mirror of
https://github.com/openfrontio/OpenFrontIO.git
synced 2026-07-23 03:42:42 +00:00
feat(client): verified-name toggle (play under your account name) (#4648)
## Summary The client half of the verified-name plan: subscribers with a claimed bare name can opt in to play under it, and the game renders a **server-validated** blue verified check next to their name. ### Verified toggle (username row) - Blue check-circle badge + "Verified" label act as a toggle button in the play username row, shown to all users (hidden on CrazyGames via `no-crazygames`); both turn blue when active and the input locks to the bare account name — `getUsername()` feeds every join path. - Non-subscribers (logged out, `unclaimed`, lapsed `claimed`) get a subscribe-first dialog whose **View store** routes to `#modal=store&tab=subscriptions`. Entitled players without a usable name (never set, or `TEMPORARY####`) are routed to the account modal instead. - The opt-in persists in localStorage but never auto-enables while ineligible; unchecking restores the saved free-form name. Anonymity stays a first-class option. - After a successful username save the page reloads so every consumer restarts from a fresh `/users/@me`. ### In-game badge (GL name pass) - New `verified` boolean on `PlayerCosmeticRefsSchema` (client claim) and `PlayerCosmeticsSchema` (resolved). `getPlayerCosmeticsRefs()` sets it from the toggle state, covering both the multiplayer join and locally-resolved singleplayer paths. - **Server-validated at join, today**: the Worker already fetches `/users/@me` with the client's token on every authenticated join (flares/friends/clans), and that response carries the account username since #4644 — so `verifiedBadgeAllowed` keeps the claim only when the bare-name status is `premium`/`indefinite` AND the join name exactly matches the account's resolved display name. Zero extra requests, no token-claim staleness. Mismatches strip the badge rather than rejecting the join; a pre-start rejoin identity change also drops it (that path skips join-time validation). Anonymous persistent-ID joins exist only in Dev and keep the claim for local testing. - Rendering: 10th instanced slot in the name pass's `StatusIconProgram`, anchored just right of the name text (`nameHalfWidth` was already in the player data texture), slightly below the name line's center. The badge art is a new cell (index 11) in `status-atlas.png`; the flag rides the free `pd8.y` column. Anonymized viewers never see it (cosmetics are already stripped for hidden players). ## Test plan - Full suite passes (2,047 + 173), including new tests: cosmetics schema `verified` (optional/boolean-only), `Privilege.isAllowed` pass-through, and `verifiedBadgeAllowed` (exact match, case rejection, unentitled statuses, missing name). - Headless real-app verification of every toggle state (dialogs, persistence, silent drops, store-tab routing, save→reload) with stubbed API routes. - Drove a real singleplayer game headless (WebGL via ANGLE Metal): the blue check renders to the right of "Bob", scaled and tucked to the name; bot/nation names show no badge. Screenshot-verified. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -13,7 +13,11 @@ import {
|
||||
SubscriptionSchema,
|
||||
TrailEffectAttributesSchema,
|
||||
} from "../src/core/CosmeticSchemas";
|
||||
import { PlayerEffectSchema } from "../src/core/Schemas";
|
||||
import {
|
||||
PlayerCosmeticRefsSchema,
|
||||
PlayerCosmeticsSchema,
|
||||
PlayerEffectSchema,
|
||||
} from "../src/core/Schemas";
|
||||
|
||||
describe("Effect cosmetic schemas", () => {
|
||||
const base = {
|
||||
