Restrict public presence to staff + let admins view any character
Public "Online now" now lists only players whose game account is linked to a STAFF website user (admin/editor/moderator) — linked players are no longer exposed publicly with their name and location. listOnlineLinked joins through to users and filters on role; the section is relabeled "Staff online". Character/roster/vendor reads gain an admin bypass: admins may view any character's data, while players (and editor/moderator staff) stay limited to accounts they have personally linked. The bypass lives in the shared player controller and only ever widens access for genuine admins. Also finalizes the uo-link character/vendor front end (player + admin character sheets, VendorSales component, ShardChar removed) and regenerates swagger-output.json. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018kj5s1QCKobuFPYmqxjy1q
This commit is contained in:
@@ -15,9 +15,10 @@
|
||||
|
||||
const log = require('./logger')('shard-broadcast')
|
||||
|
||||
// Kinds safe to expose to unauthenticated browsers.
|
||||
// Kinds safe to expose to unauthenticated browsers. Note: vendor.sale is
|
||||
// deliberately NOT here — sales are owner-private (a linked player sees only
|
||||
// their own, via /player/shard/sales).
|
||||
const PUBLIC_KINDS = new Set([
|
||||
'vendor.sale',
|
||||
'player.death',
|
||||
'player.murdered',
|
||||
'mob.killed',
|
||||
|
||||
Reference in New Issue
Block a user