Repository navigation
Draw Kick's badges, preview linked clips, say when there is an update, and let the worker ask Kick who you are - #30
Conversation
…, and let the worker ask Kick who you are Kick still did not recognise a moderator, and the reason was one header. `channels/<slug>/me` is answered only to the signed-in web session, and only when that session arrives as a bearer token — the way Kick's own site sends it. The cookie jar alone gets `401 Unauthenticated`, which is what the content script's same-origin fetch was getting, silently. The page now reads kick.com's `session_token` cookie and sends it as the Authorization header, and the worker does the same through the new `cookies` permission, which is what makes the answer available with Kick merged into a Twitch tab, where there is no kick.com page to ask. `/me` never names whose standing it is, so the account name is read from `/api/v1/user` and the guard against acting as somebody else has something to compare again. Kick history was never replayed: the messages endpoint is keyed by the channel's id, not the chatroom's, and asking with the wrong one is answered `200 OK` with an empty list rather than an error. The channel id is kept on the connection now and history asks with it. Kick sends a role badge as a type and a caption and no picture — its site draws them from icons of its own — so the feed spelled them out. They are drawn now: the channel's own subscriber badges by months, the pictures on Kick's newer `badges_v2` list, and icons for the roles, with the label only for a type none of those cover. A clip link says nothing about what is behind it. The feed finds Twitch and Kick clip addresses in a message, the worker asks the platform, and a card with the thumbnail, title, channel and length lands under the row. A newer release is now said at the top of the overlay as well as on the toolbar icon, which is only there for people who pinned it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 680315db8b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| standing.username = String(FCM.usernameFrom(who) || ''); | ||
| } | ||
| applyKickStanding(session, sink, standing, record); |
There was a problem hiding this comment.
Require a verified Kick username before enabling moderation
If /me reports moderator status but the subsequent /api/v1/user request fails or returns an unrecognized shape, this assigns an empty username and still calls applyKickStanding. Its account-mismatch guard only runs when both usernames are present, so a browser signed in as moderator A can enable controls backed by connected OAuth account B; those controls then issue requests as B and fail. Treat an unknown session username as insufficient whenever a connected account must be compared.
Useful? React with 👍 / 👎.
| close.addEventListener('click', () => { | ||
| updateEl.classList.add('fcm-hidden'); | ||
| try { | ||
| chrome.runtime.sendMessage({ cmd: 'updateDismiss', version: status.version }, () => { |
There was a problem hiding this comment.
Propagate update dismissal to every open overlay
When several stream overlays are open, or the update is dismissed from the popup, only the initiating UI is hidden. updateDismiss persists the version but neither broadcasts an unavailable status nor triggers a storage listener, so every other already-open overlay continues advertising the dismissed release until it is recreated. Notify all active sessions after dismissal so the shared per-version state is reflected immediately.
Useful? React with 👍 / 👎.
Kick moderators, actually recognised
v1.17.1 asked the right question from the right place and still got
401 Unauthenticated: Kick answerschannels/<slug>/meonly to a bearer token, never to the cookie jar. Both the content script and — through a newcookiespermission — the background worker now send kick.com'ssession_tokencookie as theAuthorizationheader, the way Kick's own site does. The worker route is what makes moderation work with Kick merged into a Twitch tab./mecarries no username, so the account name is read from/api/v1/userand the "signed in as X, connected as Y" guard is live again.Reloading: the new permission means Chrome disables the unpacked extension until it is re-approved on
chrome://extensions.Kick history replayed
/channels/<id>/messageswants the channel id, not the chatroom id. The wrong one is answered200 OK, messages: [], so nothing ever noticed. Fixed, with a suite that pins the id.Kick badges drawn
Channel subscriber badges by months, the
badges_v2pictures (level badge), and drawn icons for moderator, broadcaster, VIP, OG, founder, verified, staff, gifter (tiered by count) and sidekick. Labels remain for anything else. Contrast auditor passes both themes.Clip previews
Twitch and Kick clip links get a card under the row — thumbnail, title, channel, length — via anonymous GQL and Kick's public clip record, cached an hour, thumbnails held to the platforms' hosts. New Clip previews setting.
Update strip
One line at the top of the overlay when a newer release exists, sharing the popup's per-version dismissal.
Suite: 1702 passed. Harness gained
+ clip links,show update strip, and realistic Kick badge rows.🤖 Generated with Claude Code