@@ -964,3 +968,35 @@ describe("SubscriptionSchema canCreatePublicLobbies", () => {
|
||||
).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe("verified badge on cosmetics schemas", () => {
|
||||
it("accepts a verified claim on refs and resolved cosmetics", () => {
|
||||
const refs = PlayerCosmeticRefsSchema.safeParse({ verified: true });
|
||||
expect(refs.success).toBe(true);
|
||||
if (refs.success) {
|
||||
expect(refs.data.verified).toBe(true);
|
||||
}
|
||||
const resolved = PlayerCosmeticsSchema.safeParse({ verified: true });
|
||||
expect(resolved.success).toBe(true);
|
||||
if (resolved.success) {
|
||||
expect(resolved.data.verified).toBe(true);
|
||||
}
|
||||
});
|
||||
|
||||
it("stays optional (old clients omit it)", () => {
|
||||
const refs = PlayerCosmeticRefsSchema.safeParse({});
|
||||
expect(refs.success).toBe(true);
|
||||
if (refs.success) {
|
||||
expect(refs.data.verified).toBeUndefined();
|
||||
}
|
||||
});
|
||||
|
||||
it("rejects a non-boolean verified", () => {
|
||||
expect(
|
||||
PlayerCosmeticRefsSchema.safeParse({ verified: "yes" }).success,
|
||||
).toBe(false);
|
||||
expect(PlayerCosmeticsSchema.safeParse({ verified: 1 }).success).toBe(
|
||||
false,
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
import {
|
||||
createMatcher,
|
||||
enforceVerifiedBadge,
|
||||
FailOpenPrivilegeChecker,
|
||||
PrivilegeCheckerImpl,
|
||||
shadowNames,
|
||||
@@ -496,6 +497,104 @@ describe("Flag validation in isAllowed", () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe("Verified badge in isAllowed", () => {
|
||||
test("passes through a verified claim", () => {
|
||||
const result = flagChecker.isAllowed([], { verified: true });
|
||||
expect(result.type).toBe("allowed");
|
||||
if (result.type === "allowed") {
|
||||
expect(result.cosmetics.verified).toBe(true);
|
||||
}
|
||||
});
|
||||
|
||||
test("stays unset when absent or false", () => {
|
||||
for (const refs of [{}, { verified: false }]) {
|
||||
const result = flagChecker.isAllowed([], refs);
|
||||
expect(result.type).toBe("allowed");
|
||||
if (result.type === "allowed") {
|
||||
expect(result.cosmetics.verified).toBeUndefined();
|
||||
}
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe("enforceVerifiedBadge", () => {
|
||||
test("keeps the badge for an entitled player joining under their exact bare name", () => {
|
||||
for (const usernameStatus of ["premium", "indefinite"]) {
|
||||
const cosmetics = { verified: true };
|
||||
expect(
|
||||
enforceVerifiedBadge(cosmetics, "Bob", {
|
||||
username: "Bob",
|
||||
usernameStatus,
|
||||
}),
|
||||
).toBe(false);
|
||||
expect(cosmetics.verified).toBe(true);
|
||||
}
|
||||
});
|
||||
|
||||
test("strips on a case-different join name (exact match only)", () => {
|
||||
const cosmetics = { verified: true };
|
||||
expect(
|
||||
enforceVerifiedBadge(cosmetics, "bob", {
|
||||
username: "Bob",
|
||||
usernameStatus: "premium",
|
||||
}),
|
||||
).toBe(true);
|
||||
expect(cosmetics.verified).toBeUndefined();
|
||||
});
|
||||
|
||||
test("strips on a different name entirely", () => {
|
||||
const cosmetics = { verified: true };
|
||||
expect(
|
||||
enforceVerifiedBadge(cosmetics, "Alice", {
|
||||
username: "Bob",
|
||||
usernameStatus: "premium",
|
||||
}),
|
||||
).toBe(true);
|
||||
expect(cosmetics.verified).toBeUndefined();
|
||||
});
|
||||
|
||||
test("strips unentitled statuses even on an exact match", () => {
|
||||
for (const usernameStatus of ["unclaimed", "claimed", undefined]) {
|
||||
const cosmetics = { verified: true };
|
||||
expect(
|
||||
enforceVerifiedBadge(cosmetics, "Bob.4821", {
|
||||
username: "Bob.4821",
