v0.5.3 — a table you size yourself, and games an administrator can see and end
Both halves came out of playing the StartOS build. The wrapper's health
check and admin actions consume this; they land separately.
The host picks the table size (2-4) when creating a game, and the seats
array is built at that length once. Before, it GREW as people joined, so
the four rows on screen were partly fiction — a 2-player game just started
with a 2-long array, while a host who dropped a bot into a later chair
padded it with a null and silently disabled Start behind a one-line note.
A gap can no longer be written down rather than merely being refused.
That also avoided a trap. Compacting seats at Lobby.Start — the obvious
way to support a "closed" chair — would have shifted the player index that
every PlayerSession stamps at join time and that /api/stream and
/api/intent both route by, handing a player somebody else's railroad with
no error anywhere.
And it fixed a live balance bug: minCombinedRevenue is derived from the
player count, but the config was fixed at CREATE while the count wasn't
known until START, so the lobby guessed 4. Every 2-player game ran against
a floor of 60 instead of 30 — and missing the floor means everyone loses,
so a 2-player competitive game was set up to fail for a UI artifact rather
than a rule.
/api/health gained games:{active,lobby}, read from a new cheap summary()
on GameSession rather than exportSave(), which would copy every intent of
every game to answer a question about none of them. Three admin routes are
new behind an ADMIN_SECRET env var in an x-admin-secret header: GET
/api/games, GET /api/games/<id>/save, DELETE /api/games/<id>. Until now a
started game could not be ended by anyone — no route, no player action, no
resignation — so an abandoned game stayed active in the index and was
faithfully resumed on every boot, forever.
Three deliberate choices there: the admin secret is NOT the join secret,
which every player holds and which would therefore let anyone at the table
destroy anyone else's game; unset means the routes 404 exactly as any
unknown path does, with or without a header, so a server never given an
administrator doesn't advertise that it has one; and a delete returns the
deleted game's save, since the intents are the game (D5) — nothing is
destroyed without being handed to whoever destroyed it.
SavedGame gained an optional lastMoveAt (falling back to createdAt) so
"has this stalled?" survives a restart. Kept out of history for the same
reason the turn timings are: a replay must reproduce a game from decisions
alone, and wall-clock is not a decision.
index.ts logs "Resuming N saved games..." before the loop rather than one
line per game after it. Measured a full 4-player game at 100ms to replay,
and only unfinished games are replayed, so listening before loading would
have bought nothing for the cost of a "still loading" state everywhere.
Verified: 667 tests pass (662 + 5), and the new session tests were checked
against two mutations (lastMoveAt never advancing; resume dropping it) to
confirm they fail without the code. Live against a running server: health
counts tracking through the lobby->game transition, admin auth rejecting a
missing and a wrong secret, list/export/delete, the deleted game's files
and index entry actually gone from disk, a second delete 404ing, the admin
routes invisible when ADMIN_SECRET is unset, and a 3-player table refusing
a 4th player and a size of 5 refused at the door.
Also carries the TODO items raised on 2026-08-21: the lobby offering no
game parameters (the floor bug within it now fixed, the form still
missing), and the four optionalRules — of which only reducedVisibility and
emergencyToolbox are read by anything, while sisterTrains and
employeeRotation are declared, defaulted, and consulted nowhere.
This commit is contained in:
+129
-4
@@ -27,8 +27,11 @@ import type { Intent } from '../engine/intents.ts';
|
||||
import type { GameConfig, PlayerIndex } from '../engine/state.ts';
|
||||
import {
|
||||
appendTiming,
|
||||
deleteGame,
|
||||
deleteLobby,
|
||||
gameDir,
|
||||
readIndex,
|
||||
removeIndexEntry,
|
||||
upsertIndexEntry,
|
||||
writeGame,
|
||||
writeLobby,
|
||||
@@ -39,6 +42,7 @@ import type { GameSession, Push } from './session.ts';
|
||||
import {
|
||||
createLobby,
|
||||
freshGameCode,
|
||||
playerCountAllowed,
|
||||
joinLobby,
|
||||
reassignHost,
|
||||
setBotSeat,
|
||||
@@ -58,6 +62,14 @@ export type ServerOptions = {
|
||||
dataDir: string;
|
||||
/** `package.json`'s version — stamped onto every write, checked on every load (§12 step 15). */
|
||||
engineVersion: string;
|
||||
/**
|
||||
* Gates the administrative routes — listing, exporting and deleting games — and is DELIBERATELY
|
||||
* not the join secret. Every player holds that one, so gating a delete with it would let anyone
|
||||
* at the table destroy anyone else's game. This is held by whoever runs the server and nobody
|
||||
* else. When it is unset the admin routes do not exist at all (404, the same answer as any other
|
||||
* unknown path), so a server that was never given one cannot be administered by guessing.
