module-rust, id 'rust', built from the Integration Kit's template. Phase 1's job
is the kit's own argument: get every seam working at once with almost nothing in
them, so that afterwards you break exactly one at a time.
What is here:
* /rust on all three tiers, because the loader holds module.json's mounts against
what is registered in BOTH directions -- so the declaration and the
registration land together or not at all. The player tier is honestly thin: it
answers the server list on the authenticated tier, delegating to the same model
the public tier uses so the two cannot drift while they are meant to be the
same. It is the address the app will call, registered now rather than moved
later.
* Two tables. rust_servers is configuration an operator writes; rust_server_state
is what a sidecar reported. Separate tables because they have different
writers, lifetimes and audiences -- and because purging observed state while
keeping the configuration is a thing an operator will want.
* Per-server sidecar tokens through ctx.secretBox, write-only in the API. The
admin list reports hasToken and never the credential, and an empty token on a
save leaves the stored one alone -- a form that posts its own blank field would
otherwise erase a credential every time somebody renamed a server.
* A real sidecar client. It never throws: every call answers {ok, status, data},
and the status is what tells a wrong URL from a wrong token from a mismatched
protocol -- all three present as 'the site says my server is offline' and each
has a different fix.
* The five guards, green: check:imports, check:swagger, check:externals, and both
suites.
What is deliberately NOT registered: the Team provider, triggers, audiences,
engagement seeds, notification streams, the four event catalogues, and the two
extension slots. Each arrives with the phase that has something real to put in
it, and a test asserts their absence so that removing it is deliberate. A
declared trigger nothing emits and a declared slot nothing fills are both
surfaces an operator can configure and then wait on, which is worse than an
absent one because the absence is visible.
Two corrections to the kit's template, both feedback for a later phase:
* registration.test.js read one page BY NAME to check declared slots are
rendered, so a module declaring none dies on ENOENT before reaching the loop
that would have been empty. It now scans every file under src/routes.
* test/_fakes.js supplied validator: {}. An admin router that builds validation
chains at file scope cannot be required with that, so the fake holds the real
express-validator -- for the same reason it holds a real express Router.
The kit was right about noGameConnection.test.js: its header predicts that a
module adding a sidecar client will see the check go red, names sidecarClient.js
as the file to allow, and says narrow it rather than delete it. That is exactly
what happened on the first run, and the fix was the one line the header names.
Installed into a real core and verified: the module reaches 'started', publishes
its capability, serves its chunk, and renders a server whose server.hello
originated in a live Rust server.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016wDDVXWMDz82WqE1i969r4
140 lines
5.4 KiB
JavaScript
140 lines
5.4 KiB
JavaScript
// ── The logic half ────────────────────────────────────────────────────────
|
|
//
|
|
// Shapes what the database returned into what a client should see, and holds the
|
|
// one rule that matters most in this module: **what leaves this file is never the
|
|
// sidecar's credential.**
|
|
//
|
|
// It is a separate file from the SQL so that it is testable without a database,
|
|
// and the suite next door tests it that way.
|
|
//
|
|
// The other decision worth pointing at: **a module answers when the game is
|
|
// unreachable rather than failing.** The website is the internet-facing process
|
|
// and the game is not; a game being down, or a sidecar being mid-restart, is an
|
|
// ordinary Tuesday. A page that renders "offline, last seen 20 minutes ago" is
|
|
// right; a page that 500s because a socket is closed is a module that has made
|
|
// the site's availability depend on the game's.
|
|
|
|
const core = require('../../core')
|
|
const db = require('./servers.db')
|
|
|
|
const log = core.logger('servers')
|
|
|
|
// Past this, the last thing a server said stops being news and starts being
|
|
// history. Presentation, so the number lives with the code that shapes the
|
|
// response rather than in the client.
|
|
const STALE_AFTER_MS = 5 * 60 * 1000
|
|
|
|
/**
|
|
* A configured server with its token decrypted, for this module's own use.
|
|
*
|
|
* **Never hand the result of this to a controller.** It is the input to
|
|
* `sidecarClient`, and the only shape in this module that holds a plaintext
|
|
* secret.
|
|
*
|
|
* A token that will not decrypt is returned as `null` rather than throwing: the
|
|
* usual cause is a `SECRET_ENC_KEY` that changed, and the right behaviour is a
|
|
* server that reports itself unconfigured with a line in the log — not a module
|
|
* that fails to boot and takes every other server down with it.
