feat(rust): what the site has given a player, as the player reads it
Phase 8's website half. Phase 7 made the site the author of in-game
privilege and gave an operator every view of it; this is the other side,
and it is the first time a player can see what they hold without asking
one.
`GET /player/rust/permissions` is self-scoped in SQL and read-only by
construction — a grant a player could change would not be a grant. Three
things make it a different shape from the admin read rather than a
filtered one:
* the scope arithmetic is answered on the server. A client handed `*`
would have to know what the fleet is to say anything, and then
`inScope` exists twice. Each entry carries the servers it reaches,
already resolved and already marked.
* `live` is the pushed ledger, never the authored row. A grant is not a
privilege in a game until a sync confirmed it, and phase 7 is careful
never to record a push that silently did nothing — so "waiting" is
honest, and the alternative is the site claiming to have given
something it has not.
* nothing says WHY it is waiting. An offline server, a permission no
loaded plugin registered and a store that has never seen the account
all look the same from here; telling them apart is an operator's
diagnosis and an inventory of what is installed.
An entitlement that reaches nobody still lists, and the page says so —
authored against the website account, it exists before a Steam id does,
and hiding it until one turns up is the defect the admin user page
shipped in phase 7 (PLAN.md §20.5).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMH6bw1jXMgbyF3ZWGEzSM
This commit is contained in:
@@ -37,13 +37,21 @@ function routesOf(router) {
|
||||
}))
|
||||
}
|
||||
|
||||
test('the player tier serves the three identity routes, and nothing else new', () => {
|
||||
test('the player tier serves the identity routes, the entitlement read, and nothing else', () => {
|
||||
const api = register()
|
||||
const routes = routesOf(api.record.routes.player['/rust'])
|
||||
|
||||
assert.deepEqual(
|
||||
routes.map((r) => `${r.method} ${r.path}`).sort(),
|
||||
['DELETE /links/:steamId', 'GET /links', 'GET /servers', 'POST /link'],
|
||||
[
|
||||
'DELETE /links/:steamId',
|
||||
'GET /links',
|
||||
// Phase 8: what the site has given the caller in game. Read-only on this
|
||||
// tier by construction — the authoring routes are all admin.
|
||||
'GET /permissions',
|
||||
'GET /servers',
|
||||
'POST /link',
|
||||
],
|
||||
)
|
||||
})
|
||||
|
||||
|
||||
Reference in New Issue
Block a user