fix(multiplayer): validate persisted matchmaking snapshots

This commit is contained in:
Josh Creek
2026-09-01 22:34:59 +01:00
parent 3985b74bcf
commit a10c6d47f9
3 changed files with 30 additions and 2 deletions
+2
View File
@@ -1581,6 +1581,8 @@ Ranked profile season metadata now validates optional expiry type and RFC3339 fo
Ranked profile `season_id` now enforces the OpenAPI opaque-ID shape and exact string type, preventing undersized or coerced identifiers from entering the client projection.
Persisted matchmaking snapshots now validate field types, non-negative integral revisions/epochs, and proposal identity/state consistency before restoration; malformed restart data cannot be coerced into an active projection.
Signed MatchNet claims now also require exact JSON string/integer types for every identity, protocol, expiry, slot, team, and generation field; string-number coercion is rejected before canonical signature verification.
Presentation progress: a shared `Game/themes/cosmic_clash_theme.tres` now gives the menu, lobby, matchmaking, and settings surfaces consistent button, input, option, and label styling. The custom-font portion of `TODO.md` remains open until a distributable font asset is selected.