Add --port

This commit is contained in:
2026-09-12 23:48:03 +02:00
parent a180fe4b52
commit da36645aaf
14 changed files with 677 additions and 40 deletions
+11 -13
View File
@@ -32,27 +32,25 @@
errorBox.hidden = !msg;
}
// --- token memory -------------------------------------------------------
// Kept in localStorage only so the field survives a reload; it is never sent
// anywhere but this origin's upload endpoint.
try {
var saved = localStorage.getItem('send.token');
if (saved && tokenInput) tokenInput.value = saved;
} catch (e) { /* private mode; not important */ }
// --- credentials --------------------------------------------------------
// A token is remembered in an HttpOnly cookie the server sets, not here:
// this script cannot read it back, so an injected script cannot steal it
// either. The page is told who it is by the server when it renders, and the
// limits panel is refreshed from /api/limits, which reads the same cookie.
function refreshLimits() {
var token = tokenInput ? tokenInput.value.trim() : '';
try {
if (token) localStorage.setItem('send.token', token);
else localStorage.removeItem('send.token');
} catch (e) { /* ignore */ }
var xhr = new XMLHttpRequest();
xhr.open('GET', base + 'api/limits');
xhr.setRequestHeader('Accept', 'application/json');
// Sent only when the field holds something; otherwise the cookie answers.
if (token) xhr.setRequestHeader('Authorization', 'Bearer ' + token);
xhr.onload = function () {
if (xhr.status !== 200) return;
if (xhr.status !== 200) {
if (xhr.status === 401 && token) showError('That token is not recognised.');
return;
}
showError('');
var l;
try { l = JSON.parse(xhr.responseText); } catch (e) { return; }
limits = l;