagane, and the two novel sites. Add/remove as the
|
|
# sites' hostnames change.
|
|
ALLOWED_ORIGINS=https://asuracomic.net,https://asurascans.com,https://demonicscans.org,https://comix.to,https://kagane.to,https://novelfull.com,https://lightnovelworld.net
|
|
|
|
# Password for the bundled Postgres container, and therefore half of the
|
|
# DATABASE_URL compose builds for the backend. Generate one:
|
|
# openssl rand -hex 24
|
|
POSTGRES_PASSWORD=changeme-generate-a-long-random-password
|
|
|
|
# Override only to point the backend at a Postgres compose does not run.
|
|
# DATABASE_URL=postgres://user:pass@host:5432/bookmarks?sslmode=require
|
|
|
|
# --- Prod override (Traefik) only ---
|
|
# Subdomain Traefik routes to this service (required by the prod override).
|
|
# BOOKMARK_API_HOST=bookmark-api.example.com
|
|
# Traefik's docker network name, if not "proxy".
|
|
# PROXY_NETWORK=proxy
|
|
# Traefik HTTPS entrypoint + cert resolver names, if yours differ from these.
|
|
# TRAEFIK_ENTRYPOINT=websecure
|
|
# TRAEFIK_CERTRESOLVER=le
|
|
|
|
# --- Web UI (Discord OAuth) ---
|
|
# Sign-in is a Discord authorization code grant (ADR-0002), and it is also
|
|
# registration: any member of the configured guild becomes a Reader on their
|
|
# first successful login, with their own empty library. Create the application
|
|
# at https://discord.com/developers/applications and register the exact
|
|
# callback URL ($BOOKMARK_WEB_HOST/auth/discord/callback) as an OAuth2
|
|
# redirect.
|
|
DISCORD_CLIENT_ID=
|
|
DISCORD_CLIENT_SECRET=
|
|
# The guild whose membership gates sign-in (Developer Mode -> right-click the
|
|
# server -> Copy Server ID).
|
|
DISCORD_GUILD_ID=
|
|
# Exact callback URL, e.g. https://bookmark.example.com/auth/discord/callback.
|
|
# Discord matches it verbatim, so it must equal the registered redirect.
|
|
DISCORD_REDIRECT_URI=
|
|
# Optional: a role snowflake members must hold on top of guild membership.
|
|
# Empty (the default) means membership alone suffices.
|
|
# DISCORD_REQUIRED_ROLE=
|
|
|
|
# Subdomain Traefik routes to the browser UI (required by the prod override).
|
|
# Left commented on purpose: an example value here would be a silent
|
|
# wrong-hostname fallback, and Traefik would publish the UI router on a domain
|
|
# you do not own. The same container also answers on BOOKMARK_API_HOST for the
|
|
# userscript's API.
|
|
# BOOKMARK_WEB_HOST=bookmark.example.com
|
|
|
|
# --- Latest-chapter poller ---
|
|
# The backend re-checks each bookmarked series' newest published chapter on its
|
|
# own schedule, so latest_chapter stays fresh even when you never open the manga
|
|
# sites. This runs in parallel with the userscript's own in-browser check.
|
|
# Set to 0 to turn it off entirely.
|
|
# LATEST_CHAPTER_POLL_ENABLED=1
|
|
#
|
|
# Two independent clocks. COOLDOWN is how long one series rests between checks;
|
|
# INTERVAL is how often the poller wakes up and looks for series past that
|
|
# cooldown. Shortening INTERVAL cannot shorten a COOLDOWN.
|
|
# LATEST_CHAPTER_POLL_COOLDOWN=1h # per series, floor 15m
|
|
# LATEST_CHAPTER_POLL_INTERVAL=10m # how often to wake
|
|
# LATEST_CHAPTER_POLL_BATCH=14 # series per wake
|
|
# LATEST_CHAPTER_POLL_STAGGER=20s # delay between fetches in a batch
|
|
#
|
|
# Uses a ticker, not an immediate first run: the first poll happens one
|
|
# INTERVAL after startup, not at startup. A container restarting more often
|
|
# than INTERVAL never polls.
|
|
#
|
|
# BATCH x (COOLDOWN / INTERVAL) series hold the cooldown cadence — 84 with these
|
|
# defaults. Beyond that the cadence stretches uniformly rather than breaking;
|
|
# raise BATCH or lower INTERVAL. Keep BATCH x STAGGER under INTERVAL.
|
|
|
|
# Headless-shell CDP endpoint for sites behind a JavaScript challenge (kagane).
|
|
# Unset disables browser polling; those sites then rely on the userscript alone.
|
|
# Leave commented — the compose files' own default (ws://172.28.0.10:9222) is
|
|
# correct. Do NOT set this to the "headless-shell" DNS name: Chrome's DevTools
|
|
# HTTP handler 500s any /json/version request whose Host header isn't an IP or
|
|
# "localhost", which silently breaks every kagane poll.
|
|
# BROWSER_WS_URL=ws://172.28.0.10:9222
|