fix(rust): answer refusals in the field core reads, and show the name the game last saw
All checks were successful
PR Checks / server-tests (pull_request) Successful in 15s
PR Checks / frozen-manifest (pull_request) Successful in 48s
PR Checks / client-build (pull_request) Successful in 7m49s

The two defects the phase 6 browser walk found and #6 described but did not
carry. They were written, walked and left uncommitted; `edge` still has the
shapes the walk condemned.

**Every refusal sentence was invisible.** Core's request primitive reads one
field — `(data && data.message) || res.statusText` — and this module has
answered `{ error: … }` since phase 1. It got away with it because every
failure until phase 6 landed in `ErrorState` on a page whose whole content was
missing, where a generic sentence is honest. A form is different: the sentence
IS the outcome, and the link page showed *Service Unavailable* for all four of
the refusals phase 6 exists to write. All 23 bodies now answer in `message` —
core's `Error` schema, which these routes' own `#swagger.responses` already
referenced, so the annotations stop being a claim the handlers contradict.

`test/errorShape.test.js` drives each outcome rather than grepping for the
field, and asserts the half that is easy to leave behind: a body carrying BOTH
fields renders correctly in a browser and keeps the wrong shape alive for the
next route that copies it.

**The player saw a stale name.** `/player/rust` showed the name recorded at
link time while the admin panel showed the one the game last saw — the same
person labelled two ways on one site, because a Rust name changes on a whim and
only the admin read joined `rust_players`. A LEFT JOIN, because an account can
be linked and never played on.

123 server tests, 39 client tests, `check:imports`, `check:bundle`,
`check:swagger`, `check:externals` — all green.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMH6bw1jXMgbyF3ZWGEzSM
This commit is contained in:
2026-09-21 17:34:21 -05:00
parent f3e274b33d
commit 0876a1d568
8 changed files with 210 additions and 35 deletions

View File

@@ -23,7 +23,7 @@ async function listServers(req, res) {
res.json({ servers: await servers.listForAdmin() })
} catch (err) {
log.error('failed to read the server list', { error: err.message })
res.status(500).json({ error: 'Failed to read the server list' })
res.status(500).json({ message: 'Failed to read the server list' })
}
}
@@ -39,7 +39,7 @@ async function putServer(req, res) {
// Refusing it up front costs one round trip and saves that hunt. An EXISTING
// row is a different case: omitting the token is how you say "leave it".
if (!existing && !sidecarToken) {
return res.status(400).json({ error: 'A new server needs its sidecar token' })
return res.status(400).json({ message: 'A new server needs its sidecar token' })
}
await db.upsertServer({
@@ -71,7 +71,7 @@ async function putServer(req, res) {
return res.status(204).end()
} catch (err) {
log.error('failed to save a server', { server: id, error: err.message })
return res.status(500).json({ error: 'Failed to save the server' })
return res.status(500).json({ message: 'Failed to save the server' })
}
}
@@ -80,7 +80,7 @@ async function deleteServer(req, res) {
try {
const existing = await db.getServer(id)
if (!existing) return res.status(404).json({ error: 'No such server' })
if (!existing) return res.status(404).json({ message: 'No such server' })
await db.deleteServer(id)
await core.activity.log({ req, action: 'rust.server.delete', detail: { server: id } })
@@ -88,7 +88,7 @@ async function deleteServer(req, res) {
return res.status(204).end()
} catch (err) {
log.error('failed to delete a server', { server: id, error: err.message })
return res.status(500).json({ error: 'Failed to delete the server' })
return res.status(500).json({ message: 'Failed to delete the server' })
}
}
@@ -106,7 +106,7 @@ async function testServer(req, res) {
try {
const row = await db.getServer(id)
if (!row) return res.status(404).json({ error: 'No such server' })
if (!row) return res.status(404).json({ message: 'No such server' })
const result = await sidecar.health(servers.withToken(row))
@@ -125,7 +125,7 @@ async function testServer(req, res) {
})
} catch (err) {
log.error('failed to probe a sidecar', { server: id, error: err.message })
return res.status(500).json({ error: 'Failed to probe the sidecar' })
return res.status(500).json({ message: 'Failed to probe the sidecar' })
}
}

View File

@@ -27,7 +27,7 @@ async function listLinks(req, res) {
res.json({ links: await links.forAdmin(req.params.id) })
} catch (err) {
log.error('failed to read a users Rust links', { error: err.message })
res.status(500).json({ error: 'Failed to read this users Rust accounts' })
res.status(500).json({ message: 'Failed to read this users Rust accounts' })
}
}
@@ -50,7 +50,7 @@ async function removeLink(req, res) {
try {
const removed = await links.unlinkOwned(steamId, userId)
if (!removed) return res.status(404).json({ error: 'That account is not linked to this user' })
if (!removed) return res.status(404).json({ message: 'That account is not linked to this user' })
// The one write this panel has, so it is the one thing here worth an audit
// row: after phase 7 a link is what permissions are granted against, and
@@ -64,7 +64,7 @@ async function removeLink(req, res) {
return res.json({ unlinked: true })
} catch (err) {
log.error('failed to unlink a Steam account', { error: err.message })
return res.status(500).json({ error: 'Failed to unlink that account' })
return res.status(500).json({ message: 'Failed to unlink that account' })
}
}