feat(shard): ingest points.board and publish the leaderboards

Protocol 3.0 §7 (docs/link/v3.md). The shard publishes ~25 points/loyalty
leaderboards — Queen's Loyalty, Void Pool, the nine city loyalties, Clean Up
Britannia — and the site renders them, plus each character's own standings on
their sheet.

Server
  - shard_points_boards: one row per system, keyed by the shard's PointsType
    name. The top-N list stays inside `payload` — a fixed-size list read whole,
    exactly like shard_governors.candidates. Normalizing into an entries table
    buys nothing until something needs a per-character reverse lookup, and a
    character's own standings already ride inside char.profile.
  - shardIngest routes points.board to upsertPointsBoard and deliberately does
    NOT log it: this is board state like guild.update, and the shard emits a
    frame every time anyone's score moves a top ten.
  - uoLinkSocket backfills /points through snapshot() with ingestEach rather
    than a replace*: there is no points.remove and the system set is fixed, so
    upserting IS the reconciliation, and a system the operator later excludes
    keeps its last-known board rather than vanishing.
  - GET /public/shard/points and /points/:system behind
    requireFeature('leaderboards'), both projected per §3.6.1. :system is
    constrained to an identifier before any query runs; 404 for a system never
    published, distinct from a published board nobody has scored in (200, empty
    top).

The leaderboards field rule now keys on `name`, not `characterName`
  Part A pre-wired FEATURES.leaderboards.fields = { characterName: ... }, but
  projectValue matches on the LITERAL JSON key and the wire key is `name`. As
  written the rule was inert: an admin tightening character names would have got
  no enforcement and no error — precisely the failure §3.6.1 records for the
  flattened `ownerAcct` spelling. Fixed, with a test that fails if it is renamed
  back, and the admin panel's FIELD_LABEL carries the meaning instead.

Client
  - routes/public/Leaderboards.jsx at /site/leaderboards. A points.board frame
    describes ONE system, so live frames merge over the fetched set by system
    key rather than replacing it wholesale the way the ruleset does. Filter
    matches board name, system key, or any ranked player — the last is what
    makes it useful ("where do I appear?").
  - A "Loyalty & Points" section in CharacterSheet.jsx, one edit serving both
    PlayerCharacter and AdminCharacter.
  - Both treat maxPoints: 0 as UNCAPPED and both fall back to humanising the
    system key when nameString is null. Neither is defensive padding: on a real
    shard uncapped and cliloc-only names are the majority case.

Verified end to end against the local MariaDB, the Rust sidecar, and the real
ServUO shard: backfill from /points, live SSE delivery (a board absent from the
initial fetch appearing without a reload, and an existing one updating in
place), REST reflecting the overwrite, and the gate at every rung — 200 by
default with names, names stripped but points kept at fieldRules name=staff, 403
plus dropped from /features at audience=staff, 404 when disabled. Page rendered
clean, no console errors beyond the pre-existing React Router v7 warnings.

605 server tests pass; routes.manifest.json, routes.guards.json and the OpenAPI
spec regenerated.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-07-28 21:04:44 -05:00
parent bfa1db58c4
commit 26094459ae
22 changed files with 1098 additions and 2 deletions

View File

@@ -295,6 +295,85 @@ test('getRuleset projects: acct/webId never survive below admin', async () => {
}
})
// ── points boards ──────────────────────────────────────────────────────
const BOARD = {
system: 'QueensLoyalty',
nameString: "Queen's Loyalty",
nameNumber: 1114938,
maxPoints: 30000,
players: 842,
top: [
{ rank: 1, serial: '0x1A2B', name: 'Darrow', points: 29500 },
{ rank: 2, serial: '0x1A2C', name: 'Mireille', points: 21000 },
],
}
test('getPointsBoards serves every board with its ranked list intact', async () => {
shardState.listPointsBoards = async () => [BOARD]
const res = mockRes()
await ctrl.getPointsBoards({ viewerLevel: 'anonymous' }, res)
assert.equal(res.body.length, 1)
assert.equal(res.body[0].system, 'QueensLoyalty')
// The ranked list is an ARRAY through projection, not an object keyed 0/1 —
// the same trap the ruleset's rankThresholds assertion guards.
assert.ok(Array.isArray(res.body[0].top))
assert.equal(res.body[0].top[1].name, 'Mireille')
})
test('getPointsBoards serves an empty list before the shard has published any', async () => {
shardState.listPointsBoards = async () => []
const res = mockRes()
await ctrl.getPointsBoards({ viewerLevel: 'anonymous' }, res)
assert.deepEqual(res.body, [])
assert.equal(res.statusCode, 200)
})
// §3.6.1's rule again: a shard read that does not project is a bug. Boards carry
// no actor today — they write entries inline as {serial, name} precisely so they
// never carry acct/webId — but the gate is what keeps that true if the shape grows.
test('getPointsBoard projects: acct/webId never survive below admin', async () => {
shardState.getPointsBoard = async () => ({
system: 'QueensLoyalty',
top: [{ rank: 1, name: 'Darrow', acct: 'darrow_acct', webId: 9, points: 1 }],
})
for (const level of ['anonymous', 'logged_in', 'player', 'staff']) {
const res = mockRes()
await ctrl.getPointsBoard({ params: { system: 'QueensLoyalty' }, viewerLevel: level }, res)
assert.equal(res.body.top[0].acct, undefined, `${level} saw acct`)
assert.equal(res.body.top[0].webId, undefined, `${level} saw webId`)
assert.equal(res.body.top[0].name, 'Darrow', 'the ranked name is public by default')
}
})
// "No such system" and "a board nobody has scored in" are different answers.
test('getPointsBoard 404s for a system the shard has never published', async () => {
shardState.getPointsBoard = async () => null
const res = mockRes()
await ctrl.getPointsBoard({ params: { system: 'NoSuchSystem' }, viewerLevel: 'anonymous' }, res)
assert.equal(res.statusCode, 404)
})
test('getPointsBoard rejects a malformed system name before touching the model', async () => {
let queried = false
shardState.getPointsBoard = async () => { queried = true; return null }
for (const system of ['../etc', 'a'.repeat(64), '', 'has space', '1leading']) {
const res = mockRes()
await ctrl.getPointsBoard({ params: { system }, viewerLevel: 'anonymous' }, res)
assert.equal(res.statusCode, 400, `${JSON.stringify(system)} should be rejected`)
}
assert.equal(queried, false, 'a malformed name must never reach the query')
})
test('getPointsBoards degrades to a 500 when the model fails, without throwing', async () => {
shardState.listPointsBoards = async () => {
throw new Error('pool down')
}
const res = mockRes()
await ctrl.getPointsBoards({ viewerLevel: 'anonymous' }, res)
assert.equal(res.statusCode, 500)
assert.equal(res.body.message, 'Internal Server Error')
})
test('getRuleset degrades to a 500 when the model fails, without throwing', async () => {
shardState.getRuleset = async () => {
throw new Error('pool down')