|
||||
*/
|
||||
adminSecret?: string | undefined;
|
||||
/** Reconstructed by `index.ts`'s load-on-start. Empty maps for a fresh server. */
|
||||
initialGames: Map<string, GameSession>;
|
||||
initialLobbies: Map<string, Lobby>;
|
||||
@@ -212,24 +224,137 @@ export function startServer(opts: ServerOptions): void {
|
||||
* is what the client is about to offer the player anyway. It reveals no game and no seat.
|
||||
*/
|
||||
if (url.pathname === '/api/health' && req.method === 'GET') {
|
||||
sendJson(res, 200, { ok: true, service: 'station-master', engineVersion: opts.engineVersion });
|
||||
// `summary()` rather than `exportSave()`: this is polled on a timer, and the save copies
|
||||
// every intent of every game to answer a question about none of them.
|
||||
let active = 0;
|
||||
for (const g of games.values()) if (g.summary().status === 'active') active++;
|
||||
sendJson(res, 200, {
|
||||
ok: true,
|
||||
service: 'station-master',
|
||||
engineVersion: opts.engineVersion,
|
||||
games: { active, lobby: lobbies.size },
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
// -- Administration: listing, exporting and deleting games ------------------------------
|
||||
|
||||
if (url.pathname === '/api/games' || url.pathname.startsWith('/api/games/')) {
|
||||
// Unset means the routes are not here — indistinguishable from any other unknown path, so
|
||||
// nothing advertises an administrative surface to someone probing for one.
|
||||
if (!opts.adminSecret) {
|
||||
await serveStatic(opts.distDir, url.pathname, res);
|
||||
return;
|
||||
}
|
||||
if (req.headers['x-admin-secret'] !== opts.adminSecret) {
|
||||
sendJson(res, 403, { error: 'bad or missing admin secret' });
|
||||
return;
|
||||
}
|
||||
|
||||
const codes = new Map((await readIndex(opts.dataDir)).map((e) => [e.gameId, e.gameCode]));
|
||||
|
||||
if (url.pathname === '/api/games' && req.method === 'GET') {
|
||||
const running = [...games.entries()].map(([gameId, g]) => ({
|
||||
gameId,
|
||||
gameCode: codes.get(gameId) ?? null,
|
||||
state: 'running' as const,
|
||||
...g.summary(),
|
||||
}));
|
||||
// A lobby has no game to summarize yet — it is reported as what it is, so an
|
||||
// administrator sees a table that never started rather than nothing at all.
|
||||
const waiting = [...lobbies.values()].map((l) => ({
|
||||
gameId: l.gameId,
|
||||
gameCode: l.gameCode,
|
||||
state: 'lobby' as const,
|
||||
playerCount: l.seats.length,
|
||||
playerNames: l.seats.map((seat) =>
|
||||
seat === null ? '(empty)' : seat.kind === 'bot' ? 'Bot' : seat.displayName,
|
||||
),
|
||||
createdAt: l.createdAt,
|
||||
}));
|
||||
sendJson(res, 200, { games: [...running, ...waiting] });
|
||||
return;
|
||||
}
|
||||
|
||||
const match = /^\/api\/games\/([^/]+)(\/save)?$/.exec(url.pathname);
|
||||
const gameId = match?.[1];
|
||||
if (!gameId) {
|
||||
sendJson(res, 404, { error: 'no such route' });
|
||||
return;
|
||||
}
|
||||
|
||||
if (match?.[2] && req.method === 'GET') {
|
||||
const session = games.get(gameId);
|
||||
if (!session) {
|
||||
sendJson(res, 404, { error: 'no such game' });
|
||||
return;
|
||||
}
|
||||
sendJson(res, 200, { gameCode: codes.get(gameId) ?? null, save: session.exportSave() });
|
||||
return;
|
||||
}
|
||||
|
||||
if (req.method === 'DELETE') {
|
||||
const session = games.get(gameId);
|
||||
const lobby = lobbies.get(gameId);
|
||||
if (!session && !lobby) {
|
||||
sendJson(res, 404, { error: 'no such game' });
|
||||
return;
|
||||
}
|
||||
// The save goes back with the deletion, so a game can never be destroyed without its
|
||||
// record being handed to whoever destroyed it — the intents ARE the game (D5), so this
|
||||
// is the whole thing, replayable later, not a summary of it.
