mirror of
https://github.com/nestriness/nestri.git
synced 2026-09-19 17:25:19 +03:00
refactor(api)!: remove the shared operator secret, and let hosts sync their own
A single secret that turned any request into an operator was the only credential several routes accepted, and it had no caller left: the device pairing it existed for is on hold, and nothing in this tree or any client sent it. What remained was a key that bypassed authentication entirely, required to boot, and checked by nobody. Every route behind it had a better answer available: - Library and game sync move to host credentials. Both took a `userId` in the body, which meant one secret could write into anybody's library. A host now says which of its enrolled users a batch is for, and that claim is checked against the Steam sign-ins it actually holds — one box carries several people's accounts, so the pair is the unit. - Download-state reporting narrows to hosts alone, and the body that could name a different host is gone. Which host is reporting comes from its own credentials, and a body that still names one is refused rather than ignored. - Linking a Steam account is always for the caller. - Creating a game by hand is deleted; syncing already upserts the catalogue. - Reading the waitlist is deleted. Every address on it belongs to someone who has not agreed to anything, and answering it over HTTP made that list something a leaked key could drain. - The pairing-code routes are deleted with the flow they served. The domain module and its table stay, so returning to it is a route file rather than a migration. Nothing in the API now accepts a credential that stands for more than one caller: every request resolves to a specific user or a specific host, which is what lets a route say "the caller's own library" and mean it. BREAKING CHANGE: the `x-nestri-admin-token` header is no longer accepted and `ADMIN_SHARED_SECRET` is no longer read. `POST /games`, `GET /waitlist` and the `/pairing-code` routes are gone; `POST /games/sync` and `POST /library/sync` now require host credentials and take `userId` in the body; `POST /steam/link` no longer accepts `userId`; `POST /games/download-state` no longer accepts `hostId`.
This commit is contained in:
@@ -79,7 +79,7 @@ export namespace SteamApi {
|
||||
describeRoute({
|
||||
tags: ['Steam'],
|
||||
summary: 'Link a Steam account',
|
||||
description: 'Link a Steam account to a user (admin) or yourself (user)',
|
||||
description: 'Link a Steam account to the calling user.',
|
||||
responses: {
|
||||
200: {
|
||||
content: {
|
||||
@@ -113,13 +113,6 @@ export namespace SteamApi {
|
||||
description: 'Steam ID to link',
|
||||
example: '76561197960287930'
|
||||
}),
|
||||
userId: z
|
||||
.string()
|
||||
.optional()
|
||||
.meta({
|
||||
description: 'User ID to link to (admin only; omitted when linking your own account)',
|
||||
example: Examples.Id('user')
|
||||
}),
|
||||
profile: z
|
||||
.record(z.string(), z.unknown())
|
||||
.optional()
|
||||
@@ -131,20 +124,14 @@ export namespace SteamApi {
|
||||
),
|
||||
async (c) => {
|
||||
const body = c.req.valid('json');
|
||||
const actor = Actor.use();
|
||||
|
||||
if (body.userId && actor.type !== 'admin') {
|
||||
throw new VisibleError(
|
||||
'forbidden',
|
||||
ErrorCodes.Permission.INSUFFICIENT_PERMISSIONS,
|
||||
'Only admin can link a Steam account for another user'
|
||||
);
|
||||
}
|
||||
|
||||
// Linking is always for the caller. It once accepted a `userId`,
|
||||
// which meant one credential could attach a Steam account to any
|
||||
// user \u2014 and a linked account is how a library is reached.
|
||||
const linkedAccountID = await Steam.link({
|
||||
steamId: body.steamId,
|
||||
profile: body.profile,
|
||||
userId: body.userId
|
||||
userId: Actor.userID
|
||||
});
|
||||
return c.json({
|
||||
data: { linkedAccountId: linkedAccountID, steamId: body.steamId }
|
||||
|
||||
Reference in New Issue
Block a user