feat(anon): memorable, collision-proof animal anonymous names (#4611)

## Description:

Makes OpenFront's anonymised names **memorable and collision-proof**.

Anonymised lobbies (e.g. OFM tournaments) previously showed opaque names
— the `Anon420` fallback and hash-derived civ-tribe names in the overlay
— that were hard to remember and could repeat within a viewer's view, so
players couldn't reliably track opponents across a match.

**What changed**
- **`src/core/AnonAnimals.ts`** (new): an 80-word animal bank +
`anonAnimalName(slot, offset)`. Consecutive slots map to **distinct**
handles — the 80 animals fill first (`round 0` → a bare `AnonWolf`),
then a single round digit counts up (`AnonWolf1`, …). At a fixed offset,
two slots can never collide.
- **`GameServer.anonName`**: assigns each player its **join-order slot**
in `allClients` (stable — late-joiners append so existing names never
shift; reconnects reuse their slot) plus a **per-viewer offset**. So
within any one viewer's view no two players can share a name, while
different viewers still see different names for the same player
(**anti-team preserved**). Replaces the old per-pair hash and removes
the now-dead `anonymousUsername` helper.
- **Client fallback** (`genAnonUsername`): draws a random slot through
the same helper (no roster client-side → best-effort); the overlay is
what guarantees uniqueness in-game.
- `createRandomName` (nation/other display names) is untouched.

**Desync safety — audited against #4426**

#4426 fixed a desync where `PlayerExecution` seeded `removeClusters()`
from `player.name()`, a value anonymize-names makes per-client. This
change preserves that invariant:

| Check | Result |
|---|---|
| Deterministic state hash reads `name()`? | **No** — `PlayerImpl.hash =
simpleHash(id)·(troops+numTilesOwned) + Σ unit.hash`; `UnitImpl.hash =
tile + simpleHash(type)·id` |
| `removeClusters` seed | `simpleHash(player.id())` — id-based (#4426
fix), untouched |
| Where `anonName` is called | only `startInfoFor` / `gameInfo` —
per-viewer wire payloads, never the sim |
| Archived record | uses `wireGameStartInfo` (real names) — untouched →
replay/scoring unaffected |
| Net new sim inputs | none — only the display string + server-side
roster order |

The name is display-only and the simulation is name-blind, so this
cannot desync.

**Testing**
- New `tests/AnonAnimals.test.ts`: the no-collision guarantee (250
distinct slots → 250 distinct names), round roll-over, per-viewer
variation, wire-validity/length.
- Existing `tests/server/AnonymizeNames.test.ts` overlay suite still
passes.
- Full suite green locally (`npm test` + `npm run test:coverage`), plus
`build-prod`, `eslint`, and `prettier --check .` clean.

## Please complete the following:

- [x] I have added screenshots for all UI updates — _N/A, no UI changes
(in-game name string only)_
- [x] I process any text displayed to the user through translateText()
and I've added it to the en.json file — _N/A, generated handles are not
translatable identifiers_
- [x] I have added relevant tests to the test directory —
`tests/AnonAnimals.test.ts`

## Please put your Discord username so you can be contacted if a bug or
regression is found:

<!-- TODO: fill in Discord username -->
This commit is contained in:
Zixer1
2026-07-14 14:18:33 -07:00
committed by GitHub
parent 99e6b8ac50
commit 2422a1a7a0
6 changed files with 193 additions and 45 deletions
+104
View File
@@ -0,0 +1,104 @@
// Word bank for anonymous usernames (see genAnonUsername). Each entry is a
// single, memorable animal word that is username-safe on its own (matches
// UsernameSchema's [a-zA-Z0-9_ üÜ.] and, prefixed with "Anon" plus one digit,
// stays under MAX_USERNAME_LENGTH). Kept as recognisable animals with a matching
// emoji so a future cosmetic pass can pair each name with its animal badge.
// Order is irrelevant — genAnonUsername indexes into this by a random value.
export const ANON_ANIMALS: readonly string[] = [
"Wolf",
"Fox",
"Bear",
"Panda",
"Koala",
"Tiger",
"Lion",
"Leopard",
"Cheetah",
"Jaguar",
"Otter",
"Seal",
"Sloth",
"Raccoon",
"Badger",
"Skunk",
"Hedgehog",
"Squirrel",
"Hamster",
"Rabbit",
"Boar",
"Horse",
"Zebra",
"Deer",
"Moose",
"Bison",
"Ram",
"Goat",
"Camel",
"Llama",
"Giraffe",
"Elephant",
"Rhino",
"Hippo",
"Gorilla",
"Orangutan",
"Monkey",
"Kangaroo",
"Bat",
"Falcon",
"Eagle",
"Hawk",
"Owl",
"Raven",
"Swan",
"Goose",
"Duck",
"Chicken",
"Rooster",
"Penguin",
"Flamingo",
"Peacock",
"Parrot",
"Turkey",
"Dove",
"Shark",
"Whale",
"Dolphin",
"Orca",
"Octopus",
"Squid",
"Crab",
"Lobster",
"Shrimp",
"Pufferfish",
"Turtle",
"Crocodile",
"Snake",
"Cobra",
"Lizard",
"Gecko",
"Frog",
"Bee",
"Butterfly",
"Beetle",
"Ant",
"Spider",
"Scorpion",
"Snail",
"Ladybug",
];
// "Anon" + animal + optional round number, from a slot index and a per-viewer
// offset (e.g. "AnonWolf", "AnonFox", … then "AnonWolf1" once all 80 are used).
// Consecutive slots map to DISTINCT handles: the 80 animals fill first (round 0
// → a bare name), then the round counts up. So for a fixed offset, two different
// slots can never collide — that is what lets the anonymisation overlay
// guarantee unique names by feeding it join-order slots. The offset rotates
// which animal each slot lands on, so different viewers see a different name for
// the same player. Output is always wire-valid (letters + optional digits).
export function anonAnimalName(slot: number, offset = 0): string {
const s = Math.abs(Math.trunc(slot));
const o = Math.abs(Math.trunc(offset));
const animal = ANON_ANIMALS[(s + o) % ANON_ANIMALS.length];
const round = Math.floor(s / ANON_ANIMALS.length);
return round === 0 ? `Anon${animal}` : `Anon${animal}${round}`;
}
-12
View File
@@ -377,18 +377,6 @@ export function createRandomName(
return randomName;
}
// Deterministic anonymized username. Reuses createRandomName, then strips the
// emoji and any illegal chars so it passes UsernameSchema and survives the wire
// (createRandomName's output is a display string, not a valid username).
export function anonymousUsername(seed: string): string {
const base = createRandomName(seed, PlayerType.Human) ?? "";
const name = base
.replace(/[^a-zA-Z0-9_ üÜ.]/g, "")
.trim()
.slice(0, 27);
return name.length >= 3 ? name : "Player";
}
export const emojiTable = [
["😀", "😊", "🥰", "😇", "😎"],
["😞", "🥺", "😭", "😱", "😡"],