|
||||
const save = session?.exportSave() ?? null;
|
||||
|
||||
// Everyone watching is told the game is gone before its files are, rather than being
|
||||
// left on a stream that will never push again.
|
||||
for (const [, watcher] of gameConnections.get(gameId) ?? []) watcher.end();
|
||||
gameConnections.delete(gameId);
|
||||
for (const [, watcher] of lobbyConnections.get(gameId) ?? []) watcher.end();
|
||||
lobbyConnections.delete(gameId);
|
||||
|
||||
games.delete(gameId);
|
||||
lobbies.delete(gameId);
|
||||
gameEventIds.delete(gameId);
|
||||
const code = lobby?.gameCode ?? codes.get(gameId);
|
||||
if (code) gameCodes.delete(code);
|
||||
for (const [token, ps] of [...sessions]) if (ps.gameId === gameId) sessions.delete(token);
|
||||
|
||||
await removeIndexEntry(opts.dataDir, gameId);
|
||||
await deleteGame(opts.dataDir, gameId);
|
||||
sendJson(res, 200, { ok: true, gameCode: code ?? null, save });
|
||||
return;
|
||||
}
|
||||
|
||||
sendJson(res, 405, { error: 'method not allowed' });
|
||||
return;
|
||||
}
|
||||
|
||||
// -- Lobby: creating and joining (the door — join-secret gated) --------------------------
|
||||
|
||||
if (url.pathname === '/api/lobby/create' && req.method === 'POST') {
|
||||
const body = (await readJson(req)) as { secret?: string; config?: GameConfig; displayName?: string };
|
||||
const body = (await readJson(req)) as {
|
||||
secret?: string;
|
||||
config?: GameConfig;
|
||||
displayName?: string;
|
||||
players?: number;
|
||||
};
|
||||
if (body.secret !== opts.joinSecret) {
|
||||
sendJson(res, 403, { error: 'bad or missing secret' });
|
||||
return;
|
||||
}
|
||||
if (!body.config || typeof body.displayName !== 'string' || body.displayName.trim() === '') {
|
||||
sendJson(res, 400, { error: 'expected { secret, config, displayName }' });
|
||||
sendJson(res, 400, { error: 'expected { secret, config, displayName, players }' });
|
||||
return;
|
||||
}
|
||||
// The table size is the host's to choose and is fixed from here on, so it is validated at
|
||||
// the door rather than at Start — `createLobby` builds the seats array from it.
|
||||
const players = body.players ?? 0;
|
||||
if (!Number.isInteger(players) || !playerCountAllowed(body.config.mode, players)) {
|
||||
sendJson(res, 400, { error: 'BAD_PLAYER_COUNT' });
|
||||
return;
|
||||
}
|
||||
const gameCode = freshGameCode((code) => gameCodes.has(code));
|
||||
const { lobby, session } = createLobby(body.config, body.displayName.trim(), gameCode);
|
||||
const { lobby, session } = createLobby(body.config, body.displayName.trim(), gameCode, players);
|
||||
await persistLobby(lobby);
|
||||
await persistSession(session);
|
||||
sendJson(res, 200, { gameId: lobby.gameId, gameCode: lobby.gameCode, token: session.token, player: session.player });
|
||||
|
||||
Reference in New Issue
Block a user