The Xueqiu stock API requires a login session token (xq_a_token) that
is generated by Xueqiu's frontend JavaScript and cannot be obtained by
simply visiting the homepage. This caused persistent HTTP 400 (error
code 400016) for all users.
Changes:
- _ensure_cookies(): add three-level priority — config file (saved by
--from-browser) → live Chrome cookies via browser_cookie3 → homepage
fallback. The homepage-only approach only ever got acw_tc (anti-DDoS
token), never xq_a_token.
- _get_json(): switch User-Agent from "agent-reach/1.0" to a real Chrome
UA, and add Referer: https://xueqiu.com/ to all API requests.
- get_hot_posts(): replace the defunct /statuses/hot/listV3.json endpoint
(returns empty body) with the v4 public timeline endpoint; correctly
parse item.data as a JSON string to extract author, text, and likes.
- cookie_extract.py: add Xueqiu to PLATFORM_SPECS and configure_from_browser
so that `agent-reach configure --from-browser chrome` now also saves
Xueqiu cookies (only when xq_a_token is present).
- check(): improve error message to direct users to --from-browser instead
of suggesting a proxy.
- Fix urllib.parse.quote usage (was using urllib.request.quote).
- Update tier and backends description to reflect cookie requirement.
- Add 2 new tests: cookie loading from config, Referer/UA header verification.
- Update docs: README, install guide, troubleshooting, SKILL.md, CHANGELOG.