The séance tells guests "claim a name to keep your codex". It was a lie.
register() unconditionally created a brand-new User row with a fresh UUID,
so a wanderer's essence, discovered entities, sightings, ritual/judgment
history and Ghost Log — every one of them foreign-keyed to the guest's
user_id — were silently orphaned the moment they registered. Now that
every visitor starts as a guest, that hit essentially everyone who ever
signed up.
A wanderer hitting /register now renames that same row in place, keeping
all relationships intact. The existing AuthSession stays valid (same
user_id), so claiming a name doesn't even log you out.
Scoped deliberately to wanderers. My first attempt rejected ANY
authenticated caller with a 409, which broke registering a second account
while logged in — a legitimate flow (shared computer, alt account) that
tests/test_device.py::test_device_feed_only_broadcasts_to_the_owning_user
caught immediately: its second register 409'd, its login then failed, and
"user B's" device got paired to user A, silently defeating a
cross-user-isolation assertion. A named caller's cookie is now ignored and
the normal create-a-new-row path runs.
Adds get_optional_current_user (None instead of 401) for endpoints that
behave differently for anonymous vs. authenticated callers but must stay
reachable without auth.
This was one of eight findings from an adversarial audit whose verifier
agents all died on session limits, so nothing was machine-verified — I
confirmed this one by reading the code and then proving it end-to-end.
The other seven remain unchecked.
331 backend tests pass. Verified live: guest 23846555 -> livehunter1, same
id, same session still valid.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
POST /auth/guest mints a real user row (wanderer-<4 hex>, collision
retry, unusable random password) and issues the normal session cookie,
per-IP rate limited at 5/hour. EnterPage gains the guest action;
the séance shows a dismissible claim-a-name note for wanderer- users.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Implements the backend REST surface and WS wiring for
docs/superpowers/specs/2026-07-23-character-depth-ghost-log-design.md's
Workstream C:
- New models: UnlockRecord (unlocks), InventoryItem (inventory_items),
Sigil (sigils) — brand-new tables, picked up by main.py's existing
create_all.
- New app/inventory.py: unlock price table, item drop table/odds,
essence economy constants, sigil design validation, and an atomic
(row-locked) purchase_unlock() that guards against double-spend races.
- New app/routes/inventory.py: GET unlocks/items/sigils, POST sigils
(validates the placeholder {points, rune} shape, points capped at 12),
POST unlocks/{unlock_key} (402 on insufficient essence, 404 on unknown
key, idempotent re-buy).
- GET /auth/me now includes unlocks: list[str] and essence: int.
- ws.py: wires essence trickle + item_drop rolls into the one trigger
point that exists in this worktree today (_handle_summon, covering
every successful summon plus high-rarity summons); the other two
contract trigger points (correct judgment, successful ritual) belong
to Workstream B's not-yet-landed ritual/judgment WS handlers, which
should call app.inventory's same helpers once they land.
- User.essence: int added (Workstream B owns this column per the spec;
added here per orchestrator instruction so this workstream is
independently testable — merge controller reconciles the duplicate
edit).
Also fast-forwarded this worktree's branch onto master (it had fallen
behind several commits) so the files this workstream depends on
(shop.py, ws.py, entities.py, etc.) were actually present to build
against.
Tests: 109 passed (drop-roll statistical sanity with seeded RNG,
inventory/sigil CRUD, purchase success/insufficient-funds/idempotency/
unknown-key paths, /auth/me shape, ws summon-trickle and item-drop
wiring).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses three Important-severity review findings inherited from Task 4's
plan reference code:
- login() now sets secure=True on the session cookie (safe behind the
Cloudflare Tunnel, which terminates TLS at the edge).
- logout() looks up and deletes the matching AuthSession row before
clearing the cookie, so a leaked raw token can no longer be replayed
after logout.
- login() always performs exactly one verify_password call regardless of
whether the username exists (against a module-level dummy hash for
nonexistent users), removing the timing oracle that let unauthenticated
requests distinguish registered from unregistered usernames.
Adds two tests: nonexistent-username login rejection, and logout revoking
the session server-side. Also adjusts two cookie-propagation touch points
in test_auth.py to manually re-inject the qm_session cookie, since
httpx's cookie jar won't auto-attach a Secure cookie to the test
transport's plain http://test base_url (a real browser talking to the
HTTPS tunnel edge wouldn't have this problem).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof