feat: the first pages, and what a browser walk found behind them
All checks were successful
PR Checks / client-build (pull_request) Successful in 15s
PR Checks / frozen-manifest (pull_request) Successful in 36s
PR Checks / server-tests (pull_request) Successful in 7m58s

Phase 4. `/rust` is the server list and the module's landing page (D12);
`/rust/servers/:id` is one server with four tabs — feed, leaderboard, who is
on, wipes (D13). Everything selectable lives in the URL, so any view of the
page is a link. The feed and the presence list poll every twenty seconds while
the tab is visible and not at all when it is not (D14); the leaderboard and the
wipe list load once. `site.footer.status` is filled with a live server and
player count (D15).

Nothing on these pages calls a game server. Every field comes from this
module's own tables, which is what the phase criterion is about: the site
renders the last thing each server said while every server is off.

Walking that criterion in a browser against a live rig found four defects, two
of them already shipped in phase 3:

  * An unreachable refresh called `putState` — the whole-row write — with two
    fields, so a host that rebooted lost its hostname, map, size, seed and wipe
    id. The list then read "Offline" with nothing beside it, which is not "here
    is what we know" but "we have never heard of it". `markUnreachable` now
    moves three columns and mentions no others.
  * "Last reported" read `updated_at`, which a FAILED poll writes too — so an
    offline server claimed it had reported just now, every thirty seconds, for
    as long as it stayed down. `last_seen_at` is the new column, moved only by a
    frame that arrived.
  * Feed rows showed a bare time of day, so three events from six weeks ago all
    read as this afternoon once the feed was filtered to a past wipe.
  * `/rust/servers/typo` rendered core's ErrorState under its own heading and
    read "No such server / Something went wrong", sending a reader who mistyped
    a URL looking for an outage.

Also: a detail route (`GET …/servers/:id`), because it is the only route under
that path that can say a server does not exist — the other four answer an empty
list for an id nobody configured, and each of those is a good answer to its own
question.

`useAsync` cannot poll: it blanks its data on every dependency change, so a
twenty-second refresh built on it would clear the killfeed and re-fill it four
times a minute. `hooks/usePolled.js` is the module's own, invisible when it
succeeds and keeping the rows when it fails.

The client test fake was *nearly* core — it prefixed routes without stripping
the trailing separator, so the first module to register an index route failed
the nav check for a link that works in a browser. It now copies core's line
character for character.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
This commit is contained in:
2026-09-16 21:40:28 -05:00
parent 5ce711048c
commit 22fd8c5da7
29 changed files with 2040 additions and 65 deletions

116
server/test/refresh.test.js Normal file
View File

@@ -0,0 +1,116 @@
// ── What a refresh writes when nobody answers ─────────────────────────────
//
// The refresh loop has three outcomes (see `boot.js`), and the two unhappy ones
// are the interesting half of this module's promise: the site renders the last
// thing each server said **while every server is off**. A page can only do that
// if the row still holds what the server said.
//
// The defect this suite exists for shipped in phase 3 and was found by walking
// phase 4's own pages: an unreachable refresh called `putState` with two fields,
// and `putState` replaces the row — so the first time a game host rebooted, the
// hostname, the map, the size, the seed and the wipe id were all set to NULL.
// The list then read "Offline" with nothing beside it, which is not "here is
// what we know about a server that is down", it is "we have never heard of it".
//
// It is invisible to any test that stubs a sidecar which answers, which is why
// there was not one.
const test = require('node:test')
const assert = require('node:assert')
const { fakeCtx } = require('./_fakes')
function withCore(ctx = fakeCtx()) {
require('../core')._reset()
require('../core').init(ctx)
return ctx
}
/** The columns a description lives in — the ones an unreachable write must not touch. */
const DESCRIPTION = ['hostname', 'level', 'seed', 'world_size', 'boot_id', 'save_created_at', 'wipe_id']
test('an unreachable refresh does not write the description columns at all', async () => {
const queries = []
withCore(fakeCtx({
db: {
query: (sql, params) => {
queries.push({ sql, params })
return Promise.resolve([])
},
pool: {},
},
}))
const db = require('../model/servers/servers.db')
await db.markUnreachable('main', false)
assert.equal(queries.length, 1)
const { sql, params } = queries[0]
// Asserted against the SQL rather than against a round trip, because the whole
// failure is about which columns a statement mentions. A column named here is
// a column that can be nulled.
for (const column of DESCRIPTION) {
assert.ok(!sql.includes(column), `markUnreachable writes ${column}, which is the server's description`)
}
assert.ok(sql.includes('reachable'))
assert.ok(sql.includes('online'))
assert.ok(sql.includes('updated_at'))
assert.deepStrictEqual(params, ['main', 0])
})
test('a sidecar that is up with no game behind it is reachable and offline', async () => {
// The middle outcome, and the one that is easy to collapse into the other two:
// a fresh install whose plugin is not loaded yet. Reporting it as unreachable
// sends an operator to look at the network instead of at the game server.
const queries = []
withCore(fakeCtx({
db: {
query: (sql, params) => {
queries.push({ sql, params })
return Promise.resolve([])
},
pool: {},
},
}))
await require('../model/servers/servers.db').markUnreachable('main', true)
assert.deepStrictEqual(queries[0].params, ['main', 1])
})
test('neither unhappy path calls putState', async () => {
// The regression in one assertion: `putState` is the whole-row write, and
// calling it with two fields is what blanked the description.
withCore(fakeCtx({ db: { query: () => Promise.resolve([]), pool: {} } }))
const db = require('../model/servers/servers.db')
const sidecar = require('../sidecarClient')
const boot = require('../boot')
const originalPut = db.putState
const originalMark = db.markUnreachable
const originalBoards = sidecar.boards
const marked = []
let putCalls = 0
db.putState = async () => { putCalls += 1 }
db.markUnreachable = async (id, reachable) => { marked.push([id, reachable]) }
try {
// Nothing answered.
sidecar.boards = async () => ({ ok: false, status: 0, data: null })
await boot.refreshOne({ id: 'main', baseUrl: 'http://127.0.0.1:1', token: 't', protocol: 2 })
// The sidecar answered, and has never heard from a game.
sidecar.boards = async () => ({ ok: true, status: 200, data: { boards: {} } })
await boot.refreshOne({ id: 'main', baseUrl: 'http://127.0.0.1:1', token: 't', protocol: 2 })
assert.equal(putCalls, 0, 'an unhappy refresh replaced the whole state row')
assert.deepStrictEqual(marked, [['main', false], ['main', true]])
} finally {
db.putState = originalPut
db.markUnreachable = originalMark
sidecar.boards = originalBoards
}
})

View File

@@ -97,10 +97,96 @@ test('the public shape carries nothing about the sidecar', () => {
// someone who did not read this file, and an allowlist is the only assertion
// that catches one.
assert.deepStrictEqual(Object.keys(shaped).sort(), [
'hostname', 'id', 'level', 'maxPlayers', 'name', 'online', 'players', 'seed', 'stale', 'updatedAt', 'worldSize',
'hostname', 'id', 'lastSeenAt', 'level', 'maxPlayers', 'name', 'online', 'players', 'seed', 'stale',
'updatedAt', 'wipeId', 'wipedAt', 'worldSize',
])
})
test('"last reported" is when a frame arrived, not when we last polled', () => {
withCore()
const servers = require('../model/servers/servers.model')
// The defect the phase-4 page walk found, in one assertion. A refresh that
// cannot reach a sidecar still writes `updated_at` — it has to, because that is
// what staleness is computed from — and a page reading it as "last reported"
// told a reader that a server which had been down for days had reported just
// now, every thirty seconds, for as long as it stayed down.
const state = stateRow({
online: 0,
reachable: 0,
updatedAt: new Date(NOW - 5_000).toISOString(),
lastSeenAt: new Date(NOW - 3 * 86400_000).toISOString(),
})
const shaped = servers.shapePublic(serverRow(), state, NOW)
assert.strictEqual(shaped.lastSeenAt, new Date(NOW - 3 * 86400_000).toISOString())
assert.strictEqual(shaped.stale, false, 'the row itself is fresh — it was written five seconds ago')
assert.strictEqual(shaped.online, false)
// A server nothing has ever heard from has no such moment, and `null` is what
// a page renders as "never" rather than as the epoch.
assert.strictEqual(servers.shapePublic(serverRow(), undefined, NOW).lastSeenAt, null)
})
test('the public shape carries the current wipe, from the state row', () => {
withCore()
const servers = require('../model/servers/servers.model')
// The wipe id on the STATE row, not the newest row in `rust_wipes`. The two
// usually agree, and the state row is the one that is right when they do not:
// the wipe list is derived from events that have been ingested, so a server
// that has just wiped and said nothing since has a new id here and no row there.
const shaped = servers.shapePublic(serverRow(), stateRow({ wipeId: 'w-2026-09', saveCreatedAt: '2026-09-04T18:00:00Z' }), NOW)
assert.strictEqual(shaped.wipeId, 'w-2026-09')
assert.strictEqual(shaped.wipedAt, '2026-09-04T18:00:00Z')
// A server nothing has polled yet has no wipe, and `null` is the honest answer
// — an empty string would be sent back as `?wipe=`, which asks a different
// question and answers nothing.
const never = servers.shapePublic(serverRow(), undefined, NOW)
assert.strictEqual(never.wipeId, null)
assert.strictEqual(never.wipedAt, null)
})
test('a disabled server is not there, rather than forbidden', async () => {
withCore()
const db = require('../model/servers/servers.db')
const model = require('../model/servers/servers.model')
const originalServer = db.getServer
const originalState = db.getState
db.getState = async () => stateRow()
try {
// The detail route is the only one under `/servers/:id` that can say "no such
// server" — the other four answer an empty list, because an unknown id
// genuinely has no events. So what `null` means here decides what a page
// renders, and a disabled server and a missing one must mean the same thing:
// an operator who switched a server off did not switch it into a 403.
db.getServer = async () => ({ ...serverRow(), enabled: 0 })
assert.strictEqual(await model.getPublic('main', NOW), null)
db.getServer = async () => null
assert.strictEqual(await model.getPublic('nope', NOW), null)
// And an id nobody asked about never reaches the database.
let asked = false
db.getServer = async () => { asked = true; return null }
assert.strictEqual(await model.getPublic('', NOW), null)
assert.strictEqual(asked, false)
db.getServer = async () => serverRow()
const server = await model.getPublic('main', NOW)
assert.strictEqual(server.id, 'main')
assert.strictEqual(server.online, true)
assert.ok(!Object.prototype.hasOwnProperty.call(server, 'sidecarBaseUrl'))
} finally {
db.getServer = originalServer
db.getState = originalState
}
})
test('the admin shape reports whether a token is stored, never the token', () => {
withCore()
const servers = require('../model/servers/servers.model')