2ef769d421
Closes #27. Guild membership is now the whole gate. `discordCallback` checks membership (and `DISCORD_REQUIRED_ROLE` when set), then `Store.EnsureReader` creates the Reader on first sight and returns the same row on every later login. The refusal returns before `EnsureReader`, so a turned-away sign-in leaves no row behind. `OWNER_DISCORD_ID` still seeds the owner, but only as the administrator — it no longer gates login. The cutover grace path goes with it: `API_TOKEN`, `API_TOKEN_GRACE_UNTIL` and the legacy branch in `httpmw.ResolveReader` are deleted, so a credential authenticates exactly one Reader or nothing. `userscript.Handler` drops its re-derivation too — the resolved path segment is already the credential. New surfaces: an empty library offers both install links (behind the tab-specific empty states, so "No favourites yet" still wins), and the owner alone gets a Readers panel with `POST /readers/{id}/revoke`. The owner's own row is not revocable — 404, not a self-logout. Isolation is asserted from both directions for read, modify and delete, and the shared-series invariant is pinned: two Readers on one series produce one series row, two independent progresses, one poll per due cycle, and one Reader's delete leaves the other's bookmark and the poll intact. Verified: `go test ./...` green; live smoke against a throwaway Postgres — empty-library state in both colour branches, roster rendering, a real revoke through the panel (target 401s next request, owner untouched), owner self-revoke refused 404, per-Reader `/u/<cred>` and bearer auth both 200 with 404 for an unknown credential. Reviewed-on: #36 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
34 lines
1.8 KiB
HTML
34 lines
1.8 KiB
HTML
{{define "list"}}
|
|
{{if .Items}}
|
|
{{range .Items}}{{template "card" .}}{{end}}
|
|
{{/* The client filter only hides cards, so without this the list area goes
|
|
blank on a query that matches nothing. filter.js fills in the query and
|
|
unhides it; it lives inside #list so a tab swap re-creates it. */}}
|
|
<div class="empty" id="no-match" hidden>
|
|
<strong>No titles match “<span class="no-match-q"></span>”.</strong>
|
|
<button type="button" class="clear-search">Clear search</button>
|
|
</div>
|
|
{{else if eq .Tab "fav"}}
|
|
<div class="empty"><strong>No favourites yet.</strong><p>Star a series to pin it here.</p></div>
|
|
{{else if eq .Tab "new"}}
|
|
<div class="empty"><strong>Nothing new.</strong><p>Every series is caught up to its latest chapter.</p></div>
|
|
{{else if eq .Tab "archived"}}
|
|
<div class="empty"><strong>Nothing archived.</strong><p>Shelve a series to park it here — it keeps getting checked for new chapters.</p></div>
|
|
{{else if eq .Tab "finished"}}
|
|
<div class="empty"><strong>Nothing finished yet.</strong><p>Mark a series finished and it moves out of your reading list.</p></div>
|
|
{{else if .EmptyLibrary}}
|
|
{{/* Nothing in either library, so the links are the only thing this page can
|
|
usefully say. Both scripts: the two libraries are separate installs. */}}
|
|
<div class="empty">
|
|
<strong>Nothing here yet.</strong>
|
|
<p>Install the userscripts, then open a series and read a chapter — bookmarks arrive on their own.</p>
|
|
<p class="setup-links">
|
|
<a class="ghost" href="/install/manga-bookmark.user.js">Install Manga script</a>
|
|
<a class="ghost" href="/install/novel-bookmark.user.js">Install Novels script</a>
|
|
</p>
|
|
</div>
|
|
{{else}}
|
|
<div class="empty"><strong>Nothing here yet.</strong><p>Bookmarks appear once the userscript records a chapter.</p></div>
|
|
{{end}}
|
|
{{end}}
|