feat: ingest protocol 2, and keep the record a wipe cannot erase
The module half of the read path. Seven tables, an ingest cursor, four public routes, and one file whose only job is deciding who may see what. **The record and the window are different things.** `rust_player_wipe_stats` and `rust_gather_totals` are permanent and per-wipe, so all-time is those rows SUMmed rather than a second set of counters that can disagree with them — that is R12's "per-wipe detail plus all-time rollups" in one table instead of two. `rust_events` is a bounded 30-day window of raw frames for the killfeed, and `rust_presence` is a board: replaced wholesale, never appended. **The feed is a cursor, not a socket, and the header says why.** Core runs Node 20, where a global WebSocket is still behind a flag, so a socket means taking `ws` — against a release that asserts it has no runtime dependencies (D5). The deciding argument is the other one though: a socket needs a cursor anyway, for whatever it missed while the module was restarting, and the catch-up path is the one that has to be right. A cursor alone is one mechanism exercised every five seconds rather than two where the second only runs after an outage. **The cursor advances after the batch, never before.** A crash between the two re-reads events already counted, which inflates a total; the other order loses them silently and for ever. One is visible and bounded, the other is invisible and permanent, so the code fails in the visible direction. A server with no cursor starts at the sidecar's current END rather than at zero — replaying a fortnight of deaths into stats for wipes the site never saw is not a catch-up. **`catalogue.js` is a security boundary, default-deny.** Protocol 2 carries IP addresses (login attempts, approvals, bans), one player's report about another, and the grid reference of somebody's base. They are stored, because an operator chasing ban evasion needs them; they are not served below the admin tier. The allowlist lives here rather than as a field on the wire, because a boundary declared by the sender is one a compromised or merely out-of-date game host can widen — the same reason core's own shard fan-out filters on the serving side. A kind this build has never heard of is not public, and a test holds the list against PROTOCOL.md §8.4 so that adding a kind to the protocol without classifying it fails a build. `PROTOCOL_VERSION` goes to 2 here in the same change as the emitters, though this module consumes none of the new frames yet: the sidecar refuses a mismatched client with a 409, so a module left on 1 would stop being able to read the board it has been reading all along. A constant that lags the deployment is an outage with a version number on it. 95 server tests, 20 client tests, every guard green, and `routes.manifest.json` regenerated against a real core at the pinned ref: 10 routes, all documented, none of core's moved. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
This commit is contained in:
@@ -11,6 +11,7 @@
|
||||
|
||||
const core = require('../../core')
|
||||
|
||||
const events = require('../../model/events/events.model')
|
||||
const servers = require('../../model/servers/servers.model')
|
||||
|
||||
const log = core.logger('public')
|
||||
@@ -24,4 +25,62 @@ async function listServers(req, res) {
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { listServers }
|
||||
/**
|
||||
* The killfeed, and everything else public that happened on one server.
|
||||
*
|
||||
* **`admin` is not passed, and that is the whole security posture of this
|
||||
* handler.** `events.recent` takes the viewer explicitly and defaults to the
|
||||
* public allowlist, so the way to leak an IP address from here is to add an
|
||||
* argument rather than to forget one.
|
||||
*/
|
||||
async function listEvents(req, res) {
|
||||
try {
|
||||
res.json({
|
||||
events: await events.recent({
|
||||
serverId: req.params.id,
|
||||
kind: req.query.kind,
|
||||
wipeId: req.query.wipe || null,
|
||||
limit: req.query.limit,
|
||||
}),
|
||||
})
|
||||
} catch (err) {
|
||||
log.error('failed to read events', { server: req.params.id, error: err.message })
|
||||
res.status(500).json({ error: 'Failed to read events' })
|
||||
}
|
||||
}
|
||||
|
||||
async function listLeaderboard(req, res) {
|
||||
try {
|
||||
res.json({
|
||||
leaderboard: await events.leaderboard({
|
||||
serverId: req.params.id,
|
||||
wipeId: req.query.wipe || null,
|
||||
sort: req.query.sort,
|
||||
limit: req.query.limit,
|
||||
}),
|
||||
})
|
||||
} catch (err) {
|
||||
log.error('failed to read the leaderboard', { server: req.params.id, error: err.message })
|
||||
res.status(500).json({ error: 'Failed to read the leaderboard' })
|
||||
}
|
||||
}
|
||||
|
||||
async function listWipes(req, res) {
|
||||
try {
|
||||
res.json({ wipes: await events.wipes(req.params.id) })
|
||||
} catch (err) {
|
||||
log.error('failed to read wipes', { server: req.params.id, error: err.message })
|
||||
res.status(500).json({ error: 'Failed to read wipes' })
|
||||
}
|
||||
}
|
||||
|
||||
async function listOnline(req, res) {
|
||||
try {
|
||||
res.json({ players: await events.online(req.params.id) })
|
||||
} catch (err) {
|
||||
log.error('failed to read presence', { server: req.params.id, error: err.message })
|
||||
res.status(500).json({ error: 'Failed to read who is online' })
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { listServers, listEvents, listLeaderboard, listWipes, listOnline }
|
||||
|
||||
@@ -41,4 +41,65 @@ rustRouter.get(
|
||||
servers.listServers,
|
||||
)
|
||||
|
||||
// ── One server's read path ────────────────────────────────────────────────
|
||||
//
|
||||
// Every route below is public, and every one of them answers from this module's
|
||||
// own tables — never from a live call to a sidecar. That is what lets the
|
||||
// killfeed and the leaderboard render while every game server in the fleet is
|
||||
// off, which is the same promise the server list makes.
|
||||
//
|
||||
// **The events route serves an ALLOWLIST, default-deny** (`catalogue.js`).
|
||||
// Protocol 2 carries IP addresses and player reports; they are stored, and they
|
||||
// do not come out here.
|
||||
|
||||
rustRouter.get(
|
||||
'/servers/:id/events',
|
||||
// #swagger.tags = ['Public · Rust']
|
||||
// #swagger.summary = 'Recent events on one Rust server'
|
||||
// #swagger.description = 'The killfeed and everything else public that happened on a server, newest first. Narrow with `kind` (comma-separated) and `wipe`. Only publicly classified kinds are ever returned — moderation events, login attempts and anything carrying an IP address are stored but never served here.'
|
||||
// #swagger.parameters['id'] = { in: 'path', required: true, description: 'The server’s slug', schema: { type: 'string' } }
|
||||
// #swagger.parameters['kind'] = { in: 'query', required: false, description: 'One kind, or several comma-separated', schema: { type: 'string' } }
|
||||
// #swagger.parameters['wipe'] = { in: 'query', required: false, description: 'Restrict to one wipe id', schema: { type: 'string' } }
|
||||
// #swagger.parameters['limit'] = { in: 'query', required: false, description: 'Rows to return, capped at 200', schema: { type: 'integer' } }
|
||||
/* #swagger.responses[200] = { description: 'Recent events, newest first' } */
|
||||
siteMode,
|
||||
servers.listEvents,
|
||||
)
|
||||
|
||||
rustRouter.get(
|
||||
'/servers/:id/leaderboard',
|
||||
// #swagger.tags = ['Public · Rust']
|
||||
// #swagger.summary = 'The leaderboard for one Rust server'
|
||||
// #swagger.description = 'Per-wipe when `wipe` is given, all-time otherwise. All-time is the per-wipe rows summed rather than a second set of counters, so a wipe splits a player’s history without ending it.'
|
||||
// #swagger.parameters['id'] = { in: 'path', required: true, description: 'The server’s slug', schema: { type: 'string' } }
|
||||
// #swagger.parameters['wipe'] = { in: 'query', required: false, description: 'Restrict to one wipe id', schema: { type: 'string' } }
|
||||
// #swagger.parameters['sort'] = { in: 'query', required: false, description: 'kills, deaths, npcKills or playtime', schema: { type: 'string' } }
|
||||
// #swagger.parameters['limit'] = { in: 'query', required: false, description: 'Rows to return, capped at 200', schema: { type: 'integer' } }
|
||||
/* #swagger.responses[200] = { description: 'The leaderboard' } */
|
||||
siteMode,
|
||||
servers.listLeaderboard,
|
||||
)
|
||||
|
||||
rustRouter.get(
|
||||
'/servers/:id/wipes',
|
||||
// #swagger.tags = ['Public · Rust']
|
||||
// #swagger.summary = 'Every wipe this server has had'
|
||||
// #swagger.description = 'Newest first. A wipe id is derived by the bridge plugin from the save’s creation time and stamped on every frame, so it is the same id the events and the leaderboard are filtered by.'
|
||||
// #swagger.parameters['id'] = { in: 'path', required: true, description: 'The server’s slug', schema: { type: 'string' } }
|
||||
/* #swagger.responses[200] = { description: 'The wipes' } */
|
||||
siteMode,
|
||||
servers.listWipes,
|
||||
)
|
||||
|
||||
rustRouter.get(
|
||||
'/servers/:id/online',
|
||||
// #swagger.tags = ['Public · Rust']
|
||||
// #swagger.summary = 'Who is on one Rust server right now'
|
||||
// #swagger.description = 'Read from the presence board the bridge re-sends on every connect and every minute, rather than counted from connect and disconnect events — so it is correct even after the website has missed one.'
|
||||
// #swagger.parameters['id'] = { in: 'path', required: true, description: 'The server’s slug', schema: { type: 'string' } }
|
||||
/* #swagger.responses[200] = { description: 'Who is online' } */
|
||||
siteMode,
|
||||
servers.listOnline,
|
||||
)
|
||||
|
||||
module.exports = rustRouter
|
||||
|
||||
Reference in New Issue
Block a user