fix(multiplayer): validate REST response ids

This commit is contained in:
Josh Creek
2026-09-01 22:47:57 +01:00
parent bda3fc5aff
commit edd78d2548
3 changed files with 31 additions and 3 deletions
+2
View File
@@ -1601,6 +1601,8 @@ Authenticated client REST methods now enforce opaque ticket, proposal, and match
Persisted matchmaking snapshots now apply the same opaque-ID validation to ticket and proposal identities, preventing malformed restart state from entering recovery.
Control-plane REST responses now fail closed on malformed ticket, proposal, or session player IDs before projection, covering the server-to-client JSON boundary as well as request paths.
Signed MatchNet claims now also require exact JSON string/integer types for every identity, protocol, expiry, slot, team, and generation field; string-number coercion is rejected before canonical signature verification.
Presentation progress: a shared `Game/themes/cosmic_clash_theme.tres` now gives the menu, lobby, matchmaking, and settings surfaces consistent button, input, option, and label styling. The custom-font portion of `TODO.md` remains open until a distributable font asset is selected.