fix(multiplayer): validate session expiry response

This commit is contained in:
Josh Creek
2026-09-01 22:50:00 +01:00
parent edd78d2548
commit 3bd2387dc3
3 changed files with 21 additions and 1 deletions
+2
View File
@@ -1603,6 +1603,8 @@ Persisted matchmaking snapshots now apply the same opaque-ID validation to ticke
Control-plane REST responses now fail closed on malformed ticket, proposal, or session player IDs before projection, covering the server-to-client JSON boundary as well as request paths.
Session establishment now also requires a present, syntactically valid, future `expires_at`, preventing malformed authentication responses from creating an unbounded client session.
Signed MatchNet claims now also require exact JSON string/integer types for every identity, protocol, expiry, slot, team, and generation field; string-number coercion is rejected before canonical signature verification.
Presentation progress: a shared `Game/themes/cosmic_clash_theme.tres` now gives the menu, lobby, matchmaking, and settings surfaces consistent button, input, option, and label styling. The custom-font portion of `TODO.md` remains open until a distributable font asset is selected.