Adds the player-facing half of game account management: a panel on
/community/servers/[id] that shows your linked account for that server,
creates one, and changes its password.
None of these emulators speak OIDC and none will - each ships its own
login against its own auth database. So this is a bridge, not SSO: one
Drop identity tied to one native account per server, enforced by a unique
index on (userId, serverSlug). That constraint IS the feature.
Drop owns identity, authorization, the link table and the UI. The
per-game DB access and password crypto stay in mmo-portal's provider API
(SRP6 verifiers, EQEmu hashing) - code that writes into live auth DBs and
fails silently when subtly wrong.
The password never touches Drop's database; it goes straight through to
the provider, which turns it into whatever that emulator wants.
Notable details:
- GameServer.slug names the game, provider.key names the emulator. They
agree for eqemu and daoc but wow != trinitycore, so the mapping is an
explicit three-entry constant, not an assumption.
- Panel renders NOTHING when a server has no account backend (Impostor is
a lobby with no identity), rather than a dead button.
- 'backend unreachable' is kept distinct from 'you have no account' - the
latter would invite a duplicate during an outage.
- Provision creates in the game first, then links. The reverse would
leave a link pointing at a nonexistent account, which reads as
corruption to every later call.
- Authorization is just an authenticated Drop session with the ACL: Drop
access and game access already imply each other, so a third gate could
only disagree with them.
Typecheck clean.
- Resolve gameServerRegistry.json's null deep_link entries against the
live drop-db catalog (WoW, EverQuest, Among Us match real Game rows;
OpenDAoC and the Goldberg relay genuinely have none, left null and
documented why).
- Fix the "0 online now" panel bug: the community landing page's
persistent-world quick-strip was inferring presence from PlaySession
name-matching (presenceService.getServerPresence), which hardcodes
available=true even with zero matches -- always showing a fake "0"
for EQEmu instead of the honest unavailable state. Switched it to the
same probe-backed GameServer feed ServerStatusPanel already uses
(joined by the shared wow/eqemu/daoc slug), so known-zero and
count-unavailable never render the same.
- Header people icon now opens a friends flyout (list, incoming
requests with accept/decline, entry into chat with a friend) instead
of going nowhere, mirroring the existing notifications bell's
Menu/MenuButton/MenuItems pattern; badge shows pending request count.
Mobile sidebar links it straight to /community/friends.
- Community gets a hover submenu in the main nav (desktop) / inline
sublist (mobile) listing Friends, Chat, Devices, Mods, Servers,
Issues, Achievements.
- User dropdown menu gets a "Your profile" entry resolved from the
signed-in user's own username (/community/profile/<username>), not
hardcoded.
getFriendsActivity's declared return type omitted presenceAvailable
entirely (both the early-return-on-no-friends branch and the type
annotation), and community/index.vue's local FriendActivityEntry.playing
was typed {gameId, name} when presenceService.ts's actual FriendPlaying
shape is {platform, id, name} -- the template only ever reads `.name`, so
only the type needed to change. This was breaking `nuxt build`'s typecheck
step on plain `develop` (confirmed via a clean checkout before any M4 code
was involved), which meant nothing downstream of M3's chat/presence
landing could build. Fixed forward rather than reverting anything.
GameServer/GameServerStatusHistory/Issue/IssueComment models, a
strategy-per-probe_type ServerProbe (tcp_connect/http_get/presence_inferred,
mirroring script-library's game-server-registry-probe.py including the
integer ConnectTimeout fix), the bundled verified registry seed (WoW, EQEmu,
the Goldberg relay, Impostor, OpenDAoC), and full player+admin UI at
/community/servers and /community/issues. Featured flag pins the
persistent-world servers (WoW/EQEmu/OpenDAoC) to a compact status panel
surfaced on the community landing page. Scheduled sweep respects a
circuit-breaker backoff and never probes on page load; the relay is never
network-probed, only liveness-checked over ssh.
Friendship (request/accept/decline/remove, self-request and crossing-request
handling, DB-level pair uniqueness via a hand-written expression index),
ChatRoom/ChatMessage/ChatReadState backed by Nitro's built-in websocket
(server/api/v1/community/ws.get.ts) behind a ChatTransport seam
(server/internal/community/chatTransport.ts) with a REST send fallback.
Mid-milestone product redirect: chat's primary job is coordinating the
persistent-world servers (EQEmu/WoW/DAoC), not per-title discussion --
ChatRoomKind gets a first-class `server` case and chatService.ts ships a
static KNOWN_SERVERS registry keyed the same way M4's GameServer will be,
once that lands (gameServerId reserved for that wiring-up pass).
Presence has no new table -- "online" is a live websocket registry
(presenceRuntime.ts), "playing X" reads through an isolated query module
(presenceService.ts) that degrades to an empty, clearly-labeled result if
PlaySession's shape doesn't match what it expects.
Pages: /community/friends, /community/chat, plus a friends/servers strip on
/community itself. Migration 20260803120000_m3_friends_chat.
Adds the M5 slice of the community layer: Mod/ModVersion/ModDependency/
ModInstallation/ModInstalledFile/AchievementDefinition (migration
m5_mods_achievements). Gods/Users are referenced as plain soft columns
(gameId/uploaderId/identityId), not Prisma relations, following the
concurrent-edit-avoidance pattern devices.prisma established -- content.prisma
and user.prisma only grow a comment each.
