Require authentication for RPCs and rate-limit fan-out methods

- Every method except auth_challenge/auth_verify now requires a verified
  session (auth::require) and answers "Not authenticated" otherwise.
  Before, an unauthenticated connection could send emote_event
  notifications to any connected player and probe who is online with
  get_player.
- Rate-limit per connection the methods that fan out to other players:
  emote (burst 5, +1/s) and send_player (burst 10, +1/s).
- Cap emote/send_player targets at 256 and de-duplicate them.
- Default SUPPORTED_VERSIONS to 0.1.1-beta.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-09-25 19:56:44 +02:00
co-authored by claude
parent c4ff921a7c
commit 56f511d5f6
7 changed files with 133 additions and 12 deletions
+1 -1
View File
@@ -8,7 +8,7 @@ services:
- "${HOST_PORT:-8080}:8080"
environment:
# Comma-separated client versions served at GET /versions.
SUPPORTED_VERSIONS: ${SUPPORTED_VERSIONS:-0.1.0-beta3}
SUPPORTED_VERSIONS: ${SUPPORTED_VERSIONS:-0.1.1-beta}
DEPRECATED_VERSIONS: ${DEPRECATED_VERSIONS:-}
volumes:
- server-data:/data