A first-party Rust clan is a Team (R5). This module becomes the site's Team provider and answers core from the plugin's `clans` board. Design of record: docs/modules/rust/PLAN.md §24, D47-D58. - The store: rust_clans, rust_clan_members and rust_clan_boards. A clan's identity is <serverId>:<clanId>:<createdMs> (D52), because the game restarts clan ids whenever its clan database version changes. - The provider (D53): getTeams is complete only when every server's board is fresh, supported and untruncated. It is partial when some are, and refuses when none are. Freshness is judged by the website's clock, from when the board's `t` last advanced. - Only a complete board may mark a clan gone. A board at the game's 100-clan ceiling (D55), or one with an unreadable row, proves nothing about what it leaves out. - Leadership is diffed board to board and published (D54). The five clan events are published as team.* kinds, and written to the Team feed as members-only lines (D49). - Core only writes feed items for a Team it already holds. So the last 10 minutes of clan events are re-offered on each board refresh, deduped by a sha1 key: core clamps a dedupeKey to 40 characters, and a readable key would be truncated into collisions. - projectRoster and the clan page share one audience rule (D48): the clan's linked members and staff by default, re-read from the users row. The setting lives on Admin > Rust visibility, which also warns about uMod Clans (D47) and the ceiling. - Public: GET servers/:id/clans (the list is public, D58) and GET clans/:externalId. The client adds a Clans tab and /rust/clans/:externalId, with three module slots for core's notify, activity and forum contributions (D56). - Linking and unlinking an account ask core to reconcile Teams (D57). - The clan kinds are staff-class in the public feed allowlist. - PROTOCOL_VERSION is now 6. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
220 lines
7.9 KiB
JavaScript
220 lines
7.9 KiB
JavaScript
// ── Public · Rust — the handlers ──────────────────────────────────────────
|
|
//
|
|
// Thin on purpose: read the request, call a model, answer. Everything worth
|
|
// testing is in the model, which needs no express and no database to test.
|
|
//
|
|
// **A handler must not throw past express.** Core mounts this router inside its
|
|
// own tier router, so an unhandled rejection here reaches core's error handler
|
|
// and answers 500 — survivable, but it means an operator sees core blamed for a
|
|
// fault in this module. Catch, log through `core.logger` (so the line carries the
|
|
// module id), and answer something honest.
|
|
|
|
const core = require('../../core')
|
|
|
|
const clans = require('../../model/clans/clans.model')
|
|
const events = require('../../model/events/events.model')
|
|
const servers = require('../../model/servers/servers.model')
|
|
const visibility = require('../../model/visibility/visibility.model')
|
|
|
|
const log = core.logger('public')
|
|
|
|
/**
|
|
* Marks a response as depending on who asked.
|
|
*
|
|
* Three routes below answer differently for a moderator and for a stranger, and
|
|
* a shared cache in front of the site that stored the moderator's answer would
|
|
* hand the roll call to the next anonymous visitor. `private` keeps it out of
|
|
* every cache but the viewer's own; `Vary` says why, for any cache that reads it.
|
|
*/
|
|
function perViewer(res) {
|
|
res.set('Cache-Control', 'private, no-store')
|
|
res.vary('Cookie')
|
|
res.vary('Authorization')
|
|
}
|
|
|
|
async function listServers(req, res) {
|
|
try {
|
|
res.json({ servers: await servers.listPublic() })
|
|
} catch (err) {
|
|
log.error('failed to read the server list', { error: err.message })
|
|
res.status(500).json({ message: 'Failed to read the server list' })
|
|
}
|
|
}
|
|
|
|
/**
|
|
* One server, or a 404.
|
|
*
|
|
* **The 404 is the feature.** Everything else under `/servers/:id` answers an
|
|
* empty list for a server that does not exist — an unknown id has no events, no
|
|
* leaderboard and nobody online, and each of those is a perfectly good answer to
|
|
* the question it was asked. Only this route can tell the page that the server
|
|
* itself is not there, which is what stops `/rust/servers/typo` rendering as a
|
|
* quiet server with nothing to say.
|
|
*/
|
|
async function getServer(req, res) {
|
|
try {
|
|
const server = await servers.getPublic(req.params.id)
|
|
if (!server) {
|
|
res.status(404).json({ message: 'No such server' })
|
|
return
|
|
}
|
|
res.json({ server })
|
|
} catch (err) {
|
|
log.error('failed to read a server', { server: req.params.id, error: err.message })
|
|
res.status(500).json({ message: 'Failed to read the server' })
|
|
}
|
|
}
|
|
|
|
/**
|
|
* The killfeed, and everything else public that happened on one server.
|
|
*
|
|
* **`admin` is not passed, and that is the whole security posture of this
|
|
* handler.** `events.recent` takes the viewer explicitly and defaults to the
|
|
* public allowlist, so the way to leak an IP address from here is to add an
|
|
* argument rather than to forget one.
|
|
*
|
|
* `presence` is resolved per request from the operator's setting. Below it, the
|
|
* feed carries only what names nobody — a wipe, a start, a shutdown — and says
|
|
* so with `presenceHidden`, so a page can explain a quiet feed instead of
|
|
* implying a quiet server.
|
|
*/
|
|
async function listEvents(req, res) {
|
|
try {
|
|
const presence = await visibility.canSeePresence(req, req.params.id)
|
|
perViewer(res)
|
|
res.json({
|
|
events: await events.recent({
|
|
serverId: req.params.id,
|
|
presence: presence.visible,
|
|
kind: req.query.kind,
|
|
wipeId: req.query.wipe || null,
|
|
limit: req.query.limit,
|
|
}),
|
|
presenceHidden: !presence.visible,
|
|
presenceAudience: presence.required,
|
|
})
|
|
} catch (err) {
|
|
log.error('failed to read events', { server: req.params.id, error: err.message })
|
|
res.status(500).json({ message: 'Failed to read events' })
|
|
}
|
|
}
|
|
|
|
async function listLeaderboard(req, res) {
|
|
try {
|
|
const presence = await visibility.canSeePresence(req, req.params.id)
|
|
perViewer(res)
|
|
res.json({
|
|
leaderboard: await events.leaderboard({
|
|
serverId: req.params.id,
|
|
wipeId: req.query.wipe || null,
|
|
sort: req.query.sort,
|
|
limit: req.query.limit,
|
|
presence: presence.visible,
|
|
}),
|
|
})
|
|
} catch (err) {
|
|
log.error('failed to read the leaderboard', { server: req.params.id, error: err.message })
|
|
res.status(500).json({ message: 'Failed to read the leaderboard' })
|
|
}
|
|
}
|
|
|
|
async function listWipes(req, res) {
|
|
try {
|
|
res.json({ wipes: await events.wipes(req.params.id) })
|
|
} catch (err) {
|
|
log.error('failed to read wipes', { server: req.params.id, error: err.message })
|
|
res.status(500).json({ message: 'Failed to read wipes' })
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Who is on the server right now — or, below the operator's audience, how many.
|
|
*
|
|
* The count stays public: it is already on the server list and in the footer,
|
|
* and a number names nobody. The names do not, by default (the org lead's rule,
|
|
* `model/visibility`). A hidden answer is still a 200 with the same shape — an
|
|
* empty `players` array — plus `hidden` and `count`, so a client that predates
|
|
* the flag renders an empty list rather than breaking, and a current one can say
|
|
* "12 online" instead of "nobody".
|
|
*/
|
|
async function listOnline(req, res) {
|
|
try {
|
|
const presence = await visibility.canSeePresence(req, req.params.id)
|
|
perViewer(res)
|
|
|
|
if (!presence.visible) {
|
|
const server = await servers.getPublic(req.params.id)
|
|
res.json({
|
|
players: [],
|
|
hidden: true,
|
|
count: server ? server.players : 0,
|
|
audience: presence.required,
|
|
})
|
|
return
|
|
}
|
|
|
|
const players = await events.online(req.params.id)
|
|
res.json({ players, hidden: false, count: players.length, audience: presence.required })
|
|
} catch (err) {
|
|
log.error('failed to read presence', { server: req.params.id, error: err.message })
|
|
res.status(500).json({ message: 'Failed to read who is online' })
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Who is asking, as core describes a viewer to `projectRoster`: `{ userId, role }`
|
|
* or null. Only the id is trusted — `model/clans` re-reads the row — so a token
|
|
* that cannot be decoded is simply nobody.
|
|
*/
|
|
function viewerOf(req) {
|
|
try {
|
|
const claimed = req.user || core.auth.getUserFromRequest(req)
|
|
if (!claimed || claimed.id == null) return null
|
|
return { userId: claimed.id, role: claimed.role || null }
|
|
} catch (err) {
|
|
return null
|
|
}
|
|
}
|
|
|
|
/**
|
|
* One server's clans (D58): name, colour, score and member count, best first.
|
|
*
|
|
* Public at every setting, because none of it names a player. `board` says
|
|
* whether the list can be trusted — a server whose plugin predates protocol 6,
|
|
* or whose clans the bridge cannot read, answers an empty list AND the reason,
|
|
* so the tab can say "unavailable" rather than "no clans".
|
|
*/
|
|
async function listClans(req, res) {
|
|
try {
|
|
res.json(await clans.listForServer(req.params.id))
|
|
} catch (err) {
|
|
log.error('failed to read clans', { server: req.params.id, error: err.message })
|
|
res.status(500).json({ message: 'Failed to read clans' })
|
|
}
|
|
}
|
|
|
|
/**
|
|
* One clan, and its roster when the viewer is inside the roster audience (D48).
|
|
*
|
|
* The same decision core's `projectRoster` makes, from the same function, so
|
|
* this page and core's roster cannot disagree about who may look. Below the
|
|
* audience the clan is still described — its name and its count are public —
|
|
* and `roster.visible` is false with no names at all.
|
|
*/
|
|
async function getClan(req, res) {
|
|
try {
|
|
const answer = await clans.getForViewer(req.params.externalId, viewerOf(req))
|
|
perViewer(res)
|
|
if (!answer) {
|
|
res.status(404).json({ message: 'No such clan' })
|
|
return
|
|
}
|
|
res.json(answer)
|
|
} catch (err) {
|
|
log.error('failed to read a clan', { clan: req.params.externalId, error: err.message })
|
|
res.status(500).json({ message: 'Failed to read the clan' })
|
|
}
|
|
}
|
|
|
|
module.exports = { listServers, getServer, listEvents, listLeaderboard, listWipes, listOnline, listClans, getClan }
|