fix(auth): grant GameLauncher sessions ServerListReadOnly access - #67
Merged
x64-dev merged 1 commit intoSep 28, 2026
Conversation
undead2146
pushed a commit
to community-outpost/GenHub
that referenced
this pull request
Sep 27, 2026
The public site 403s requests without a User-Agent (.NET HttpClient sends none), so signed-out counts always failed; verified empty UA -> 403 and GenHub UA -> 200 against production. All GO requests now send ApiConstants.DefaultUserAgent. Non-success lobby and public-page responses now log a scrubbed, truncated body preview so backend failures (e.g. the Lobbies 500, root-caused to SessionTypeHasAccessTo denying GameLauncher ServerListReadOnly — see GeneralsOnlineDevelopmentTeam/Services#67) are diagnosable from client logs.
undead2146
force-pushed
the
fix/gamelauncher-server-list-read
branch
from
September 27, 2026 16:29
c0ac999 to
f9fb43c
Compare
SessionTypeHasAccessTo is a stub that only grants GameClient, so every GameLauncher caller of GET /Lobbies falls into the explicit 500 branch even though the endpoint policy admits the GameLauncher role. Launcher clients (client_id genhub) can sign in but can never list lobbies.
Grant GameLauncher the ServerListReadOnly access the enum documents ("can read lobby list and players etc, but cannot join"). ServerListReadOnly is consumed only by LobbiesController.Get, so no join, mutate, matchmaking, or gameplay path is affected; all other access types stay GameClient-only.
undead2146
force-pushed
the
fix/gamelauncher-server-list-read
branch
from
September 27, 2026 17:06
f9fb43c to
97a1b92
Compare
undead2146
pushed a commit
to community-outpost/GenHub
that referenced
this pull request
Sep 28, 2026
The public site 403s requests without a User-Agent (.NET HttpClient sends none), so signed-out counts always failed; verified empty UA -> 403 and GenHub UA -> 200 against production. All GO requests now send ApiConstants.DefaultUserAgent. Non-success lobby and public-page responses now log a scrubbed, truncated body preview so backend failures (e.g. the Lobbies 500, root-caused to SessionTypeHasAccessTo denying GameLauncher ServerListReadOnly — see GeneralsOnlineDevelopmentTeam/Services#67) are diagnosable from client logs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
SessionHelpers.SessionTypeHasAccessToonly grantsGameClientand ignores the requested access type, so everyGameLaunchercaller ofGET /Lobbiesfalls into the explicit500branch inLobbiesController.Get— even though theAnyClientOrMonitorOrApiKeypolicy admits theGameLauncherrole. Launcher clients (client_id: genhub, which maps toGameLauncherinKnownClientSessionTypes) can sign in but can never list lobbies.Changes
GenOnlineService/Constants.cs: grantGameLaunchertheServerListReadOnlyaccess the enum documents ("can read lobby list and players etc, but cannot join"). All other access types stayGameClient-only.Blast radius
ServerListReadOnlyis consumed only byLobbiesController.Get. Verified every otherSessionTypeHasAccessTocaller passesGameplayorAuthenticate, so no join, mutate, matchmaking, social, or gameplay path is affected by this change.Notes
GET /Lobbieswith a validgenhubsession returns500; the only 500 path in that handler is the access-denied branch (exceptions are caught and return 200 with an empty result).InternalServerError;403 Forbiddenwould let clients distinguish denial from a real server error.