Files
JesseandClaude Opus 5 a70337cf8b 0.8.0.12:0 — bundle Station Master v0.8.0.12, and a Restore a Seat action
A player who has lost their browser storage can be put back in their seat
(Gitea#33 in the game repo). The session token is the only identity the game
has and it lives in one browser's localStorage, scoped to the origin joined at,
so a cleared profile, a private window or a different browser locks a player
out of a game that is still running with their session still on disk. Seen at a
real table: of two humans in one game, the host reloaded straight back in and
the joiner met an empty lobby.

New action, restore-seat: pick a seat from a dropdown of the players actually
holding a session — bots never appear, since seatedPlayers is read from the
server's session map rather than guessed from display names — and get back a
link built from this interface's own address. serverApi gained mintClaim; the
dictionary gained 57-64 in all five locales.

THE LINK CARRIES A CODE, NOT THE TOKEN. lobby-and-sessions.md §1 says to keep
the token out of URLs so it is not shoulder-surfed or pasted into a chat, and a
recovery link is exactly what gets pasted into a chat. The code is single-use,
expires in 30 minutes, and the page trades it for the real token over a POST.
Minting is admin-gated because deciding that somebody has lost a seat is a
judgement no route can make safely; spending needs no secret, because the
player following the link holds none.

GAMES IN PROGRESS RESUME NORMALLY, measured rather than assumed:
`git diff v0.8.0.11..v0.8.0.12 -- src/engine/` is EMPTY. The release is the
server's HTTP surface, the client and the docs. The codes live in memory and
are deliberately not persisted, so nothing new reaches the volume and there is
nothing to migrate. README, instructions.md and the release notes in all five
locales say so.

NOT YET EXERCISED END TO END: the two routes and the action are typechecked and
the claim store is unit-tested, but nothing has run them against a live server.
This build is what makes that possible.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017nnuCv8UodHucFfx3LWEoX
2026-09-16 20:21:15 -04:00

12 lines
365 B
TypeScript

import { sdk } from '../sdk'
import { gamesInProgress } from './gamesInProgress'
import { getJoinSecret } from './getJoinSecret'
import { manageGame } from './manageGame'
import { restoreSeat } from './restoreSeat'
export const actions = sdk.Actions.of()
.addAction(getJoinSecret)
.addAction(gamesInProgress)
.addAction(manageGame)
.addAction(restoreSeat)