Commit Graph
2 Commits
Author SHA1 Message Date
Josh HarrisandGitHub 2ecdbdfe8d Steam desktop authentication support (SteamSDK, Auth branch, audience config, username seeding) (#4683)
> **Maintainer note:** part of the private OpenFront Steam release
(Milestone 2, tracked in Linear), not a public GitHub issue. Per the
contributor policy this needs an approved/assigned issue or a maintainer
label to avoid auto-close — flagging for a maintainer to handle.

Resolves: _n/a — private Steam-release work (see note above)_

## Description:

Adds the client-side pieces for authenticating the OpenFront **Steam
desktop build** (an Electron shell) against the existing API, mirroring
the established CrazyGames integration. The native Steamworks code lives
in the desktop shell and is exposed to this client through a
`window.openfrontDesktop.steam` bridge; this PR is the renderer half.

- **`SteamSDK.ts`** (new) — thin wrapper over the desktop shell's Steam
bridge (`isOnSteam` / `getTicket` / `getUser`), mirroring
`CrazyGamesSDK`; narrows the loosely-typed `window.openfrontDesktop`
locally rather than re-declaring it.
- **`Auth.ts`** — a Steam branch at the top of `doRefreshJwt()` plus
`doSteamLogin()`, exchanging a Steam Web-API ticket at `POST
/auth/steam` for a session JWT, exactly paralleling `doCrazyGamesLogin`.
Re-exchanges on expiry (the refresh cookie is cross-site-blocked from
the `app://` origin); no ticket / not on Steam falls through to the
existing flow.
- **`Api.ts`** — `getAudience()` now sources from `BOOTSTRAP_CONFIG`
(`ClientEnv.jwtAudience()`) instead of `window.location`, so the desktop
app (running at `app://openfront`) resolves the real API base.
Behavior-preserving on web, where the injected audience already equals
the hostname-derived one.
- **`UsernameInput.ts`** — seeds the in-game display name from the Steam
persona on first launch and persists it (unlike CrazyGames). Writes only
the local display name; never the account username.
- **`SteamLinkSignpost.ts`** (new) — a one-time, dismissible notice
shown on first Steam launch that account linking is coming.

## Please complete the following:

- [ ] I have added screenshots for all UI updates — ⚠️ _the new
first-launch link signpost is a UI addition; it renders only inside the
Steam desktop shell. Screenshots to be added by the maintainer._
- [x] I process any text displayed to the user through translateText()
and I've added it to the en.json file — signpost strings go through
`translateText()` with keys added to `resources/lang/en.json`
(`steam.link_signpost`, `common.got_it`).
- [x] I have added relevant tests to the test directory — unit tests for
`SteamSDK` (incl. bridge-throws degradation), the `Auth.ts` Steam
exchange + fall-through, the `Api.ts` audience change, username seeding,
and the signpost gating. Full suite green (1976) + `tsc --noEmit` clean.

## Please put your Discord username so you can be contacted if a bug or
regression is found:

_⚠️ maintainer to fill_

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01BWxUzYb2uqjcBFQuNSJhMy
2026-07-23 14:13:14 +01:00
Josh HarrisandGitHub ddc1abe146 Fix getApiBase() returning https://undefined when API_DOMAIN unset (#4685)
Resolves #4684

## Description:

Fixes `getApiBase()` returning `https://undefined` on `localhost` when
`API_DOMAIN` is unset (a plain `npm run dev`).

- `src/client/Api.ts`: use the exact `process.env.API_DOMAIN` form so
Vite's `define` replaces it (the previous `process?.env?.API_DOMAIN`
optional-chaining form wasn't matched, leaving the literal string
`"undefined"`).
- `vite.config.ts`: `JSON.stringify(env.API_DOMAIN ?? "")` so an unset
value becomes a falsy empty string instead of the truthy string
`"undefined"`.

Net: an unset `API_DOMAIN` now falls back to `http://localhost:8787` as
intended.

## Please complete the following:

- [x] I have added screenshots for all UI updates — _no UI changes_
- [x] I process any text displayed to the user through translateText()
and I've added it to the en.json file — _no user-facing text_
- [x] I have added relevant tests to the test directory — new
`tests/Api.test.ts` reproduces `https://undefined` (RED) and asserts the
`http://localhost:8787` fallback (GREEN); full suite green (2149 tests)

## Please put your Discord username so you can be contacted if a bug or
regression is found:

_⚠️ maintainer to fill_

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01BWxUzYb2uqjcBFQuNSJhMy
2026-07-23 12:58:37 +01:00