feat: subscriber-hosted public lobby listing (#4480)

Part of #4040 (v1 scope: listing + browser + per-subscriber limit;
custom lobby name/description left for a follow-up).

## What

Subscribers can toggle their **private lobby** to be **publicly
listed**; a browsable **"Open Lobbies"** list appears in the Join Lobby
modal. Hard limit of **one listed lobby per subscriber**, enforced
cluster-wide.

## How

**Semantics** — a listed lobby stays `GameType.Private`: the host keeps
full control and starts the game manually; the toggle only controls
visibility. The `listed` flag lives on `GameServer` (not `GameConfig`),
so it cannot be smuggled in through `update_game_config` and never
touches core/sim/records.

**Distribution** — reuses the existing public-lobby pipeline end to end:
a new `"hosted"` `PublicGameType` bucket flows worker → master IPC →
`/lobbies` websocket → `PublicLobbySocket`. Master scheduling now
iterates only `SCHEDULED_PUBLIC_GAME_TYPES` (`ffa`/`team`/`special`), so
it never sets countdowns on or schedules replacements for hosted
lobbies. Lobbies delist automatically when the game starts/fills/dies
(phase change). The broadcast fingerprint now includes browser-visible
config, so host edits (map/mode) refresh the list even though the gameID
doesn't change.

**Gating** — new authenticated endpoint `POST /api/game/:id/listing`:
- creator-only (403), private + not-started only (409)
- fresh subscription check via server-side `getUserMe` using the shared
`hasActiveSubscription()` helper (`active`/`trialing`); skipped in
`GameEnv.Dev` (same precedent as Turnstile) so it's testable locally
- one-lobby-per-creator (409): a SHA-256 hash of the creator's
persistentID rides worker↔master IPC (`PublicGameInfo.creatorID`); the
master dedupes as a race backstop. The hash — and host-only config
(whitelist, name reveals) — are **stripped from every client payload**
(broadcast + primed snapshot).

**Client** — subscriber-gated "List lobby publicly" toggle in the host
modal (server rejection reverts the toggle and shows a translated
message); "Open Lobbies" rows (map, mode, player count) in the Join
Lobby modal that reuse the existing private-join flow.

**Compat** — `PublicGames.games` is now a `partialRecord`, so newer
clients tolerate servers that don't send every bucket. Note:
already-open old clients will fail to parse broadcasts containing the
new `hosted` key until refreshed (closed Zod enum) — same class of break
as previous wire-schema changes.

## Testing

- `tests/server/HostedLobbyListing.test.ts` (15 tests): listed-lobby
filtering, flag not settable via config intent, master aggregation +
creator dedupe + no scheduling of hosted, creatorID stripping (broadcast
+ primed snapshot), `creatorHasListedLobby` (broadcast + local),
fingerprint refresh on config change
- `hasActiveSubscription` cases in `ApiSchemas.test.ts`; hosted
counts-delta patch in `LobbySocket.test.ts`
- Full suite green (1723 + 141 tests), tsc/eslint/prettier clean
- **E2E in the real app** (headless Chromium, two browser contexts):
host lists lobby → appears in second browser's Join Lobby list
(creatorID absent from payload) → join succeeds (2 players in lobby) →
same creator's second lobby rejected 409 with toggle revert → unlist
removes it from a fresh browser's list. Curl negatives: missing auth
400, bad token 401, non-creator 403, missing game 404, bad body 400.

## Known follow-ups

- Custom lobby name/description in the browser (needs the censor
pipeline) — rest of #4040
- A listed lobby whose host closes the tab stays advertised indefinitely
(an empty private lobby never leaves the Lobby phase) — pre-existing
lifecycle, now more visible; consider delisting on creator disconnect

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Evan
2026-07-05 20:25:56 -07:00
committed by GitHub
co-authored by Claude Fable 5
parent 22c873cf55
commit 5d21be826d
18 changed files with 1777 additions and 150 deletions
+90
View File
@@ -7,10 +7,12 @@ import path from "path";
import { fileURLToPath } from "url";
import { WebSocket, WebSocketServer } from "ws";
import { z } from "zod";
import { hasActiveSubscription } from "../core/ApiSchemas";
import { GameEnv } from "../core/configuration/Config";
import { GameType } from "../core/game/Game";
import {
ClientMessageSchema,
MAX_HOSTED_LOBBIES,
PartialGameRecordSchema,
ServerErrorMessage,
} from "../core/Schemas";
@@ -195,6 +197,94 @@ export async function startWorker() {
});
});
// Toggle whether a private lobby is visible in the public lobby browser.
// Creator-only; listing requires an active subscription (checked fresh
// against the API) and is limited to one listed lobby per creator.
app.post("/api/game/:id/listing", async (req, res) => {
const authHeader = req.headers.authorization;
if (!authHeader?.startsWith("Bearer ")) {
return res.status(400).json({ error: "Authorization header required" });
}
const token = authHeader.substring("Bearer ".length);
const auth = await verifyClientToken(token);
if (auth.type !== "success") {
return res.status(401).json({ error: "Invalid token" });
}
const parsed = z.object({ listed: z.boolean() }).safeParse(req.body);
if (!parsed.success) {
return res.status(400).json({ error: z.prettifyError(parsed.error) });
}
const { listed } = parsed.data;
const game = gm.game(req.params.id);
if (game === null) {
return res.status(404).json({ error: "Game not found" });
}
if (!game.isCreator(auth.persistentId)) {
return res
.status(403)
.json({ error: "Only the lobby creator can change its listing" });
}
if (game.isPublic() || game.hasStarted()) {
return res.status(409).json({ error: "Game cannot be listed" });
}
if (listed) {
// A whitelisted lobby would be advertised to everyone yet reject every
// joiner; the whitelist itself is stripped from the broadcast, so
// browsers could not even tell why.
if (game.hasJoinWhitelist()) {
return res.status(409).json({ error: "listing_whitelist_enabled" });
}
// Host cheats give the host an asymmetric advantage over players
// recruited from the lobby browser. Enabling them while listed is
// likewise rejected (GameServer's update_game_config handling).
if (game.hasHostCheats()) {
return res.status(409).json({ error: "listing_host_cheats_enabled" });
}
// Dev has no subscription backend; skip the check so the feature is
// testable locally (same precedent as Turnstile).
if (ServerEnv.env() !== GameEnv.Dev) {
const userMe = await getUserMe(token);
if (userMe.type === "error") {
log.warn(
`listing rejected, user me fetch failed: ${userMe.message}`,
{
gameID: req.params.id,
},
);
return res.status(403).json({ error: "subscription_required" });
}
if (!hasActiveSubscription(userMe.response)) {
return res.status(403).json({ error: "subscription_required" });
}
}
const creatorID = game.hashedCreatorID();
if (
creatorID !== undefined &&
lobbyService.creatorHasListedLobby(creatorID, game.id)
) {
return res.status(409).json({ error: "listing_limit_reached" });
}
// Cluster-wide cap to prevent listing spam. Approximate here (the
// broadcast lags by ~1s); the master's cap is the backstop.
if (lobbyService.hostedLobbyCount() >= MAX_HOSTED_LOBBIES) {
return res.status(409).json({ error: "listing_full" });
}
}
game.setListed(listed);
log.info(`lobby listing ${listed ? "enabled" : "disabled"}`, {
gameID: game.id,
});
res.json({ listed });
});
app.get("/api/game/:id/exists", async (req, res) => {
const lobbyId = req.params.id;
res.json({