feat(client): verified-name toggle (play under your account name) (#4648)

## Summary

The client half of the verified-name plan: subscribers with a claimed
bare name can opt in to play under it, and the game renders a
**server-validated** blue verified check next to their name.

### Verified toggle (username row)
- Blue check-circle badge + "Verified" label act as a toggle button in
the play username row, shown to all users (hidden on CrazyGames via
`no-crazygames`); both turn blue when active and the input locks to the
bare account name — `getUsername()` feeds every join path.
- Non-subscribers (logged out, `unclaimed`, lapsed `claimed`) get a
subscribe-first dialog whose **View store** routes to
`#modal=store&tab=subscriptions`. Entitled players without a usable name
(never set, or `TEMPORARY####`) are routed to the account modal instead.
- The opt-in persists in localStorage but never auto-enables while
ineligible; unchecking restores the saved free-form name. Anonymity
stays a first-class option.
- After a successful username save the page reloads so every consumer
restarts from a fresh `/users/@me`.

### In-game badge (GL name pass)
- New `verified` boolean on `PlayerCosmeticRefsSchema` (client claim)
and `PlayerCosmeticsSchema` (resolved). `getPlayerCosmeticsRefs()` sets
it from the toggle state, covering both the multiplayer join and
locally-resolved singleplayer paths.
- **Server-validated at join, today**: the Worker already fetches
`/users/@me` with the client's token on every authenticated join
(flares/friends/clans), and that response carries the account username
since #4644 — so `verifiedBadgeAllowed` keeps the claim only when the
bare-name status is `premium`/`indefinite` AND the join name exactly
matches the account's resolved display name. Zero extra requests, no
token-claim staleness. Mismatches strip the badge rather than rejecting
the join; a pre-start rejoin identity change also drops it (that path
skips join-time validation). Anonymous persistent-ID joins exist only in
Dev and keep the claim for local testing.
- Rendering: 10th instanced slot in the name pass's `StatusIconProgram`,
anchored just right of the name text (`nameHalfWidth` was already in the
player data texture), slightly below the name line's center. The badge
art is a new cell (index 11) in `status-atlas.png`; the flag rides the
free `pd8.y` column. Anonymized viewers never see it (cosmetics are
already stripped for hidden players).

## Test plan

- Full suite passes (2,047 + 173), including new tests: cosmetics schema
`verified` (optional/boolean-only), `Privilege.isAllowed` pass-through,
and `verifiedBadgeAllowed` (exact match, case rejection, unentitled
statuses, missing name).
- Headless real-app verification of every toggle state (dialogs,
persistence, silent drops, store-tab routing, save→reload) with stubbed
API routes.
- Drove a real singleplayer game headless (WebGL via ANGLE Metal): the
blue check renders to the right of "Bob", scaled and tucked to the name;
bot/nation names show no badge. Screenshot-verified.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Evan
2026-07-20 08:28:21 -07:00
committed by GitHub
co-authored by Claude Fable 5
parent d9976babbd
commit ad8d7e995a
20 changed files with 508 additions and 80 deletions
+37 -4
View File
@@ -21,6 +21,7 @@ function makeClient(
role: string | null = null,
publicId: string | undefined = undefined,
friends: string[] = [],
cosmetics: { verified?: boolean } | undefined = undefined,
): Client {
return new Client(
clientID,
@@ -32,7 +33,7 @@ function makeClient(
username,
clanTag,
makeMockWs() as any,
undefined,
cosmetics,
publicId,
friends,
);
@@ -67,9 +68,17 @@ function makeGame(
[
makeClient("creator", "creator-pid", "CreatorReal", "HOST"),
makeClient("admin", "admin-pid", "AdminReal", "ADM", "admin"),
makeClient("alice", "alice-pid", "AliceReal", "AAA", null, "alice-pub", [
"bob-pub",
]),
makeClient(
"alice",
"alice-pid",
"AliceReal",
"AAA",
null,
"alice-pub",
["bob-pub"],
// Join-time validated cosmetics (enforceVerifiedBadge already ran).
{ verified: true },
),
makeClient("bob", "bob-pid", "BobReal", "BBB", null, "bob-pub"),
].forEach((c) => game.joinClient(c));
return game;
@@ -155,6 +164,30 @@ describe("anonymizeNames: gameInfo (lobby / HTTP / preview)", () => {
});
});
describe("verified badge in gameInfo", () => {
beforeEach(() => vi.useFakeTimers());
afterEach(() => {
vi.clearAllTimers();
vi.useRealTimers();
});
it("real entries carry verified from the join-validated cosmetics", () => {
const info = makeGame(false).gameInfo("bob");
expect(byId(info, "alice").verified).toBe(true);
expect(byId(info, "bob").verified).toBeUndefined();
});
it("anonymized entries never carry verified", () => {
const info = makeGame(true).gameInfo("bob");
expect(byId(info, "alice").verified).toBeUndefined();
});
it("the anonymized player still sees their own badge", () => {
const info = makeGame(true).gameInfo("alice");
expect(byId(info, "alice").verified).toBe(true);
});
});
describe("anonymizeNames: config updates propagate", () => {
beforeEach(() => vi.useFakeTimers());
afterEach(() => {