Repository navigation
Redesign xmoj-script.uk and deploy the site on every push - #1043
Conversation
- Rewrite index.html: new copy, feature grid, 3-step install with browser detection and the Chrome/Edge "allow user scripts" step, FAQ, feedback. Drop AdSense, the inline GPL text, and the screenshot carousel. - Add shared site.css (tokens copied from MonochromeSkinCSS in XMOJ.user.js) and site.js (theme toggle, browser detection, live version from Update.json). - Rebuild 404.html in the same style. - Rewrite privacy/terms/child-protection in plain Chinese based on what the script and XMOJ-bbs actually store. - Remove the dead SSO login tab and its code from messages.html. - Move links off the dead xmoj-bbs.me domain (site, README, sitemap); add the sitemap to robots.txt. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
- New Deploy workflow deploys on every push to master (Cloudflare Pages + GitHub Pages) and dev (GitHub Pages). Release/Prerelease now only cut releases, so site-only changes no longer wait for a script release. - Track XMOJ-bbs master in .gitmodules and let Dependabot open daily submodule bump PRs against dev. - Bump backend to 7bd99ac (latest master, includes the session log redaction from XMOJ-bbs#72). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
Reviewer's GuideThis PR modernizes the website with a shared monochrome responsive UI, clearer browser-aware installation instructions and rewritten policy pages, removes obsolete SSO/dead-link integrations, and introduces push-triggered Cloudflare Pages/GitHub Pages deployment plus automated submodule updates. Review should block merging until the backend privacy fix is live and the new deployment workflow and real messages login have been verified. Sequence diagram for browser-aware userscript installationsequenceDiagram
actor User
participant Site as xmoj-script.uk
participant Browser as Browser
participant Manager as Tampermonkey_or_ScriptCat
participant XMOJ as xmoj.tech
User->>Site: Open installation section
Site->>Browser: DetectBrowser()
Browser-->>Site: Chrome, Edge, Firefox, or Safari
Site->>Site: ChromeMajorVersion()
Site-->>User: Show browser-specific instructions
User->>Browser: Enable userscript permission or developer mode
User->>Site: Click XMOJ.user.js
Site->>Manager: Download userscript
User->>Manager: Install script
User->>XMOJ: Open and refresh xmoj.tech
Manager-->>XMOJ: Run XMOJ-Script
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Deploying xmoj-script-dev-channel with
|
| Latest commit: |
c7549b0
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://64584c15.xmoj-script-dev-channel.pages.dev |
| Branch Preview URL: | https://website-redesign.xmoj-script-dev-channel.pages.dev |
There was a problem hiding this comment.
Hey - I've found 4 issues
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path=".github/workflows/Deploy.yml" line_range="26" />
<code_context>
+ steps:
+ - uses: actions/checkout@v6
+ - uses: cloudflare/pages-action@v1
+ if: github.ref == 'refs/heads/master'
+ with:
+ apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
+ accountId: 89969bdf9d5ab8202f8ad8b8ae2c40b8
+ projectName: xmoj-script
+ directory: .
+ - uses: actions/configure-pages@v5
+ - uses: actions/upload-pages-artifact@v3
+ with:
</code_context>
<issue_to_address>
**issue (broader_impact):** A failure in the Cloudflare Pages deployment stops the job before `configure-pages`, `upload-pages-artifact`, and `deploy-pages` run, so GitHub Pages is not deployed either. The documented transient Cloudflare API failure therefore prevents the GitHub Pages deployment from completing.
**Triggers:** When the Cloudflare Pages action returns an error on a master push.
**Suggested fix:** Put the Cloudflare and GitHub Pages deployments in separate jobs, or otherwise allow the GitHub Pages job to run independently of Cloudflare failures.
```suggestion
if: github.ref == 'refs/heads/master'
continue-on-error: true
```
</issue_to_address>
### Comment 2
<location path=".github/workflows/Deploy.yml" line_range="6" />
<code_context>
+name: Deploy
+on:
+ push:
+ branches:
+ - master
+ - dev
+ workflow_dispatch:
+# master 与 dev 共用同一个 GitHub Pages 站点,避免两次部署同时进行
</code_context>
<issue_to_address>
**issue (bug_risk):** Pushes to `dev` deploy the checked-out dev branch to the same public `github-pages` environment/site used by `master`, so a dev push overwrites the public site with development content instead of providing an isolated dev deployment.
**Triggers:** When dev receives a push after a master deployment.
**Suggested fix:** Use a separate Pages site/environment for dev, or remove `dev` from this public deployment workflow and publish it through a branch-specific preview.
