Files
Module-Rust/server/router/admin/rust.router.js
wtclaude e54ae3afb9
All checks were successful
PR Checks / server-tests (pull_request) Successful in 18s
PR Checks / frozen-manifest (pull_request) Successful in 51s
PR Checks / client-build (pull_request) Successful in 7m56s
feat(rust): mod configuration from the site, and an editor that will not rewrite a float
R18's two tiers: a form generated from a config file's own values, and raw JSON
for what a form cannot express. Admin → Rust mod config, one live round trip per
action, nothing cached between a browser and a game host's disk.

`configEdit.js` is the part that could not be done naively. JavaScript cannot
tell `1` from `1.0`, and both mod frameworks deserialize a config into typed C#
classes — so a read-modify-write silently rewrites every whole-numbered float as
an integer on fields nobody touched, and a plugin that then throws at load does
not come back. It never parses, mutates and re-serialises: it records the SOURCE
SPAN of every value and splices literals into them, so an untouched `1.0` is
still `1.0` and a number an admin types travels as text the whole way (D35/D36).

The bridge's own config is editable with `Host`, `Port` and `ServerId` locked,
in the form and in the raw tier, because either would cut the link carrying the
edit or strand every row this site holds (D38). Credentials render masked with a
reveal; the raw tier shows them (D37) and the audit trail never does.

`rust_config_writes` records every save including the refused and the rolled
back — an operator asking why a setting is not what they set needs to see that
somebody tried.

Three defects a browser walk found that 179 green tests did not:

* every save of the bridge's own config was refused while the page said the
  opposite — a `<select>` whose value matches no `<option>` shows the first one,
  so the reload guess `RunicGateway` was on the wire and "nothing" was on the
  screen;
* `btn ghost` is not a class this platform defines (`.btn-ghost` is), so every
  secondary button in this module has rendered as a primary one since phase 7 —
  here it made the open file and the active tier indistinguishable;
* a save's refusal rendered at the top of a long form, far from the button.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMH6bw1jXMgbyF3ZWGEzSM
2026-09-22 08:55:28 -05:00

100 lines
5.3 KiB
JavaScript
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

// ── Admin · Rust ──────────────────────────────────────────────────────────
//
// Mounted at `/api/v1/admin/rust`. The tier's gate is already applied: `admin`
// sits behind `noindex, isLoggedIn, requireRole('admin','editor','moderator')`.
//
// **That gate is broader than these routes should be.** Editing a server row
// means editing the credential that reaches a game host, which is an
// administrator's job and not a moderator's — so the routes that write add
// `requireRole('admin')` on top of the tier. A module adds per-route gates over
// the tier gate and never re-implements it; this is what adding one looks like.
//
// ── The token is write-only ───────────────────────────────────────────────
//
// `sidecarToken` is accepted and never returned. The list route reports
// `hasToken` instead, because a blank field otherwise means both "unset" and
// "set, and not being shown to you". An empty string on a save leaves the stored
// value alone — an operator renaming a server must not have to re-paste a
// credential, and a form that posts its own blank field would otherwise erase one
// on every unrelated edit.
const core = require('../../core')
const express = core.express
const admin = require('./rust.controller')
const { requireRole, validate } = core.middleware
const { body, param } = core.validator
const adminRustRouter = express.Router()
// R2's authoring surface, under `/rust/permissions`. Its own file because it is
// its own subject — this router configures the bridge, that one decides who may
// do what inside the game the bridge reaches.
adminRustRouter.use('/permissions', require('./permissions.router'))
// R18's editor, under `/rust/config`. A third subject again: this router
// configures the BRIDGE, `permissions` decides who may do what inside the game,
// and this one edits the game host's own plugin settings.
adminRustRouter.use('/config', require('./config.router'))
adminRustRouter.get(
'/servers',
// #swagger.tags = ['Admin · Rust']
// #swagger.summary = 'Every configured Rust server'
// #swagger.description = 'The operators server rows with their sidecar URLs, whether a token is stored, and whether each sidecar was reachable on the last poll. The token itself is never returned.'
/* #swagger.responses[200] = { description: 'The configured servers', content: { "application/json": { schema: { $ref: "#/components/schemas/RustAdminServerList" } } } } */
admin.listServers,
)
adminRustRouter.put(
'/servers/:id',
// #swagger.tags = ['Admin · Rust']
// #swagger.summary = 'Create or update a Rust server'
// #swagger.description = 'Writes one server row. `sidecarToken` is write-only — send it to set or rotate the credential, and omit it or send an empty string to leave the stored one untouched. The id is the slug every URL under the module carries.'
/* #swagger.responses[204] = { description: 'Saved' } */
/* #swagger.responses[400] = { description: 'Invalid body' } */
requireRole('admin'),
param('id')
.matches(/^[a-z0-9][a-z0-9-]{0,63}$/)
.withMessage('id must be lowercase letters, digits and hyphens'),
body('name').isString().trim().isLength({ min: 1, max: 120 }),
// A base URL is validated for SHAPE and not for reachability: an operator
// configures a sidecar before installing it about half the time, and refusing
// the row because nothing answers yet would make the obvious order of
// operations impossible.
body('sidecarBaseUrl').isURL({ require_tld: false, protocols: ['http', 'https'] }),
body('sidecarToken').optional({ values: 'falsy' }).isString().isLength({ max: 512 }),
body('protocol').optional().isInt({ min: 1, max: 1000 }).toInt(),
body('enabled').optional().isBoolean().toBoolean(),
body('sortOrder').optional().isInt({ min: -1000, max: 1000 }).toInt(),
validate,
admin.putServer,
)
adminRustRouter.delete(
'/servers/:id',
// #swagger.tags = ['Admin · Rust']
// #swagger.summary = 'Remove a Rust server'
// #swagger.description = 'Deletes the server row and the observed state that hangs off it. It does not touch the sidecar or the game host — those are removed with the installer.'
/* #swagger.responses[204] = { description: 'Deleted' } */
requireRole('admin'),
param('id').isString().isLength({ min: 1, max: 64 }),
validate,
admin.deleteServer,
)
adminRustRouter.post(
'/servers/:id/test',
// #swagger.tags = ['Admin · Rust']
// #swagger.summary = 'Probe a servers sidecar'
// #swagger.description = 'Calls the sidecars health endpoint with the stored credential and reports what came back — whether it answered, whether the bridge plugin is connected to it, and which protocol version it speaks. This is the one route that tells a wrong URL from a wrong token from a mismatched version.'
/* #swagger.responses[200] = { description: 'What the sidecar said', content: { "application/json": { schema: { $ref: "#/components/schemas/RustSidecarProbe" } } } } */
/* #swagger.responses[404] = { description: 'No such server' } */
requireRole('admin'),
param('id').isString().isLength({ min: 1, max: 64 }),
validate,
admin.testServer,
)
module.exports = adminRustRouter