sunnymh-manga-site/lib/api-guards.ts
yiekheng b993de43bc Reader: fix resume bug, add loading skeleton, scraping protection, bounded image cache
- Resume scroll position only when arriving via 继续阅读 (?resume=1).
  Plain chapter-list / drawer clicks now actively scroll to top on mount.
- Progress format extended to {chapter, page, ratio} for within-page
  precision; legacy bare-number and {chapter, page} still read correctly.
- Tappable skeleton logo (sunflower outline, spins) while a page loads;
  tap force-fetches a fresh signed URL.
- Viewport-priority image loading: second IntersectionObserver at margin 0
  marks truly-visible pages, drives <img fetchpriority="high"> and fires
  immediate single-page fetches that cut the batch queue.
- Bounded image cache: unmount previous chapter's <img> elements when
  currentPage > 5 into the new chapter; placeholders stay for layout.
  One AbortController per live chapter; unmount aborts in-flight batches.
- Hashed chapter IDs on the wire via hashids; DB PKs unchanged.
- Origin/Referer allowlist + rate limiting on all /api/* routes via a
  withGuards(opts, handler) wrapper (eliminates 6-line boilerplate x5).
- robots.txt allows Googlebot/Bingbot/Slurp/DuckDuckBot/Baiduspider/
  YandexBot only; disallows /api/ for all UAs.
- Extract pure helpers for future TDD: lib/scroll-ratio.ts (calcScrollRatio,
  scrollOffsetFromRatio), lib/progress.ts (parseProgress + injectable
  StorageLike), lib/rate-limit.ts (optional { now, store, ipOf } deps),
  lib/api-guards.ts.
- New env keys: HASHIDS_SALT, ALLOWED_ORIGINS (wired into docker-compose).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-15 21:48:15 +08:00

33 lines
748 B
TypeScript

import { checkOrigin } from "@/lib/origin-check";
import { checkRateLimit } from "@/lib/rate-limit";
type RateLimitOpts = {
key: string;
limit: number;
windowMs: number;
};
type GuardOpts = {
origin?: boolean;
rateLimit?: RateLimitOpts;
};
type Handler<TCtx> = (request: Request, ctx: TCtx) => Promise<Response>;
export function withGuards<TCtx>(
opts: GuardOpts,
handler: Handler<TCtx>
): Handler<TCtx> {
return async (request, ctx) => {
if (opts.origin !== false) {
const blocked = checkOrigin(request);
if (blocked) return blocked;
}
if (opts.rateLimit) {
const blocked = checkRateLimit(request, opts.rateLimit);
if (blocked) return blocked;
}
return handler(request, ctx);
};
}