feat(anon): memorable, collision-proof animal anonymous names (#4611)

## Description:

Makes OpenFront's anonymised names **memorable and collision-proof**.

Anonymised lobbies (e.g. OFM tournaments) previously showed opaque names
— the `Anon420` fallback and hash-derived civ-tribe names in the overlay
— that were hard to remember and could repeat within a viewer's view, so
players couldn't reliably track opponents across a match.

**What changed**
- **`src/core/AnonAnimals.ts`** (new): an 80-word animal bank +
`anonAnimalName(slot, offset)`. Consecutive slots map to **distinct**
handles — the 80 animals fill first (`round 0` → a bare `AnonWolf`),
then a single round digit counts up (`AnonWolf1`, …). At a fixed offset,
two slots can never collide.
- **`GameServer.anonName`**: assigns each player its **join-order slot**
in `allClients` (stable — late-joiners append so existing names never
shift; reconnects reuse their slot) plus a **per-viewer offset**. So
within any one viewer's view no two players can share a name, while
different viewers still see different names for the same player
(**anti-team preserved**). Replaces the old per-pair hash and removes
the now-dead `anonymousUsername` helper.
- **Client fallback** (`genAnonUsername`): draws a random slot through
the same helper (no roster client-side → best-effort); the overlay is
what guarantees uniqueness in-game.
- `createRandomName` (nation/other display names) is untouched.

**Desync safety — audited against #4426**

#4426 fixed a desync where `PlayerExecution` seeded `removeClusters()`
from `player.name()`, a value anonymize-names makes per-client. This
change preserves that invariant:

| Check | Result |
|---|---|
| Deterministic state hash reads `name()`? | **No** — `PlayerImpl.hash =
simpleHash(id)·(troops+numTilesOwned) + Σ unit.hash`; `UnitImpl.hash =
tile + simpleHash(type)·id` |
| `removeClusters` seed | `simpleHash(player.id())` — id-based (#4426
fix), untouched |
| Where `anonName` is called | only `startInfoFor` / `gameInfo` —
per-viewer wire payloads, never the sim |
| Archived record | uses `wireGameStartInfo` (real names) — untouched →
replay/scoring unaffected |
| Net new sim inputs | none — only the display string + server-side
roster order |

The name is display-only and the simulation is name-blind, so this
cannot desync.

**Testing**
- New `tests/AnonAnimals.test.ts`: the no-collision guarantee (250
distinct slots → 250 distinct names), round roll-over, per-viewer
variation, wire-validity/length.
- Existing `tests/server/AnonymizeNames.test.ts` overlay suite still
passes.
- Full suite green locally (`npm test` + `npm run test:coverage`), plus
`build-prod`, `eslint`, and `prettier --check .` clean.

## Please complete the following:

- [x] I have added screenshots for all UI updates — _N/A, no UI changes
(in-game name string only)_
- [x] I process any text displayed to the user through translateText()
and I've added it to the en.json file — _N/A, generated handles are not
translatable identifiers_
- [x] I have added relevant tests to the test directory —
`tests/AnonAnimals.test.ts`

## Please put your Discord username so you can be contacted if a bug or
regression is found:

<!-- TODO: fill in Discord username -->
This commit is contained in:
Zixer1
2026-07-14 14:18:33 -07:00
committed by GitHub
parent 99e6b8ac50
commit 2422a1a7a0
6 changed files with 193 additions and 45 deletions
+21 -6
View File
@@ -1,6 +1,7 @@
import { LitElement, html } from "lit";
import { customElement, property, state } from "lit/decorators.js";
import { generateCryptoRandomUUID, translateText } from "../client/Utils";
import { translateText } from "../client/Utils";
import { ANON_ANIMALS, anonAnimalName } from "../core/AnonAnimals";
import { sanitizeClanTag } from "../core/Util";
import {
MAX_CLAN_TAG_LENGTH,
@@ -318,10 +319,24 @@ export class UsernameInput extends LitElement {
}
}
// A memorable anonymous username: "Anon" + animal (+ digit), the same handle
// format the server-side anonymisation overlay uses (anonAnimalName). Client-side
// fallback for players who never set a name — no roster here, so it draws a
// random slot (best-effort-unique); the overlay is what guarantees uniqueness
// in-game.
//
// Rejection-sample a uniform slot in [0, bound) from the CSPRNG: drawing a raw
// uint32 and taking `% bound` would be very slightly biased (the top partial
// bucket), so we discard the unrepresentable tail first. The bias is cosmetically
// irrelevant here, but this keeps the draw provably uniform.
export function genAnonUsername(): string {
const uuid = generateCryptoRandomUUID();
const cleanUuid = uuid.replace(/-/g, "").toLowerCase();
const decimal = BigInt(`0x${cleanUuid}`);
const threeDigits = decimal % 1000n;
return "Anon" + threeDigits.toString().padStart(3, "0");
const bound = ANON_ANIMALS.length * 10;
const limit = Math.floor(0x1_0000_0000 / bound) * bound;
const buf = new Uint32Array(1);
let rand: number;
do {
crypto.getRandomValues(buf);
rand = buf[0] ?? 0;
} while (rand >= limit);
return anonAnimalName(rand % bound);
}