Skip to content

feat(publisher): advertise access-token admission with Game v2 - #95

Open
zoeyrose wants to merge 3 commits into
mainfrom
feat/access-tokens
Open

zoeyrose wants to merge 3 commits into
mainfrom
feat/access-tokens

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Summary

Replace the replacement server's shared-password publication flag with access-token admission metadata using the protocol-owned Game publisher v2 contract. Public visibility remains independent of whether admission requires a code.

Implementation / behavior

  • Consume the generated metaserver/v2 types and v2 signed publisher helpers; emit accessRequired through /v2/servers/{serverId}/publish with no v1 fallback.
  • Replace -password-required with -access-required and preserve admission-only changes in publication scheduling.
  • Default current publication to GP1 1.1 and reject unsupported minor versions before reserving a sequence or contacting the network.
  • Preserve exact DER-leaf certificate identity and durable publication sequence state. Test the distinction from QUIC's SPKI fingerprint and reject implicit same-key certificate identity reuse.
  • Record the exact MIT protocol fixture provenance and document the M1 foundation boundary.

Validation

tools/validate.sh passed for server 4f0234c3a9d0b2a62f75b74c3856310e25c57438 in the pinned Linux build image with Go 1.26.6 using the normal public Go proxy and checksum database. No private modfile, module replacement or private proxy was used. This includes all tests, race detection, static analysis, bounded fuzz/benchmark checks, vulnerability/dependency-license checks, Git LFS attribute checks, Linux/Windows package builds and package reproducibility.

Independent review approved the complete source and the final dependency-only change. Focused tests cover all four visibility/admission combinations, obsolete flags and fields, policy-only republishing, protocol-minor rejection and certificate identity binding. Native Linux and Windows CI passed on this exact head, including the required Server validation aggregate and Conventional PR title check.

Limitations / follow-up

The protocol dependency is now pinned to the published source behind protocol v2.6.0: commit 58ed75f13fab6a405160fac617c54e990b067e8b, resolved by normal Go tooling as v1.5.6-0.20261004163427-58ed75f13fab. The pseudo-version is necessary because the Go module path remains github.com/atrinik/protocol without a /v2 suffix. Its public checksum record is committed in go.sum; the release/pin blocker is resolved.

The M1 replacement server has no gameplay listener, token administration/store, account authentication or private rendezvous consumer. This change implements its actual publisher/configuration boundary and does not claim gameplay token lifecycle acceptance. No production deployment or live service change is included.

@zoeyrose
zoeyrose marked this pull request as ready for review October 4, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant