Conversation
Carry the response status on thrown fetch errors so a Cloudflare block is reported as a block instead of a plugin failure.
|
| if ( | ||
| name.toLowerCase().startsWith('on') || | ||
| value.startsWith('javascript:') | ||
| ) { | ||
| $(ele).removeAttr(name); |
There was a problem hiding this comment.
Chapter content can cover controls
cleanHtml keeps inline style attributes in chapters and teasers. A story author can use one to place content over the preview’s controls, because the preview inserts the returned HTML directly into the page. Strip inline styles before returning the HTML.
How this was verified: Author-controlled chapter HTML keeps style attributes and is inserted directly into the chapter preview.
There was a problem hiding this comment.
Fixed in fbcc780: cleanHtml now drops every inline style attribute (.find('[style]').removeAttr('style'), as lightnovelworld.ts does) and removes <link>/<meta> along with <style>, for both chapter and teaser HTML. I checked it on a synthetic chapter with position:fixed; z-index overlays (the styles are removed; em/strong/br/img are kept) and on a live public chapter (the text is intact). (Reply by an AI agent.)
Chapter and teaser bodies are author-written; drop style attributes and link/meta tags so content cannot be positioned over the reader.
Closes #2383
Adds a standalone plugin for Asianfanfics (
plugins/english/asianfanfics.ts) and its 96x96 icon (the site's ownfavicon-96x96.png).What it supports
Sortfilter (Trending (default), Latest, Newest, Completed, One Shots, Featured, Views, Subscriptions, Commented) and aLanguagefilter (the site's story-language list). "Latest" in the app uses the site's Latest list.<style>/<link>), inlinestyleattributes, iframes/forms,on*attributes andjavascript:URLs removed. Chapter bodies are author-written, so inline styles could otherwise lay content over the reader.The site renders listings, descriptions and chapter text as HTMX fragments (
/htmx/...) after the page loads, so the plugin requests those fragments directly. The search fragment only answers with aRefererheader, which the plugin sends.What it can't read without an account
Logged-out readers only see what the site shows them ("Sign in to see every story"). Many stories are marked Members Only, Subscribers Only or Friends Only. Their story pages and chapter lists are public, but chapter text is not. For those chapters the plugin returns the site's own notice (for example "Please log in to read further chapters.") with a note that the chapter needs an Asianfanfics account, plus the public teaser the site shows when there is one. The plugin has no login or credential handling and does not try to get around these restrictions.
Testing
npx eslint plugins/english/asianfanfics.ts,npx prettier --check plugins/english/asianfanfics.tsandnpm run build:compilepass locally. CI Lint Check and Format Check pass.popularNovels | INCONCLUSIVE | HTTP 403 (Cloudflare). On the first commit this check was FAIL (run https://github.com/lnreader/lnreader-plugins/actions/runs/36696977845). The runner got past the site probe, but the fragment request got the same 403. The plugin was throwing a plainErrorwith no status, so the checker couldn't tell it was a block. The follow-up commit keepsstatus/responseon the thrown error, the way dragonholic/daotekno do. The checker was not changed.fetch(undici), both/and/htmx/browse/en/trending?page=1return 403 withcf-mitigated: challenge, with or without a browser User-Agent,HX-RequestorReferer.curlgets 200 on the same URLs. So this is Cloudflare's bot check on the client, not a header the plugin is missing.npm run check:plugin -- plugins/english/asianfanfics.tsreports INCONCLUSIVE atsiteReachability(HTTP 403, Cloudflare). A local, uncommitted copy of the checker with the site probe skipped (as on the runner) reportspopularNovelsINCONCLUSIVE (HTTP 403, Cloudflare) after the fix.fetchthroughcurl. It passed: popularNovels 30 novels, searchNovels found the novel, parseNovel 12 chapters, parseChapter 14334 chars (a subscribers-only chapter: notice plus teaser).koon Latest returns 30 stories; some sorts such as Trending have no stories for some languages, and the site says so); search pages 1 and 2 differ; a public chapter returns the full text; a members-only chapter returns the notice plus teaser; a completed story reportsCompleted; the sanitizer stripsonclick/onerrorandjavascript:hrefs on a synthetic sample. After the style fix (fbcc780): a synthetic chapter withposition:fixed; z-indexoverlays and<style>/<link>tags comes back with no styles while keepingem/strong/br/img; a live public chapter still returns its full text (1292 paragraphs) with nostyleattributes; the curl-backed checker copy passes again (popularNovels 30, parseNovel 12 chapters, parseChapter 14334 chars).This PR was written by an AI agent (Claude); no human has reviewed it yet.