v0.5.5 — a remembered session for a game that no longer exists

Reported after updating to v0.5.4: clicking Multiplayer went straight into
a game with no lobby and no controls, and the board was blank.

Three things lined up. start() enters a remembered session WITHOUT checking
it still exists — that is what makes reconnection seamless, and it is why
the lobby was skipped. The v0.5.4 update had refused to resume that game,
its save being recorded under v0.5.3 and the engine-version check being
exact (D7). And createRemoteSession had no onerror at all, so EventSource
retried the resulting 404 forever in silence while frame stayed null and
nothing rendered. The only escape was clearing site data, and nothing on
screen said so.

v0.5.3's Manage Game -> End had just widened the same dead end: it closes
every watcher's stream, so a player whose game an administrator ended would
sit frozen on a stale board indefinitely, for exactly the same reason.

GET /api/session?token= is new: a cheap yes/no on whether a token still
names a live game. EventSource fires error identically for a transient blip
— the expected shape of a game idle for minutes (§9) — and for a 404 it
will retry forever, and exposes no status code either way, so the client
asks rather than guessing. Only a definite 404 closes the stream and
reports the game gone; a flaky network still self-heals.

The page then forgets the stored session, says why (ended by an
administrator, or the service was updated, which does not carry games
across), and drops into the lobby. Forgetting the token is what stops the
next load repeating it. It also stops rendering nothing while it waits —
"… connecting to the game" sits in the presence banner until the first push
arrives, because a page showing nothing is indistinguishable from a broken
one, which is what this looked like.

Recorded but NOT fixed, in TODO.md: three releases in a row destroyed every
game in progress, and v0.5.4's changes were rendering only. The refusal is
right, but the test is exact equality against the PACKAGE version, which
moves for reasons unrelated to the rules. Three options costed; the
recommendation is to replay the save and refuse only if an intent actually
rejects — the real question rather than a proxy for it, and a full replay
measures ~100 ms.

Verified live: /api/session answers 200 for a seated token, 404 once an
administrator ends the game, 404 for a garbage token, and /api/stream 404s
in the same state — which is the response EventSource had been retrying
silently. 673 tests pass.
This commit is contained in:
Jesse
2026-08-21 17:55:59 -04:00
parent 689de2ff0f
commit bfd2708ecc
6 changed files with 178 additions and 3 deletions
+21
View File
@@ -481,6 +481,27 @@ export function startServer(opts: ServerOptions): void {
// -- The running game (token-authenticated) ------------------------------------------------
/**
* IS THIS TOKEN STILL GOOD FOR ANYTHING?
*
* A browser remembers its session in `localStorage` and re-enters the game on the next load
* without asking, which is what makes reconnection seamless — and what leaves it stranded
* when the game is gone. `EventSource` cannot report a status code and retries a 404
* silently forever, so the client needs somewhere cheap to ask a yes/no question. Two ways a
* game legitimately disappears under a player: an engine-version bump refuses to resume it
* (D7), and an administrator ends it (`DELETE /api/games/<id>`).
*/
if (url.pathname === '/api/session' && req.method === 'GET') {
const ps = sessions.get(url.searchParams.get('token') ?? '');
const live = ps ? games.get(ps.gameId) : undefined;
if (!ps || !live) {
sendJson(res, 404, { error: 'no such game' });
return;
}
sendJson(res, 200, { gameId: ps.gameId, player: ps.player });
return;
}
if (url.pathname === '/api/stream' && req.method === 'GET') {
const token = url.searchParams.get('token') ?? '';
const ps = sessions.get(token);