|
||||
usernameStatus,
|
||||
}),
|
||||
).toBe(true);
|
||||
expect(cosmetics.verified).toBeUndefined();
|
||||
}
|
||||
});
|
||||
|
||||
test("strips when the account has no username set", () => {
|
||||
for (const account of [
|
||||
{ username: null, usernameStatus: "premium" },
|
||||
{ usernameStatus: "premium" },
|
||||
]) {
|
||||
const cosmetics = { verified: true };
|
||||
expect(enforceVerifiedBadge(cosmetics, "Bob", account)).toBe(true);
|
||||
expect(cosmetics.verified).toBeUndefined();
|
||||
}
|
||||
});
|
||||
|
||||
test("keeps the badge on an anonymous join (null account, Dev-only)", () => {
|
||||
const cosmetics = { verified: true };
|
||||
expect(enforceVerifiedBadge(cosmetics, "Whatever", null)).toBe(false);
|
||||
expect(cosmetics.verified).toBe(true);
|
||||
});
|
||||
|
||||
test("no-op without a claim", () => {
|
||||
for (const cosmetics of [{}, { verified: false }]) {
|
||||
expect(
|
||||
enforceVerifiedBadge(cosmetics, "Bob", {
|
||||
username: "Other",
|
||||
usernameStatus: "unclaimed",
|
||||
}),
|
||||
).toBe(false);
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe("Skin validation", () => {
|
||||
describe("isSkinAllowed (direct)", () => {
|
||||
test("returns skin when user has wildcard flare", () => {
|
||||
|
||||
@@ -21,6 +21,7 @@ function makeClient(
|
||||
role: string | null = null,
|
||||
publicId: string | undefined = undefined,
|
||||
friends: string[] = [],
|
||||
cosmetics: { verified?: boolean } | undefined = undefined,
|
||||
): Client {
|
||||
return new Client(
|
||||
clientID,
|
||||
@@ -32,7 +33,7 @@ function makeClient(
|
||||
username,
|
||||
clanTag,
|
||||
makeMockWs() as any,
|
||||
undefined,
|
||||
cosmetics,
|
||||
publicId,
|
||||
friends,
|
||||
);
|
||||
@@ -67,9 +68,17 @@ function makeGame(
|
||||
[
|
||||
makeClient("creator", "creator-pid", "CreatorReal", "HOST"),
|
||||
makeClient("admin", "admin-pid", "AdminReal", "ADM", "admin"),
|
||||
makeClient("alice", "alice-pid", "AliceReal", "AAA", null, "alice-pub", [
|
||||
"bob-pub",
|
||||
]),
|
||||
makeClient(
|
||||
"alice",
|
||||
"alice-pid",
|
||||
"AliceReal",
|
||||
"AAA",
|
||||
null,
|
||||
"alice-pub",
|
||||
["bob-pub"],
|
||||
// Join-time validated cosmetics (enforceVerifiedBadge already ran).
|
||||
{ verified: true },
|
||||
),
|
||||
makeClient("bob", "bob-pid", "BobReal", "BBB", null, "bob-pub"),
|
||||
].forEach((c) => game.joinClient(c));
|
||||
return game;
|
||||
@@ -155,6 +164,30 @@ describe("anonymizeNames: gameInfo (lobby / HTTP / preview)", () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe("verified badge in gameInfo", () => {
|
||||
beforeEach(() => vi.useFakeTimers());
|
||||
afterEach(() => {
|
||||
vi.clearAllTimers();
|
||||
vi.useRealTimers();
|
||||
});
|
||||
|
||||
it("real entries carry verified from the join-validated cosmetics", () => {
|
||||
const info = makeGame(false).gameInfo("bob");
|
||||
expect(byId(info, "alice").verified).toBe(true);
|
||||
expect(byId(info, "bob").verified).toBeUndefined();
|
||||
});
|
||||
|
||||
it("anonymized entries never carry verified", () => {
|
||||
const info = makeGame(true).gameInfo("bob");
|
||||
expect(byId(info, "alice").verified).toBeUndefined();
|
||||
});
|
||||
|
||||
it("the anonymized player still sees their own badge", () => {
|
||||
const info = makeGame(true).gameInfo("alice");
|
||||
expect(byId(info, "alice").verified).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
describe("anonymizeNames: config updates propagate", () => {
|
||||
beforeEach(() => vi.useFakeTimers());
|
||||
afterEach(() => {
|
||||
|
||||
Reference in New Issue
Block a user