Skip to content

feat(english): add We Tried TLS source plugin - #2588

Merged
rajarsheechatterjee merged 4 commits into
lnreader:masterfrom
RevDev909:feat/wetriedtls-plugin
Sep 28, 2026
Merged

rajarsheechatterjee merged 4 commits into
lnreader:masterfrom
RevDev909:feat/wetriedtls-plugin

Conversation

@RevDev909

Copy link
Copy Markdown
Contributor

Adds the We Tried TLS (wetriedtls.com) source plugin for English-translated Korean web novels.

Implementation notes:

  • Catalog and search use the site's public API; chapter lists merge free and paid chapters, with paid ones shown under a visible lock prefix. Opening a paid chapter shows the site's premium notice — access controls are not bypassed.
  • Chapter bodies live in Next.js Flight payloads; the row's hex prefix is the exact UTF-8 byte length of the payload and is used as the slice boundary (a next-row lookahead overshoots into flight metadata).
  • Gallery/illustration chapters embed their HTML inline in chapter_content instead of a flight row; both formats are handled, and image and heading blocks are preserved.

Verified: popularNovels, searchNovels, parseNovel and parseChapter all pass against the live site; ESLint and Prettier are clean.

@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 1/5

[Medium risk] Adds a new content source plugin for a novel site.

The PR is not safe to merge until chapter HTML is sanitized and the image-only and failed-pagination paths are corrected.

Findings

  1. P1 Security Unsafe chapter HTML reaches reader ▶
  2. P1 Image-only chapters appear unavailable ▶
  3. P1 Failed requests truncate chapter lists ▶
  4. P2 Covers depend on external proxy ▶

Summary

Adds an English We Tried TLS source with API-backed catalog, search, and free/paid chapter lists, plus Flight-payload chapter extraction and a source icon.

  • The chapter HTML path needs sanitization, and image-only chapters need to remain readable.
  • A failed free-chapter page can silently truncate the list; proxied covers have no direct fallback.

Reviews (1) · Last reviewed commit: "feat(english): add We Tried TLS icon"

Comment on lines +324 to +326
const blocks = body.match(
/<p[\s\S]*?<\/p>|<h[1-6][\s\S]*?<\/h[1-6]>|<figure[\s\S]*?<\/figure>|<img[^>]*>/gi,
) || [body];

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Unsafe chapter HTML reaches reader

If a remote chapter contains an event handler, such as an image with an onerror attribute, these blocks preserve it and the reader inserts the HTML without sanitizing it. That allows code from the chapter page to run in the reader. Sanitize the retained HTML before returning it.

How this was verified: Remote chapter markup retains its attributes and reaches the reader’s unsanitized HTML insertion point.

while (start < end && isEdgeJunk(blocks[start])) start++;
while (end > start && isEdgeJunk(blocks[end - 1])) end--;
const cleaned = blocks.slice(start, end).join('\n');
if (!paragraphText(cleaned)) return { status: 'empty' };

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Image-only chapters appear unavailable

For a chapter made entirely of illustrations, paragraphText strips the image tags and finds no text. This check marks the chapter empty, so readers see “Could not load this chapter” instead of its images. Treat retained images as nonempty content.

Suggested change
if (!paragraphText(cleaned)) return { status: 'empty' };
if (!paragraphText(cleaned) && !/<img[\s>]/i.test(cleaned))
return { status: 'empty' };

'&perPage=500&order=asc',
),
);
lastPage = page.lastPage;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Failed requests truncate chapter lists

If a free-chapter page request fails, fetchText returns an empty string. The parser then defaults lastPage to 1, and this assignment stops pagination. parseNovel returns an incomplete chapter list as though it were complete; the request failure needs to be handled separately.

Comment thread plugins/english/wetriedtls.ts Outdated
Comment on lines +246 to +250
return (
'https://images.weserv.nl/?url=' +
encodeURIComponent(bare) +
'&w=400&q=80&output=webp'
);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Covers depend on external proxy

Every HTTP cover URL is replaced with an images.weserv.nl URL, with no fallback to the original image. If that proxy is blocked or unavailable while the source CDN still works, all covers for this plugin fail to load. Keeping a direct-image fallback would avoid that dependency.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@rajarsheechatterjee
rajarsheechatterjee merged commit 3508214 into lnreader:master Sep 28, 2026
3 checks passed
@RevDev909

Copy link
Copy Markdown
Contributor Author

Addressed all four review findings:

  • Chapter HTML is now sanitized before it reaches the reader: script/iframe/object-style elements are removed, event-handler attributes (e.g. onerror) are stripped, and javascript: URLs are neutralized. All other markup is preserved.
  • Image-only chapters (illustrations with no text) are now treated as real content instead of 'empty'.
  • A failed chapter-list page can no longer silently truncate the list: a blank response throws, so parseNovel fails loudly instead of returning an incomplete list as though it were complete.
  • Covers now use the site's direct CDN URL. A single URL field can't carry a fallback, so the images.weserv.nl proxy dependency is gone (in-chapter illustration shrinking is unchanged).

No test files added to this PR, per your note on #2575.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants