Sb/1b gm route auth - #104
Merged
Merged
Conversation
added 3 commits
September 29, 2026 15:08
…ocket events Every token is signed with the same secret, and the checks only asked whether a token was valid and not temporary, which a player's login token is. It passed authenticate (delete buildings, GM notes, approve accounts, reset passwords) and every admin socket check (socket admin at identify, grant editor rights, set any bank balance, NPC users, purge dice history). The checks now say what they mean: authenticate admits the GM or a granted editor; authenticatePlayer adds a player's own login for their own sheet and portrait; optionalAuthenticate treats players as anonymous; admin socket events require the GM's own login. Three tests signed a GM token without the role the real login always carries, and now sign it the real way. Tests walk a player token against every route behind the GM check, and hold GM login, granted editors, player sheet and portrait, and chat. Verified end to end on a real server in secure mode.
…d the GM grantElevatedAccess and approveEditing sent the new editor's token with io.emit, so every connected client received a working key. They now send it only to the target's own connections (the client already ignored grants for anyone else, so the promoted player sees no difference). approveEditing, denyEditing and revokeEditing had no check at all: a player could approve their own edit request. They now require the GM or a granted editor, the same people who see those buttons. Tests run several connections on one server; mutation-checked. Verified on a real secure-mode server: grant, use, revoke, surrender, approve and kick all work, a bystander receives nothing, a player cannot approve themselves.
The trigger listed only main and dev, so PRs into a feature branch (feature/system-builder and its sb/* pieces) were never tested until the final merge to main.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Test plan
Pre-merge checklist
Code quality:
Version & Release:
frontend/package.jsonversiondocker-compose.ymlAPP_VERSIONCHANGELOG.mdwith release notesBefore merging to main:
Related issues