```suggestion
```
</issue_to_address>
### Comment 3
<location path="privacy.html" line_range="92" />
<code_context>
+ </table>
+ </div>
+ <p>发帖等操作可能需要通过 Cloudflare Turnstile 人机验证,验证时你的 IP 地址会发送给 Cloudflare。</p>
+ <p>服务器的运行日志会记录用户名和会话哈希值的前几位,用于排查故障,不包含会话本身。</p>
- <h3>四、信息共享与披露</h3>
</code_context>
<issue_to_address>
**issue:** The privacy page states that runtime logs contain only a session-hash prefix, but the repository change only updates the backend submodule pointer and does not make the failed Cloudflare backend deployment live. Until that backend deployment succeeds, the published policy contradicts the actual logging behavior and exposes an inaccurate privacy disclosure.
**Triggers:** When the site deploys before XMOJ-bbs#72 is live on the API backend.
**Suggested fix:** Do not publish this wording until the backend deployment succeeds, or describe the currently deployed logging behavior and update the page after rollout.
```suggestion
```
</issue_to_address>
### Comment 4
<location path="404.html" line_range="105" />
<code_context>
+ </div>
+ </footer>
+ <script>
+ document.getElementById("RequestedPath").textContent = decodeURI(location.pathname);
+ </script>
+</body>
</code_context>
<issue_to_address>
**nitpick (bug_risk):** `decodeURI(location.pathname)` throws `URIError` for a malformed percent-encoded request path, producing a console error and leaving the requested-path diagnostic unset on the 404 page.
**Triggers:** When a user requests a path containing an invalid percent escape such as `%`.
**Suggested fix:** Wrap the decode in `try/catch` or use the raw `location.pathname` as a fallback.
```suggestion
try {
document.getElementById("RequestedPath").textContent = decodeURI(location.pathname);
} catch {
document.getElementById("RequestedPath").textContent = location.pathname;
}
```
</issue_to_address>Sourcery assessment
Needs a human reviewer. 3 findings to address first, and the new workflow publishes repository contents on every push and grants GitHub Pages, deployment, and OIDC permissions, so a mistaken change can take the public site down or publish unintended content. Reverting stops future deployments, but it does not undo an already-published artifact without another deployment.
Blocking findings: .github/workflows/Deploy.yml:26, .github/workflows/Deploy.yml:6, privacy.html:92
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 96c57e1c4a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
All reported issues were addressed across 17 files
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
- Replace the CSS mock status card with screenshots of xmoj.tech running XMOJ.user.js with MonochromeUI (contest problem page), captured with tests/userscript-harness.cjs in light and dark theme. The username in the navbar is blurred. The shown image follows the site theme. - The logo is 317x180; keep its aspect ratio instead of forcing 32x32. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
There was a problem hiding this comment.
All reported issues were addressed across 4 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
- Deploy: split Cloudflare Pages and GitHub Pages into separate jobs so a Cloudflare failure no longer blocks the GitHub Pages deploy. - Pin Bootstrap CSS/JS with SRI (sha512 from cdnjs, verified locally). - 404: resolve assets/links through <base> so the page works under the github.io /XMOJ-Script/ project path; don't throw on malformed paths. - Show the latest stable version from Update.json, not a prerelease. - Replace the ↗ character (renders as emoji on Apple devices) with a CSS arrow that follows the text color. - Browser picker: toggle buttons with aria-pressed instead of fake tabs. - Chrome 138+ step covers ScriptCat as well as Tampermonkey. - Link 短消息在线看 from the main nav and add a homepage section for it. - Privacy: Clarity is site-wide; state the product is not intended for EU residents. Child protection: admins can technically read messages; GitHub Issues are public, send identifying details by email. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
Messages are AES-encrypted before storage (XMOJ-bbs Process.ts SendMail), so admins can't read them without changing server code. Say that, note it's not end-to-end, and ask reporters to include a screenshot. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
There was a problem hiding this comment.
All reported issues were addressed across 8 files (changes from recent commits).
Requires human review: Auto-approval blocked because this review re-detected 1 unresolved issue already reported by Cubic.
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
- Drop Microsoft Clarity from every page: Microsoft says it shouldn't be used on sites aimed at under-18s, and most of our users are minors. - Privacy: replace "以代码为准" with a commitment to keep the page in sync; rephrase the EU notice; say third parties do process data instead of "不会交给其他人"; add a third-party services table; warn that uploaded images are public by link and can't be self-deleted; state that unread messages currently have no retention limit. - Child protection: "不会要求提供…个人照片" instead of "不收集照片"; extend the personal-info warning to images. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
…rialize Cloudflare deploys Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
There was a problem hiding this comment.
All reported issues were addressed across 3 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
xmoj-script (master → www.xmoj-script.uk) and xmoj-script-dev-channel (dev → dev./ghpages.xmoj-script.uk) build on every push, including pushes that don't touch XMOJ.user.js. The workflow only produced duplicate deployments and a github.io copy nothing links to. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
What does this PR aim to accomplish?:
The project website (xmoj-script.uk) was dated, wordy (GPT-3.5-era copy), and full of dead links (
xmoj-bbs.me,sso.xmoj-bbs.me). It also didn't tell Chrome/Edge users that they must allow userscripts, which is the most common "installed but nothing happens" cause.How does this PR accomplish the above?:
Site (
40babdc)index.htmlrewritten in the userscript's MonochromeUI style: hero, 6-card feature grid, 3-step install with browser auto-detection (Chrome 138+ "允许用户脚本" toggle vs Developer mode for older Chrome/Edge, per Tampermonkey FAQ Q209), FAQ, feedback. Version is read live fromUpdate.json.xmoj-bbs.melinks. Statuspage and the 萌ICP line are kept.site.css(tokens copied fromMonochromeSkinCSS, with a note to keep them in sync) andsite.js. Bootstrap 5.2.3 → 5.3.3 fordata-bs-themedark mode; fonts from the samefonts.loli.netmirror as the script.404.htmlrebuilt in the same style.privacy.html/terms.html/child-protection.htmlrewritten in plain Chinese, based on an audit of what XMOJ-bbsmasteractually stores (session hash ≤5 days, read messages deleted after 5 days, analytics fields, images in a GitHub repo, AI badge moderation).messages.html: only the dead SSO tab and its code are removed (it never redirected). Its visual style is unchanged.sitemap.xml,robots.txt, README: moved toxmoj-script.uk.CI / submodule (
96c57e1)master→xmoj-script(www.xmoj-script.uk),dev→xmoj-script-dev-channel(dev. / ghpages.xmoj-script.uk, whichDebugModeuses).Release.yml/Prerelease.ymlno longer upload the site themselves. That upload duplicated everymasterdeployment, and the GitHub Pages copy wasn't linked from anywhere..gitmodulestracks XMOJ-bbsmaster; Dependabot opens daily submodule bump PRs againstdev.backendbumped toa55c2b0. That includes XMOJ-bbs#72 (our log lines record only a session hash prefix), Sync Dev #73 (Workers AI over HTTP, because Cloudflare can't attach theaibinding on this account; getPlatformProxy / remote proxy session fails with "binding AI of type ai failed to generate: internal error [code: 10021]" on edge-preview cloudflare/workers-sdk#15973) and Update to release 1.0.207 #74 (Workers invocation logs off, since they stored the notification WebSocket's?SessionID=URL; replaced by our own per-request log line with no query string).Privacy claim now holds: the page says server logs contain only a session hash prefix. XMOJ-bbs#72–#74 are deployed (build
8bc3b56e, 2026-10-05 11:34 UTC). Querying Workers Logs after the deploy finds noSessionID=entries, and the new per-request lines are present. Older raw entries age out under Cloudflare's log retention.Testing (done locally with Playwright, Chromium):
messages.htmllogin with a real account after the SSO removal: tested by the maintainer (2026-10-05).By submitting this pull request, I confirm the following:
XMOJ.user.js, only the project website.🤖 Generated with Claude Code
https://claude.ai/code/session_017dqWu3YgeVRGwBt5pXDq4A
Summary by cubic
Redesigns
xmoj-script.ukin the userscript's monochrome style and deploys site changes on every push instead of only whenXMOJ.user.jschanges. The new site replaces dead links and outdated content with clearer installation guidance, including the Chrome/Edge 138+ userscript toggle.Site
Update.json, supports ScriptCat alongside Tampermonkey, and uses accessible browser toggles.xmoj-script.uk.Deployment
masteranddev, while Cloudflare Pages deploys frommaster; the jobs fail independently and Cloudflare deploys are serialized.a55c2b0, which includes the session-log redaction. The privacy wording depends on that XMOJ-bbs change being live, so its pending Cloudflare deployment must be retried before merging.Written for commit c7549b0. Summary will update on new commits.
Summary by Sourcery
Modernize the XMOJ-Script website, improve installation and privacy guidance, remove obsolete integrations, and streamline push-based deployment.
New Features:
Bug Fixes:
Enhancements:
CI:
Deployment:
Documentation:
Tests: