feat(kit): the engagement contract, taught and built (cutover 5 of 7)
The kit was pinned to website 963d734 -- MODULE_API 1.6.0, the Teams cutover --
and the platform is on 1.9.0. Three registrations and two calls arrived in
between, and a reader building against this book would have found no mention of
any of them: a module can now declare what its game can announce, and never who
is told.
Moving `ci/core-ref.json` is the mechanism for exactly this. The pin is now
66bb3b9a (website `main`, the engagement cutover) and `template/module.json`
declares `^1.9.0`.
What chapter 2 gained, under "Telling core something happened":
* a TRIGGER is a payload contract, not a notification stream -- the two share
one id namespace and are constantly confused;
* `ceiling` is required, has no default, and is a CONTAINMENT tree rather than
a size ladder (a `staff` ceiling does not permit `owner`);
* an AUDIENCE resolver returns user ids and nothing else, resolves to NOBODY
on failure, and takes CONSTANT params -- the constraint worth knowing before
you design around it;
* templates re-ensure per seedVersion, rule groups are offered ONCE per group
key, so a rule appended to an existing group reaches fresh installs only;
* `ctx.events.emit` binds the owner and is fire-and-forget; `ctx.inbox.push`
is the direct write, for when there is nothing for an operator to decide.
The template builds all of it: one trigger, one audience over the clan roster it
already had, one seeded body and one seeded rule group, and an emitter in
`boot.js` that fires on the TRANSITION rather than on the poll. Seven new tests,
including the audience that resolves to nobody when its query throws.
Three claims were wrong and are corrected here rather than shipped:
* core validates `subjectKey` against the declared variables and refuses the
module; the draft taught a cooldown keyed on `undefined`, which the check
exists to prevent and a reader will never see.
* `emit` throws OUTSIDE production and only drops-and-logs inside it. Teaching
the second half alone leaves a developer meeting a throw the book says
cannot happen.
* the seeded body itself was malformed -- heading `level: 2` where the block
registry takes 'h2', and no block ids at all.
The third is the one worth keeping: `registerEngagementSeeds` checks that
`blocks` is a non-empty array and stops, so that body would have registered,
seeded, and failed the first time an operator opened it. Found by running the
template's `register()` through core's real registry at the pinned ref -- which
CI does not do, and cannot: the template job checks the version and runs the
template against fakes. A fake accepts what core refuses. The gap is now named
in the chapter, beside the code, and in the pin's own comment, and the rule that
bit has a test that fails on it.
Also: `checkLinks` skipped `.core/`. Bumping this pin means cloning core into
that directory first, and the walk then reported nine broken links in someone
else's README. CI never saw it -- the clone happens in the `template` job and
the check runs in `prose` -- so it was a failure only a person could meet.
Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -52,7 +52,45 @@ async function refresh() {
|
||||
try {
|
||||
// A real module calls its sidecar's REST API here. Two hardcoded values
|
||||
// stand in, so that the page renders and the seam is visible.
|
||||
await worldStatusDb.setStatus({ online: true, players: 0, worldName: 'Example World' })
|
||||
const next = { online: true, players: 0, worldName: 'Example World' }
|
||||
|
||||
// ── Emitting a declared event ──────────────────────────────────────────
|
||||
//
|
||||
// **Emit on the TRANSITION, not on the poll.** This function runs every
|
||||
// thirty seconds; a rule on an event fired every thirty seconds is a rule
|
||||
// that mails somebody every thirty seconds. Core has a cooldown and an
|
||||
// hourly cap and they would both hold, but leaning on them means the module
|
||||
// is emitting "the world is still up" and calling it news. Read the previous
|
||||
// state, compare, and emit only when the answer changed.
|
||||
//
|
||||
// The read is BEFORE the write for the same reason, and getting that
|
||||
// backwards is the easy version of this bug: after `setStatus` the previous
|
||||
// value is gone and every poll looks like no change at all — an emitter that
|
||||
// never fires and never errors.
|
||||
const previous = await worldStatusDb.getStatus()
|
||||
await worldStatusDb.setStatus(next)
|
||||
|
||||
// `previous === null` is the first boot on a fresh install, not a change.
|
||||
// Treating it as one would announce the world coming online to everyone the
|
||||
// first time an operator started the site.
|
||||
if (previous && Boolean(previous.online) !== next.online) {
|
||||
// Fire-and-forget: no await, no return value, nothing to handle. Core
|
||||
// validates the payload against what `index.js` declared, and what a
|
||||
// mismatch does depends on where you are running. **In production it is
|
||||
// dropped and logged** against this module, because a notification must
|
||||
// never be able to break the thing it is about. **Anywhere else it throws**,
|
||||
// at this line, so the stack points at your own call instead of at a
|
||||
// warning nobody reads. Neither is a condition to catch: a payload that
|
||||
// does not match the contract you declared is a bug to fix.
|
||||
core.emit('examplegame.world.status_changed', {
|
||||
data: {
|
||||
worldName: next.worldName,
|
||||
status: next.online ? 'online' : 'offline',
|
||||
players: next.players,
|
||||
url: '/world',
|
||||
},
|
||||
})
|
||||
}
|
||||
} catch (err) {
|
||||
log.warn('could not refresh world status', { error: err.message })
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user