Mods: syncs from script-library/scripts/archive-mod.py's _index/catalog.json
(read-only bind mount, homelab-compose/drop-stack/docker-compose.yml) into
Mod/ModVersion/ModDependency, resolves dependency refs into real Mod rows
where archived, and exposes a topologically-ordered install-plan resolver
with cycle/conflict/unresolved-dependency detection
(GET /mods/:id/versions/:v/plan). The install manifest
(ModInstallation/ModInstalledFile) records created/overwrote/skipped per
file so an uninstall plan is exact, computed server-side from what was
recorded, applied by the caller. Downloads stream directly off the mount
(GET /mods/:id/versions/:v/download) since cdn.quasarke.net has no
file_server wired to /mnt/local24/game-mods yet -- documented as a known gap
in server/internal/community/README.md, deliberately not fixed by editing
the live Caddyfile. A manual add form covers the DESIGN.md open-question #4
fallback (no upload write path exists).
Achievements: imports gbe_fork's archived generate_emu_config output
(/mnt/local24/game-tools/goldberg/schemas, also read-only mounted) via
goldbergAdapter.ts, copying icons into Drop's own object store
(objectHandler.createFromSource, same mechanism as Steam cover art) so
nothing is hotlinked. Display joins AchievementDefinition against M2's
already-landed AchievementUnlock by (steamAppId, apiName), exactly the join
key M2 designed it around -- no stub needed, M2's table was already in the
tree. Verified against real fixtures: appid 245170 (Skullgirls) importing
45/45 definitions with 90 icons, and 274190 (Broforce) importing 17/17.
Pages: /community/mods, /community/mods/:slug, /community/mods/new,
/community/achievements, /community/games/:gameId (achievement grid +
per-title mods, completion %). Small additive nav links on /community's
index rather than touching the actively-changing shared game-detail page.
Adds the M2 slice of the community layer: Device/DeviceToken/EnrollmentCode/
PlaySession/AchievementUnlock (migration m2_devices_playtime), the
device-token-authenticated ingest surface (POST /api/v1/ingest/enroll,
session-start, session-stop, achievements -- every success acks 2xx +
{"ok":true}, idempotent on sessionId), the /community/devices enrollment UI,
a PowerShell launch wrapper (homelab-compose/drop-stack/wrapper), and unified
playtime rails across Drop + RomM on the profile page.
Also implements the community titles listing change: default view is now
played-only (PlaySession + native Playtime, both platforms), sorted by most
recently played, with a friendly empty state and a "browse all" toggle back
to the full catalog. Adds a live-activity panel (now playing / recently
played) sourced from PlaySession, and a clearly-labeled server-status slot
for M4 to fill in.
PlaySession is the join table for M3/M4/M5: userId, deviceId, titlePlatform
('drop'|'romm'), gameId, communityTitleId, steamAppId, sessionId (unique),
startedAt, endedAt, durationSeconds, endReason, exitCode. No stale-session
sweeper in this pass -- "currently playing" is endedAt IS NULL, filtered to
sessions started within the last 12h for the live panel.
runCommunityTitleSync's "hide titles that disappeared from RomM" step
built `externalId: { notIn: Array.from(seenExternalIds) }` -- on a
first sync essentially every title is "seen", so that list is ~34.5k
entries, each becoming a bound parameter and blowing Postgres's query
parameter limit (Prisma P2029: "query parameter limit... is exceeded").
Caught live: the first real "Sync now" click 500'd immediately.
Replaced with a timestamp comparison: capture syncStartedAt before any
row is touched, let every create/update set (or DB-default) lastSyncedAt
to now, then hide anything still older than syncStartedAt. Same "wasn't
touched by this run" semantics as the id-set check, O(1) parameters
regardless of catalog size.
Also hardens server/pages/community/index.vue's initial title fetch and
admin sync-status fetch with try/catch instead of an unguarded top-level
await -- a request that throws for any reason (this bug, a future one,
a transient adapter hiccup) should degrade to an empty/quiet state, not
take the whole page down via Nuxt's full-page error boundary. This is
exactly how a *different*, now-fixed bug (an arktype schema requiring
the `platform` query key to be present) surfaced: a plain 400 from the
API turned into a hard page crash purely because nothing caught it.
Replaces the server/pages/community.vue stub ({{ $t("todo") }}) with real
Nuxt pages: a unified Drop+RomM title browser, an admin catalog-sync panel,
and a profile page with playtime rails. Corrects the original architecture
mistake of building this as a separate service at community.quasarke.net --
now that we own the fork's source, community is ordinary Nuxt pages instead
of a sidecar with its own auth/DB/vhost.
Data model: one new table, CommunityTitle, for the RomM catalog (ported
from drop-community M1's Title spine). Drop's own Game/User/Playtime models
already ARE the title/identity/playtime spine for Drop content, so nothing
new was needed there -- profile playtime rails read real, already-existing
Playtime rows, no wrapper/ingest milestone required to populate them.
RommAdapter (server/server/internal/community/rommAdapter.ts) reads RomM's
MariaDB directly via the community_ro read-only role, same deviation and
same reasoning as M1's adapter (RomM's /api/roms needs a browser session,
no service-account key). TitleSyncService runs every 6h
(scheduledTasks.communityTitleSync) and via an admin "Sync now" button
(system:community:sync ACL) -- never deletes, hides instead.
Also folds the three post-build JS patches
(homelab-compose/drop-stack/patch-{launcher-button,telemetry-snippet,
footer-links}.js) into source now that the fork builds from source instead
of patching upstream's prebuilt image:
- library/game/[id]/index.vue: the "Open in Launcher" button gets a real
@click handler (drop://open with a timeout fallback to /download).
- plugins/telemetry.client.ts: OpenPanel RUM injected via a Nuxt client
plugin instead of appending to the compiled entry chunk.
- UserFooter.vue + admin/library source-help links + error.vue + the
Weblate link: repointed at our own infra. The Discord/social link
used to point at community.quasarke.net; that service is retired, so
it now points at /community directly.