R2, and the first phase where this module WRITES to a game. Groups and grants are authored on the website and pushed into each server's own permission store, so every plugin that already calls `UserHasPermission` honours them with no adapter, and a wipe stops being a data-loss event. **Seven org-lead decisions (D28-D34).** A grant is keyed to the website USER and resolved to every Steam id they have linked at push time (D28); every authored row carries a scope — a server or `*` (D29); groups are mirrored as real groups rather than flattened (D30); a holder the site did not author is REPORTED, never undone, with adopt and revoke offered (D31); one verb, with the plugin diffing locally (D32); a permission no server has registered is reported unresolved and never self-registered (D33); authoring is people and groups by hand, with rules deferred (D34). **Three sets, and every interesting question is a difference between two.** `desired − pushed` is what to apply; `pushed − desired` is what to RETIRE, because the site put it there and has since withdrawn it; `present − desired` is drift. The middle one is why `rust_perm_pushed` exists: a name in the store that is not in the desired set is either something the site retired or something a human granted, and those two have opposite correct answers. **What lands is not what was sent.** A grant naming a permission the server has not registered did not land — `GrantUserPermission` no-ops silently — and a member the store has never seen could not be placed. Neither is recorded as pushed, so the site never believes it gave a privilege it did not. The loop asks a cheap question every thirty seconds — does the digest of the desired set still equal what this server last confirmed — and syncs on a change, a restart, a wipe, a drift hook, a failed attempt past its backoff, or the fifteen-minute audit that finds drift on a server nobody has touched. **This module's first admin page**, because a permission model is the first thing here that has to be composed rather than configured. What is on it is decided by what an operator can get wrong: four states are invisible from the game and from a list of grants, and each is a sentence rather than a number. Walked end to end against a real core at the pinned ref, the real sidecar, and a stand-in speaking protocol 4 — including a restart that emptied the store and was fully re-pushed. Four defects the browser found that 133 green tests did not. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PMH6bw1jXMgbyF3ZWGEzSM
119 lines
4.4 KiB
JavaScript
119 lines
4.4 KiB
JavaScript
// ── The boundary, asserted ────────────────────────────────────────────────
|
|
//
|
|
// `catalogue.js` is the only thing standing between a frame carrying an IP
|
|
// address and a public page, so it gets a suite of its own rather than being
|
|
// covered incidentally by a route test.
|
|
//
|
|
// The most valuable test here is the last one: it holds the classification
|
|
// against the specification in `docs/rust-link/PROTOCOL.md` §8.4. Without it the
|
|
// two drift the first time somebody adds a kind to the protocol, and the drift
|
|
// is silent in the direction that matters — a new kind is simply never served,
|
|
// until the day somebody "fixes" that by adding it to the wrong list.
|
|
|
|
const test = require('node:test')
|
|
const assert = require('node:assert')
|
|
|
|
const catalogue = require('../catalogue')
|
|
|
|
test('an unknown kind is not public — the default is deny', () => {
|
|
assert.equal(catalogue.isPublic('player.death'), true)
|
|
assert.equal(catalogue.isPublic('something.new'), false)
|
|
assert.equal(catalogue.isPublic(''), false)
|
|
assert.equal(catalogue.isPublic(undefined), false)
|
|
|
|
// The shape of the mistake this prevents: a kind a LATER protocol adds, which
|
|
// this build ingests happily and would publish on the day it first arrived if
|
|
// the filter were a deny list.
|
|
assert.equal(catalogue.isKnown('player.location'), false)
|
|
assert.equal(catalogue.isPublic('player.location'), false)
|
|
})
|
|
|
|
test('nothing carrying an IP address, a report or an identity is public', () => {
|
|
for (const kind of [
|
|
'player.login.attempt',
|
|
'player.approved',
|
|
'player.banned',
|
|
'player.unbanned',
|
|
'player.reported',
|
|
'entity.destroyed',
|
|
// Protocol 3. A link request on a public killfeed would tell everyone which
|
|
// Steam id is about to become a named website account, and an unlink would
|
|
// say when somebody stopped being one.
|
|
'account.link.requested',
|
|
'account.unlinked',
|
|
]) {
|
|
assert.equal(catalogue.isPublic(kind), false, `${kind} must not be public`)
|
|
assert.ok(catalogue.STAFF_KINDS.includes(kind), `${kind} must be classified, not merely absent`)
|
|
}
|
|
})
|
|
|
|
test('a viewer with no kinds asked for gets the allowlist, never everything', () => {
|
|
const asPublic = catalogue.kindsFor({})
|
|
const asAdmin = catalogue.kindsFor({ admin: true })
|
|
|
|
assert.deepEqual(asPublic, [...catalogue.PUBLIC_KINDS])
|
|
assert.equal(asAdmin.length, catalogue.ALL_KINDS.length)
|
|
|
|
// The property that makes the route safe by construction: there is no argument
|
|
// a caller can omit that turns the filter off.
|
|
assert.ok(asPublic.length > 0)
|
|
assert.ok(!asPublic.includes('player.banned'))
|
|
})
|
|
|
|
test('a kind a viewer may not see is dropped, not refused', () => {
|
|
const asked = catalogue.kindsFor({ requested: ['player.death', 'player.banned'] })
|
|
|
|
assert.deepEqual(asked, ['player.death'])
|
|
|
|
// Asking for only forbidden kinds answers with nothing to select, which the
|
|
// model turns into an empty list — the events are, as far as this viewer is
|
|
// concerned, not there.
|
|
assert.deepEqual(catalogue.kindsFor({ requested: ['player.banned'] }), [])
|
|
|
|
// And an admin gets what they asked for.
|
|
assert.deepEqual(catalogue.kindsFor({ admin: true, requested: ['player.banned'] }), [
|
|
'player.banned',
|
|
])
|
|
})
|
|
|
|
test('every kind is classified exactly once', () => {
|
|
const seen = new Set()
|
|
|
|
for (const kind of catalogue.ALL_KINDS) {
|
|
assert.ok(!seen.has(kind), `${kind} appears in both lists`)
|
|
seen.add(kind)
|
|
}
|
|
|
|
assert.equal(seen.size, catalogue.PUBLIC_KINDS.length + catalogue.STAFF_KINDS.length)
|
|
})
|
|
|
|
test('the classification covers exactly the kinds protocol 4 defines', () => {
|
|
// The spec lives in another repository, so the list is restated here rather
|
|
// than parsed — and restating it is the point: adding a kind to the protocol
|
|
// without deciding who may see it has to fail somewhere, and this is where.
|
|
//
|
|
// Sourced from docs/rust-link/PROTOCOL.md §8.4.
|
|
const PROTOCOL_4 = [
|
|
'player.connected',
|
|
'player.disconnected',
|
|
'player.respawned',
|
|
'player.death',
|
|
'player.chat',
|
|
'player.tally',
|
|
'entity.destroyed',
|
|
'player.reported',
|
|
'player.banned',
|
|
'player.unbanned',
|
|
'player.login.attempt',
|
|
'player.approved',
|
|
'server.wipe',
|
|
'server.initialized',
|
|
'server.shutdown',
|
|
'account.link.requested',
|
|
'account.unlinked',
|
|
'perm.drift',
|
|
]
|
|
|
|
assert.deepEqual([...catalogue.ALL_KINDS].sort(), [...PROTOCOL_4].sort())
|
|
})
|