|
|
*/
|
|
function withToken(row) {
|
|
if (!row) return null
|
|
|
|
let token = null
|
|
if (row.sidecarTokenEnc) {
|
|
try {
|
|
token = core.secretBox().decrypt(row.sidecarTokenEnc)
|
|
} catch (err) {
|
|
log.error('could not decrypt a sidecar token', { server: row.id, error: err.message })
|
|
}
|
|
}
|
|
|
|
return { id: row.id, name: row.name, baseUrl: row.sidecarBaseUrl, token, protocol: row.protocol }
|
|
}
|
|
|
|
/** Every enabled server, with tokens, for the poller. */
|
|
async function listForPolling() {
|
|
const rows = await db.listServers({ enabledOnly: true })
|
|
return rows.map(withToken)
|
|
}
|
|
|
|
/**
|
|
* The public view: every enabled server and what it last said.
|
|
*
|
|
* Nothing here is conditional on who is asking, which is the point of it being
|
|
* the public shape. What a *player* or an *admin* additionally sees is added by
|
|
* their own tier's controller, never removed by this one.
|
|
*/
|
|
async function listPublic(now = Date.now()) {
|
|
const [servers, states] = await Promise.all([db.listServers({ enabledOnly: true }), db.listState()])
|
|
const byId = new Map(states.map((s) => [s.serverId, s]))
|
|
|
|
return servers.map((row) => shapePublic(row, byId.get(row.id), now))
|
|
}
|
|
|
|
function shapePublic(row, state, now) {
|
|
const updatedAt = state && state.updatedAt ? new Date(state.updatedAt) : null
|
|
const stale = !updatedAt || now - updatedAt.getTime() > STALE_AFTER_MS
|
|
|
|
return {
|
|
id: row.id,
|
|
name: row.name,
|
|
// A stale row cannot claim a server is up. The row says what was true when it
|
|
// was written, and nothing has written it since.
|
|
online: Boolean(state && state.online) && !stale,
|
|
players: stale ? 0 : Number(state && state.players) || 0,
|
|
maxPlayers: Number(state && state.maxPlayers) || 0,
|
|
hostname: (state && state.hostname) || null,
|
|
level: (state && state.level) || null,
|
|
worldSize: state && state.worldSize != null ? Number(state.worldSize) : null,
|
|
seed: state && state.seed != null ? Number(state.seed) : null,
|
|
updatedAt: updatedAt ? updatedAt.toISOString() : null,
|
|
stale,
|
|
}
|
|
}
|
|
|
|
/**
|
|
* The admin view: configuration plus reachability, and **no token**.
|
|
*
|
|
* `hasToken` rather than the token, because the credential is write-only in the
|
|
* API: the admin form accepts a new value and never shows the stored one. An
|
|
* operator still needs to know whether one is set — a blank field means both
|
|
* "unset" and "set, and not being shown you" otherwise.
|
|
*/
|
|
async function listForAdmin(now = Date.now()) {
|
|
const [servers, states] = await Promise.all([db.listServers(), db.listState()])
|
|
const byId = new Map(states.map((s) => [s.serverId, s]))
|
|
|
|
return servers.map((row) => {
|
|
const state = byId.get(row.id)
|
|
return {
|
|
// The public shape first, so the admin-only fields below cannot be
|
|
// overwritten by a key the public shape happens to share.
|
|
...shapePublic(row, state, now),
|
|
sidecarBaseUrl: row.sidecarBaseUrl,
|
|
hasToken: Boolean(row.sidecarTokenEnc),
|
|
protocol: Number(row.protocol),
|
|
enabled: Boolean(row.enabled),
|
|
sortOrder: Number(row.sortOrder),
|
|
reachable: Boolean(state && state.reachable),
|
|
bootId: (state && state.bootId) || null,
|
|
sidecarProtocol: state && state.protocol != null ? Number(state.protocol) : null,
|
|
}
|
|
})
|
|
}
|
|
|
|
/** Encrypt a token for storage. `null`/empty means "leave whatever is stored alone". */
|
|
function encryptToken(token) {
|
|
if (token === null || token === undefined || token === '') return null
|
|
return core.secretBox().encrypt(String(token))
|
|
}
|
|
|
|
module.exports = {
|
|
STALE_AFTER_MS,
|
|
withToken,
|
|
listForPolling,
|
|
listPublic,
|
|
listForAdmin,
|
|
shapePublic,
|
|
encryptToken,
|
|
}
|