Skip to content

Sb/1b gm route auth - #104

Merged
over2take merged 3 commits into
feature/system-builderfrom
sb/1b-gm-route-auth
Sep 29, 2026
Merged

over2take merged 3 commits into
feature/system-builderfrom
sb/1b-gm-route-auth

Conversation

@over2take

Copy link
Copy Markdown
Owner

Summary

Test plan

  • Tested locally
  • Tests pass

Pre-merge checklist

Code quality:

  • Code follows project style
  • No breaking changes (or clearly documented)
  • No console errors or warnings

Version & Release:

  • Version bumped? If releasing to users, update:
    • frontend/package.json version
    • docker-compose.yml APP_VERSION
    • CHANGELOG.md with release notes
  • GitHub Actions will auto-tag Docker images with the new version

Before merging to main:

  • All tests passing
  • PR reviewed and approved
  • Branch is up to date with main
  • No merge conflicts

Related issues

Developer added 3 commits September 29, 2026 15:08
…ocket events

Every token is signed with the same secret, and the checks only asked whether a
token was valid and not temporary, which a player's login token is. It passed
authenticate (delete buildings, GM notes, approve accounts, reset passwords) and
every admin socket check (socket admin at identify, grant editor rights, set any
bank balance, NPC users, purge dice history).

The checks now say what they mean: authenticate admits the GM or a granted
editor; authenticatePlayer adds a player's own login for their own sheet and
portrait; optionalAuthenticate treats players as anonymous; admin socket events
require the GM's own login. Three tests signed a GM token without the role the
real login always carries, and now sign it the real way.

Tests walk a player token against every route behind the GM check, and hold GM
login, granted editors, player sheet and portrait, and chat. Verified end to end
on a real server in secure mode.
…d the GM

grantElevatedAccess and approveEditing sent the new editor's token with
io.emit, so every connected client received a working key. They now send it
only to the target's own connections (the client already ignored grants for
anyone else, so the promoted player sees no difference). approveEditing,
denyEditing and revokeEditing had no check at all: a player could approve
their own edit request. They now require the GM or a granted editor, the same
people who see those buttons.

Tests run several connections on one server; mutation-checked. Verified on a
real secure-mode server: grant, use, revoke, surrender, approve and kick all
work, a bystander receives nothing, a player cannot approve themselves.
The trigger listed only main and dev, so PRs into a feature branch
(feature/system-builder and its sb/* pieces) were never tested until the
final merge to main.
@over2take
over2take merged commit 679816b into feature/system-builder Sep 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant