Files
Module-Rust/server/model/servers/servers.model.js
wtclaude 22fd8c5da7
All checks were successful
PR Checks / client-build (pull_request) Successful in 15s
PR Checks / frozen-manifest (pull_request) Successful in 36s
PR Checks / server-tests (pull_request) Successful in 7m58s
feat: the first pages, and what a browser walk found behind them
Phase 4. `/rust` is the server list and the module's landing page (D12);
`/rust/servers/:id` is one server with four tabs — feed, leaderboard, who is
on, wipes (D13). Everything selectable lives in the URL, so any view of the
page is a link. The feed and the presence list poll every twenty seconds while
the tab is visible and not at all when it is not (D14); the leaderboard and the
wipe list load once. `site.footer.status` is filled with a live server and
player count (D15).

Nothing on these pages calls a game server. Every field comes from this
module's own tables, which is what the phase criterion is about: the site
renders the last thing each server said while every server is off.

Walking that criterion in a browser against a live rig found four defects, two
of them already shipped in phase 3:

  * An unreachable refresh called `putState` — the whole-row write — with two
    fields, so a host that rebooted lost its hostname, map, size, seed and wipe
    id. The list then read "Offline" with nothing beside it, which is not "here
    is what we know" but "we have never heard of it". `markUnreachable` now
    moves three columns and mentions no others.
  * "Last reported" read `updated_at`, which a FAILED poll writes too — so an
    offline server claimed it had reported just now, every thirty seconds, for
    as long as it stayed down. `last_seen_at` is the new column, moved only by a
    frame that arrived.
  * Feed rows showed a bare time of day, so three events from six weeks ago all
    read as this afternoon once the feed was filtered to a past wipe.
  * `/rust/servers/typo` rendered core's ErrorState under its own heading and
    read "No such server / Something went wrong", sending a reader who mistyped
    a URL looking for an outage.

Also: a detail route (`GET …/servers/:id`), because it is the only route under
that path that can say a server does not exist — the other four answer an empty
list for an id nobody configured, and each of those is a good answer to its own
question.

`useAsync` cannot poll: it blanks its data on every dependency change, so a
twenty-second refresh built on it would clear the killfeed and re-fill it four
times a minute. `hooks/usePolled.js` is the module's own, invisible when it
succeeds and keeping the rows when it fails.

The client test fake was *nearly* core — it prefixed routes without stripping
the trailing separator, so the first module to register an index route failed
the nav check for a link that works in a browser. It now copies core's line
character for character.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
2026-09-16 21:40:28 -05:00

174 lines
7.1 KiB
JavaScript

// ── The logic half ────────────────────────────────────────────────────────
//
// Shapes what the database returned into what a client should see, and holds the
// one rule that matters most in this module: **what leaves this file is never the
// sidecar's credential.**
//
// It is a separate file from the SQL so that it is testable without a database,
// and the suite next door tests it that way.
//
// The other decision worth pointing at: **a module answers when the game is
// unreachable rather than failing.** The website is the internet-facing process
// and the game is not; a game being down, or a sidecar being mid-restart, is an
// ordinary Tuesday. A page that renders "offline, last seen 20 minutes ago" is
// right; a page that 500s because a socket is closed is a module that has made
// the site's availability depend on the game's.
const core = require('../../core')
const db = require('./servers.db')
const log = core.logger('servers')
// Past this, the last thing a server said stops being news and starts being
// history. Presentation, so the number lives with the code that shapes the
// response rather than in the client.
const STALE_AFTER_MS = 5 * 60 * 1000
/**
* A configured server with its token decrypted, for this module's own use.
*
* **Never hand the result of this to a controller.** It is the input to
* `sidecarClient`, and the only shape in this module that holds a plaintext
* secret.
*
* A token that will not decrypt is returned as `null` rather than throwing: the
* usual cause is a `SECRET_ENC_KEY` that changed, and the right behaviour is a
* server that reports itself unconfigured with a line in the log — not a module
* that fails to boot and takes every other server down with it.
*/
function withToken(row) {
if (!row) return null
let token = null
if (row.sidecarTokenEnc) {
try {
token = core.secretBox().decrypt(row.sidecarTokenEnc)
} catch (err) {
log.error('could not decrypt a sidecar token', { server: row.id, error: err.message })
}
}
return { id: row.id, name: row.name, baseUrl: row.sidecarBaseUrl, token, protocol: row.protocol }
}
/** Every enabled server, with tokens, for the poller. */
async function listForPolling() {
const rows = await db.listServers({ enabledOnly: true })
return rows.map(withToken)
}
/**
* The public view: every enabled server and what it last said.
*
* Nothing here is conditional on who is asking, which is the point of it being
* the public shape. What a *player* or an *admin* additionally sees is added by
* their own tier's controller, never removed by this one.
*/
async function listPublic(now = Date.now()) {
const [servers, states] = await Promise.all([db.listServers({ enabledOnly: true }), db.listState()])
const byId = new Map(states.map((s) => [s.serverId, s]))
return servers.map((row) => shapePublic(row, byId.get(row.id), now))
}
function shapePublic(row, state, now) {
const updatedAt = state && state.updatedAt ? new Date(state.updatedAt) : null
const lastSeenAt = state && state.lastSeenAt ? new Date(state.lastSeenAt) : null
const stale = !updatedAt || now - updatedAt.getTime() > STALE_AFTER_MS
return {
id: row.id,
name: row.name,
// A stale row cannot claim a server is up. The row says what was true when it
// was written, and nothing has written it since.
online: Boolean(state && state.online) && !stale,
players: stale ? 0 : Number(state && state.players) || 0,
maxPlayers: Number(state && state.maxPlayers) || 0,
hostname: (state && state.hostname) || null,
level: (state && state.level) || null,
worldSize: state && state.worldSize != null ? Number(state.worldSize) : null,
seed: state && state.seed != null ? Number(state.seed) : null,
// The CURRENT wipe, from the state row rather than from the newest row in
// `rust_wipes`. The two usually agree and the state row is the one that is
// right when they do not: a wipe list is derived from events that have been
// ingested, so a server that has just wiped and said nothing since has a new
// wipe id here and no row there at all.
wipeId: (state && state.wipeId) || null,
wipedAt: (state && state.saveCreatedAt) || null,
// Two timestamps, because they are two facts. `lastSeenAt` is when a frame
// last arrived and is what a page means by "last reported"; `updatedAt` is
// when this module last wrote the row, and is what `stale` is computed from.
// Reading the second as the first is what made an offline server claim it had
// reported just now, on every failed poll, for as long as it stayed down.
lastSeenAt: lastSeenAt ? lastSeenAt.toISOString() : null,
updatedAt: updatedAt ? updatedAt.toISOString() : null,
stale,
}
}
/**
* One enabled server, or `null`.
*
* It exists because `/rust/servers/:id` is a page and a page needs to be able to
* 404. A detail view built by fetching the list and finding the row in it cannot
* tell "no such server" from "a server that has said nothing" — both are an
* absence — and renders an empty page under a heading for a server that does not
* exist. Filtering happens here, where `enabled = 0` and "never configured" are
* the same answer on purpose: a disabled server is not a 403, it is not there.
*/
async function getPublic(id, now = Date.now()) {
if (!id) return null
const row = await db.getServer(id)
if (!row || !row.enabled) return null
return shapePublic(row, await db.getState(row.id), now)
}
/**
* The admin view: configuration plus reachability, and **no token**.
*
* `hasToken` rather than the token, because the credential is write-only in the
* API: the admin form accepts a new value and never shows the stored one. An
* operator still needs to know whether one is set — a blank field means both
* "unset" and "set, and not being shown you" otherwise.
*/
async function listForAdmin(now = Date.now()) {
const [servers, states] = await Promise.all([db.listServers(), db.listState()])
const byId = new Map(states.map((s) => [s.serverId, s]))
return servers.map((row) => {
const state = byId.get(row.id)
return {
// The public shape first, so the admin-only fields below cannot be
// overwritten by a key the public shape happens to share.
...shapePublic(row, state, now),
sidecarBaseUrl: row.sidecarBaseUrl,
hasToken: Boolean(row.sidecarTokenEnc),
protocol: Number(row.protocol),
enabled: Boolean(row.enabled),
sortOrder: Number(row.sortOrder),
reachable: Boolean(state && state.reachable),
bootId: (state && state.bootId) || null,
sidecarProtocol: state && state.protocol != null ? Number(state.protocol) : null,
}
})
}
/** Encrypt a token for storage. `null`/empty means "leave whatever is stored alone". */
function encryptToken(token) {
if (token === null || token === undefined || token === '') return null
return core.secretBox().encrypt(String(token))
}
module.exports = {
STALE_AFTER_MS,
withToken,
listForPolling,
listPublic,
getPublic,
listForAdmin,
shapePublic,
encryptToken,
}