Skip to content

fix(auth): grant GameLauncher sessions ServerListReadOnly access - #67

Merged
x64-dev merged 1 commit into
GeneralsOnlineDevelopmentTeam:mainfrom
undead2146:fix/gamelauncher-server-list-read
Sep 28, 2026
Merged

x64-dev merged 1 commit into
GeneralsOnlineDevelopmentTeam:mainfrom
undead2146:fix/gamelauncher-server-list-read

Conversation

@undead2146

Copy link
Copy Markdown

Summary

SessionHelpers.SessionTypeHasAccessTo only grants GameClient and ignores the requested access type, so every GameLauncher caller of GET /Lobbies falls into the explicit 500 branch in LobbiesController.Get — even though the AnyClientOrMonitorOrApiKey policy admits the GameLauncher role. Launcher clients (client_id: genhub, which maps to GameLauncher in KnownClientSessionTypes) can sign in but can never list lobbies.

Changes

  • GenOnlineService/Constants.cs: grant GameLauncher the ServerListReadOnly access the enum documents ("can read lobby list and players etc, but cannot join"). All other access types stay GameClient-only.

Blast radius

ServerListReadOnly is consumed only by LobbiesController.Get. Verified every other SessionTypeHasAccessTo caller passes Gameplay or Authenticate, so no join, mutate, matchmaking, social, or gameplay path is affected by this change.

Notes

  • Observed against production: GET /Lobbies with a valid genhub session returns 500; the only 500 path in that handler is the access-denied branch (exceptions are caught and return 200 with an empty result).
  • Out of scope but worth a look: the access-denied branch sets InternalServerError; 403 Forbidden would let clients distinguish denial from a real server error.
  • Could not build locally (repo targets .NET 10, only the .NET 8 SDK is available here); relying on CI.

undead2146 pushed a commit to community-outpost/GenHub that referenced this pull request Sep 27, 2026
The public site 403s requests without a User-Agent (.NET HttpClient sends none), so signed-out counts always failed; verified empty UA -> 403 and GenHub UA -> 200 against production. All GO requests now send ApiConstants.DefaultUserAgent.

Non-success lobby and public-page responses now log a scrubbed, truncated body preview so backend failures (e.g. the Lobbies 500, root-caused to SessionTypeHasAccessTo denying GameLauncher ServerListReadOnly — see GeneralsOnlineDevelopmentTeam/Services#67) are diagnosable from client logs.
@undead2146
undead2146 force-pushed the fix/gamelauncher-server-list-read branch from c0ac999 to f9fb43c Compare September 27, 2026 16:29
SessionTypeHasAccessTo is a stub that only grants GameClient, so every GameLauncher caller of GET /Lobbies falls into the explicit 500 branch even though the endpoint policy admits the GameLauncher role. Launcher clients (client_id genhub) can sign in but can never list lobbies.

Grant GameLauncher the ServerListReadOnly access the enum documents ("can read lobby list and players etc, but cannot join"). ServerListReadOnly is consumed only by LobbiesController.Get, so no join, mutate, matchmaking, or gameplay path is affected; all other access types stay GameClient-only.
@undead2146
undead2146 force-pushed the fix/gamelauncher-server-list-read branch from f9fb43c to 97a1b92 Compare September 27, 2026 17:06
undead2146 pushed a commit to community-outpost/GenHub that referenced this pull request Sep 28, 2026
The public site 403s requests without a User-Agent (.NET HttpClient sends none), so signed-out counts always failed; verified empty UA -> 403 and GenHub UA -> 200 against production. All GO requests now send ApiConstants.DefaultUserAgent.

Non-success lobby and public-page responses now log a scrubbed, truncated body preview so backend failures (e.g. the Lobbies 500, root-caused to SessionTypeHasAccessTo denying GameLauncher ServerListReadOnly — see GeneralsOnlineDevelopmentTeam/Services#67) are diagnosable from client logs.
@x64-dev
x64-dev merged commit 7aa0867 into GeneralsOnlineDevelopmentTeam:main Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants