Skip to content

Draw Kick's badges, preview linked clips, say when there is an update, and let the worker ask Kick who you are - #30

Merged
JRBlaze merged 1 commit into
mainfrom
kick-badges-clips-and-update-strip
Sep 3, 2026
Merged

JRBlaze merged 1 commit into
mainfrom
kick-badges-clips-and-update-strip

Conversation

@JRBlaze

@JRBlaze JRBlaze commented Sep 3, 2026

Copy link
Copy Markdown
Owner

Kick moderators, actually recognised

v1.17.1 asked the right question from the right place and still got 401 Unauthenticated: Kick answers channels/<slug>/me only to a bearer token, never to the cookie jar. Both the content script and — through a new cookies permission — the background worker now send kick.com's session_token cookie as the Authorization header, the way Kick's own site does. The worker route is what makes moderation work with Kick merged into a Twitch tab. /me carries no username, so the account name is read from /api/v1/user and the "signed in as X, connected as Y" guard is live again.

Reloading: the new permission means Chrome disables the unpacked extension until it is re-approved on chrome://extensions.

Kick history replayed

/channels/<id>/messages wants the channel id, not the chatroom id. The wrong one is answered 200 OK, messages: [], so nothing ever noticed. Fixed, with a suite that pins the id.

Kick badges drawn

Channel subscriber badges by months, the badges_v2 pictures (level badge), and drawn icons for moderator, broadcaster, VIP, OG, founder, verified, staff, gifter (tiered by count) and sidekick. Labels remain for anything else. Contrast auditor passes both themes.

Clip previews

Twitch and Kick clip links get a card under the row — thumbnail, title, channel, length — via anonymous GQL and Kick's public clip record, cached an hour, thumbnails held to the platforms' hosts. New Clip previews setting.

Update strip

One line at the top of the overlay when a newer release exists, sharing the popup's per-version dismissal.

Suite: 1702 passed. Harness gained + clip links, show update strip, and realistic Kick badge rows.

🤖 Generated with Claude Code

…, and let the worker ask Kick who you are

Kick still did not recognise a moderator, and the reason was one header.
`channels/<slug>/me` is answered only to the signed-in web session, and
only when that session arrives as a bearer token — the way Kick's own site
sends it. The cookie jar alone gets `401 Unauthenticated`, which is what
the content script's same-origin fetch was getting, silently. The page now
reads kick.com's `session_token` cookie and sends it as the Authorization
header, and the worker does the same through the new `cookies` permission,
which is what makes the answer available with Kick merged into a Twitch
tab, where there is no kick.com page to ask. `/me` never names whose
standing it is, so the account name is read from `/api/v1/user` and the
guard against acting as somebody else has something to compare again.

Kick history was never replayed: the messages endpoint is keyed by the
channel's id, not the chatroom's, and asking with the wrong one is answered
`200 OK` with an empty list rather than an error. The channel id is kept on
the connection now and history asks with it.

Kick sends a role badge as a type and a caption and no picture — its site
draws them from icons of its own — so the feed spelled them out. They are
drawn now: the channel's own subscriber badges by months, the pictures on
Kick's newer `badges_v2` list, and icons for the roles, with the label only
for a type none of those cover.

A clip link says nothing about what is behind it. The feed finds Twitch
and Kick clip addresses in a message, the worker asks the platform, and a
card with the thumbnail, title, channel and length lands under the row.

A newer release is now said at the top of the overlay as well as on the
toolbar icon, which is only there for people who pinned it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@JRBlaze
JRBlaze merged commit 3281c1a into main Sep 3, 2026
3 checks passed
@JRBlaze
JRBlaze deleted the kick-badges-clips-and-update-strip branch September 3, 2026 02:13

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 680315db8b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +412 to +414
standing.username = String(FCM.usernameFrom(who) || '');
}
applyKickStanding(session, sink, standing, record);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require a verified Kick username before enabling moderation

If /me reports moderator status but the subsequent /api/v1/user request fails or returns an unrecognized shape, this assigns an empty username and still calls applyKickStanding. Its account-mismatch guard only runs when both usernames are present, so a browser signed in as moderator A can enable controls backed by connected OAuth account B; those controls then issue requests as B and fail. Treat an unknown session username as insufficient whenever a connected account must be compared.

Useful? React with 👍 / 👎.

Comment thread src/content/overlay.js
close.addEventListener('click', () => {
updateEl.classList.add('fcm-hidden');
try {
chrome.runtime.sendMessage({ cmd: 'updateDismiss', version: status.version }, () => {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Propagate update dismissal to every open overlay

When several stream overlays are open, or the update is dismissed from the popup, only the initiating UI is hidden. updateDismiss persists the version but neither broadcasts an unavailable status nor triggers a storage listener, so every other already-open overlay continues advertising the dismissed release until it is recreated. Notify all active sessions after dismissal so the shared per-version state is reflected immediately.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant