180ee78b1f
Tracks read progress on comix.to and kagane.to alongside asura and demonic, in both the userscript and the backend. Implements `docs/superpowers/plans/2026-08-03-comix-kagane-support.md`. ## Userscript - `comix` adapter — `/title/<id>-<slug>`; only the id prefix is identity (the slug follows the title). No `og:image`, so the cover is matched by `alt`. - `kagane` adapter — reader URLs are uuids with no chapter number, so it comes out of `og:title`; anchor scanning is structurally impossible, replaced by `latestChapterFromApi` against kagane's same-origin JSON API. - `seriesId` threaded through `latestChapterFromAnchors` so comix can scope its scan to its own series and a recommendation strip cannot win the maximum. - `@match` for both hosts, panel chips, v1.6.0. ## Backend - `latestChapterFrom` cases: comix parses the SSR JSON state blob (`latestChapterUrl`, scoped to the series id); kagane parses API JSON (`chapter_no`). - Poller allowlist extended; `Poller.BrowserFetch` with `fetcherFor(site)` routes kagane to a browser fetcher. Nil means kagane is not polled at all — never a fallback to the TLS fetcher, which would only ever retrieve a challenge page. - `BrowserFetcher`: chromedp against a `headless-shell` sidecar. kagane sits behind a Cloudflare JS challenge that no TLS fingerprint clears, and the request is made inside the page rather than by replaying `cf_clearance`. - `BROWSER_WS_URL` wiring, sidecar in both compose files (no `ports:`, dedicated non-external network), Dockerfile on `golang:1.26-alpine` — chromedp requires go 1.26. - Web UI `--comix` / `--kagane` tokens in both colour branches. ## Notes for review - `series_url` is client-supplied and a headless browser is a strong SSRF primitive, so kagane's host is pinned twice: in `fetchableSeriesURL` and again in `kaganeAPIURL`. - Three chained defects found during verification made the browser path dead under Compose (sidecar flag collision, Chrome's Host-header DNS-rebinding check, the wrong chromedp option). Fixed; the compose comments record the wrong configurations too, so they don't get "simplified" back. - `ALLOWED_ORIGINS` now includes both new origins. Without it every write from comix/kagane silently fails CORS preflight, parks in the retry queue, and drops at the cap. ## Verification 221 backend tests, 32 userscript tests, static `CGO_ENABLED=0` build, both compose configs. Two gaps, both real: 1. The userscript on live pages via Violentmonkey needs a human browser profile — not run. Check: comix series page (title/cover, no chapter), comix chapter page (records the number; an *older* chapter must not regress it), comix SPA navigation without reload, kagane series page (og:image cover), kagane reader (number from `og:title`), both chips opening the right sites. 2. The kagane browser path has not completed end-to-end anywhere. Dial/navigate/fetch is confirmed, but Cloudflare 403'd headless-shell's Chrome on every attempt from the dev sandbox, and comix's poll-through-Docker was blocked by that environment's TLS interception. Both environment-dependent rather than branch defects — the first real deploy is the actual verification. Reviewed-on: #13 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
59 lines
2.8 KiB
YAML
59 lines
2.8 KiB
YAML
# Production override: join an existing Traefik network and let Traefik route
|
|
# manga-api.<domain> -> this service with TLS. No host port published.
|
|
#
|
|
# docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d --build
|
|
#
|
|
# Set in .env:
|
|
# MANGA_API_HOST=manga-api.example.com # your subdomain (required)
|
|
# MANGA_WEB_HOST=manga.example.com # browser UI subdomain, same container (required)
|
|
# PROXY_NETWORK=proxy # Traefik's network name, if not "proxy"
|
|
# TRAEFIK_ENTRYPOINT=websecure # your HTTPS entrypoint name
|
|
# TRAEFIK_CERTRESOLVER=le # your ACME/cert resolver name
|
|
#
|
|
# The network must already exist and Traefik must watch it:
|
|
# docker network create proxy # if it doesn't yet
|
|
|
|
services:
|
|
manga-api:
|
|
# Traffic arrives over the Traefik network, not a published port.
|
|
ports: !reset []
|
|
environment:
|
|
# Must be an IP, not the DNS name — see the base file's comment on this
|
|
# same key: Chrome's DevTools HTTP handler 500s any Host header that
|
|
# isn't an IP or "localhost".
|
|
BROWSER_WS_URL: ${BROWSER_WS_URL:-ws://172.28.0.10:9222}
|
|
depends_on:
|
|
- headless-shell
|
|
# `networks:` here replaces the base file's list entirely, so both must be
|
|
# named: `proxy` for Traefik routing, `browser` (defined in the base file)
|
|
# to keep reaching headless-shell without putting it on `proxy` too.
|
|
networks:
|
|
- proxy
|
|
- browser
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.docker.network=${PROXY_NETWORK:-proxy}"
|
|
- "traefik.http.routers.mangabm.rule=Host(`${MANGA_API_HOST:?set MANGA_API_HOST in .env}`)"
|
|
- "traefik.http.routers.mangabm.entrypoints=${TRAEFIK_ENTRYPOINT:-websecure}"
|
|
- "traefik.http.routers.mangabm.tls=true"
|
|
- "traefik.http.routers.mangabm.tls.certresolver=${TRAEFIK_CERTRESOLVER:-le}"
|
|
- "traefik.http.services.mangabm.loadbalancer.server.port=8080"
|
|
# Second hostname for the browser UI, same container. Traefik needs the
|
|
# service named explicitly once more than one router targets it.
|
|
- "traefik.http.routers.mangabm.service=mangabm"
|
|
- "traefik.http.routers.mangaweb.rule=Host(`${MANGA_WEB_HOST:?set MANGA_WEB_HOST in .env}`)"
|
|
- "traefik.http.routers.mangaweb.entrypoints=${TRAEFIK_ENTRYPOINT:-websecure}"
|
|
- "traefik.http.routers.mangaweb.tls=true"
|
|
- "traefik.http.routers.mangaweb.tls.certresolver=${TRAEFIK_CERTRESOLVER:-le}"
|
|
- "traefik.http.routers.mangaweb.service=mangabm"
|
|
|
|
# headless-shell is untouched here: it keeps its `browser` network membership
|
|
# from the base file and must never join `proxy` — that network is shared
|
|
# with whatever else sits behind Traefik on this host, and an exposed
|
|
# CDP endpoint on it would be remote code execution for any of them.
|
|
|
|
networks:
|
|
proxy:
|
|
external: true
|
|
name: ${PROXY_NETWORK:-proxy}
|