Require authentication for RPCs and rate-limit fan-out methods
- Every method except auth_challenge/auth_verify now requires a verified session (auth::require) and answers "Not authenticated" otherwise. Before, an unauthenticated connection could send emote_event notifications to any connected player and probe who is online with get_player. - Rate-limit per connection the methods that fan out to other players: emote (burst 5, +1/s) and send_player (burst 10, +1/s). - Cap emote/send_player targets at 256 and de-duplicate them. - Default SUPPORTED_VERSIONS to 0.1.1-beta. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
+1
-1
@@ -8,7 +8,7 @@ services:
|
||||
- "${HOST_PORT:-8080}:8080"
|
||||
environment:
|
||||
# Comma-separated client versions served at GET /versions.
|
||||
SUPPORTED_VERSIONS: ${SUPPORTED_VERSIONS:-0.1.0-beta3}
|
||||
SUPPORTED_VERSIONS: ${SUPPORTED_VERSIONS:-0.1.1-beta}
|
||||
DEPRECATED_VERSIONS: ${DEPRECATED_VERSIONS:-}
|
||||
volumes:
|
||||
- server-data:/data
|
||||
|
||||
Reference in New Issue
Block a user