The audit that produced these had every verifier agent die, so none were
confirmed. Checked each against the running system rather than guessing.
1. COOKIE Secure FLAG — REAL, fixed. The Cloudflare Tunnel runs OFF this box
(observed source 10.30.20.67, 155 requests in the journal) and uvicorn
only honours X-Forwarded-* from --forwarded-allow-ips, default 127.0.0.1.
Proven by hitting the LAN IP with X-Forwarded-Proto: https and watching
Secure vanish from Set-Cookie. Every internet visitor's session cookie
was going out without it.
Fixed in the unit drop-in with --proxy-headers and an allow-list scoped
to the tunnel host — NOT "*", because trusting that header from anywhere
would let a LAN client forge the IP the per-IP limiters key on. Verified
both directions: trusted source + header gets Secure, plain LAN http
correctly does not, and a spoof from an untrusted host is ignored.
2. DOUBLE GUEST ON REMOUNT — REAL but narrow, left alone. The guestAttempted
ref already covers StrictMode's double-effect (refs survive it). The only
hole is unmounting during the in-flight request, which needs navigating
away and back inside ~200ms and costs one unused row. Not worth
complicating the open door's happy path for.
3. SILENT REDIRECT WHEN RATE-LIMITED — REAL, fixed. A visitor whose guest
provisioning was refused got bounced to /enter with no explanation — and
at 5/hour/IP a household or cafe behind one NAT reaches that easily. The
failure reason (the backend's own in-fiction line) now rides along in
router state and /enter shows it, so nobody is silently handed a login
form they never asked for.
4. RATE LIMITER KEYS NEVER EVICTED — REAL, fixed. defaultdict entries
survived forever even once their hit list emptied. The open door made
this materially worse: every visitor is now a real account, so every
visitor permanently added a key across eleven limiter instances. Added an
opportunistic sweep every 512 admitted calls — no background task, cost
lands on whoever generates the load. Three tests; verified they catch it
by disabling the sweep and watching one fail.
5. SUMMON RACE vs TELEMETRY — REAL, fixed. Nothing serialised summoning.
_handle_anomaly checks `state.entity is None` then awaits a summon
containing a multi-second LLM mint, and the ESP32's HTTP ingestion path
calls _handle_anomaly on the SAME SeanceState — which is the entire point
of the device integration. Both could pass the check: two entities
minted, two essence credits, two item rolls, state.entity clobbered by
whichever finished last. Now guarded by a per-session asyncio.Lock.
6. LEGACY ENTITIES STUCK AT DEFAULT TRAITS — mechanism REAL, zero rows
affected here. The ALTER defaults traits to '{}' with no backfill and
roll_traits only runs at mint, so a pre-migration spirit would read 0.5
for everything — making `trust` always correct and `cross_over`
unreachable. This install has 0 such rows. Added a signature-seeded
backfill anyway, guarded to empty-traits rows so it can never touch a
spirit that already has a real nature.
(A seventh claim from the same batch — that iOS EMF is silently dead — was
refuted earlier and deliberately left untouched.)
34 targeted tests pass; deployed and verified live.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
196 lines
8.2 KiB
Python
196 lines
8.2 KiB
Python
import asyncio
|
|
import contextlib
|
|
from contextlib import asynccontextmanager
|
|
from pathlib import Path
|
|
|
|
from fastapi import FastAPI, HTTPException
|
|
from fastapi.responses import FileResponse
|
|
from fastapi.staticfiles import StaticFiles
|
|
from sqlalchemy import text
|
|
|
|
import app.models # noqa: F401 — registers models on Base.metadata before create_all
|
|
from app.db import Base, async_session_maker, engine
|
|
from app.routes.auth import router as auth_router
|
|
from app.routes.codex import router as codex_router
|
|
from app.routes.conditions import router as conditions_router
|
|
from app.routes.device import router as device_router
|
|
from app.routes.inventory import router as inventory_router
|
|
from app.routes.messages import router as messages_router
|
|
from app.routes.profile import router as profile_router
|
|
from app.routes.seances import router as seances_router
|
|
from app.routes.seo import router as seo_router
|
|
from app.routes.shop import router as shop_router
|
|
from app.session_cleanup import delete_expired_sessions
|
|
from app.ws import AUDIO_DIR
|
|
from app.ws import router as ws_router
|
|
|
|
FRONTEND_DIST = Path(__file__).resolve().parent.parent.parent / "frontend" / "dist"
|
|
|
|
SESSION_CLEANUP_INTERVAL_SECONDS = 30 * 60
|
|
|
|
|
|
async def _session_cleanup_loop() -> None:
|
|
"""Periodically sweeps expired auth_sessions rows so the table doesn't
|
|
grow forever — get_current_user already rejects expired sessions on
|
|
read, this just deletes the rows themselves."""
|
|
try:
|
|
while True:
|
|
await asyncio.sleep(SESSION_CLEANUP_INTERVAL_SECONDS)
|
|
try:
|
|
async with async_session_maker() as db:
|
|
await delete_expired_sessions(db)
|
|
except Exception:
|
|
# A transient DB hiccup shouldn't kill the sweep loop —
|
|
# just try again next interval.
|
|
pass
|
|
except asyncio.CancelledError:
|
|
pass
|
|
|
|
|
|
@asynccontextmanager
|
|
async def lifespan(app: FastAPI):
|
|
AUDIO_DIR.mkdir(parents=True, exist_ok=True)
|
|
async with engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
# No Alembic in this repo — `create_all` never alters existing
|
|
# tables, so columns added to live models need a manual, idempotent
|
|
# migration here. Safe to run on every startup.
|
|
await conn.execute(text(
|
|
"ALTER TABLE entities ADD COLUMN IF NOT EXISTS traits JSONB NOT NULL DEFAULT '{}'::jsonb"
|
|
))
|
|
# Workstream C (character-depth-ghost-log spec) — missing from C's
|
|
# own commit, added by the integrator after Workstream B's report
|
|
# flagged that User.essence had a live model column and application
|
|
# code (auth/me, inventory purchases, summon trickle) but no
|
|
# migration, which would have broken on the real production DB.
|
|
await conn.execute(text(
|
|
"ALTER TABLE users ADD COLUMN IF NOT EXISTS essence INTEGER NOT NULL DEFAULT 0"
|
|
))
|
|
# Workstream B (character-depth-ghost-log spec).
|
|
await conn.execute(text(
|
|
"ALTER TABLE users ADD COLUMN IF NOT EXISTS favor DOUBLE PRECISION NOT NULL DEFAULT 0.0"
|
|
))
|
|
await conn.execute(text(
|
|
"ALTER TABLE entities ADD COLUMN IF NOT EXISTS at_peace BOOLEAN NOT NULL DEFAULT false"
|
|
))
|
|
# Any entity that predates the traits column above was left with
|
|
# `{}` — the ALTER defaults it and nothing backfills. Every judgment
|
|
# read then falls back to 0.5, which makes `trust` always correct and
|
|
# `cross_over` unreachable for that spirit: the minigame is silently
|
|
# solved for it. roll_traits() only ever runs at mint time, so such a
|
|
# row can never repair itself.
|
|
#
|
|
# Seeded from the entity's own signature so the values are stable and
|
|
# reproducible rather than random, matching how a freshly-minted
|
|
# spirit derives them. Guarded to empty-traits rows only, so it can
|
|
# never touch a spirit that already has a real hidden nature. This
|
|
# install currently has zero such rows; the backfill exists so the
|
|
# gap cannot bite a longer-lived deployment.
|
|
await conn.execute(text(
|
|
"""
|
|
UPDATE entities SET traits = jsonb_build_object(
|
|
'alignment', round((('x' || substr(md5(signature || 'alignment'), 1, 8))::bit(32)::bigint % 1000) / 1000.0, 3),
|
|
'power', round((('x' || substr(md5(signature || 'power'), 1, 8))::bit(32)::bigint % 1000) / 1000.0, 3),
|
|
'volatility', round((('x' || substr(md5(signature || 'volatility'), 1, 8))::bit(32)::bigint % 1000) / 1000.0, 3),
|
|
'deceptiveness',round((('x' || substr(md5(signature || 'deceptiveness'),1, 8))::bit(32)::bigint % 1000) / 1000.0, 3)
|
|
)
|
|
WHERE traits = '{}'::jsonb OR traits IS NULL
|
|
"""
|
|
))
|
|
|
|
# Hunter profile columns. All nullable (or defaulted) so existing
|
|
# rows, guests included, stay valid without a backfill.
|
|
for column, ddl in (
|
|
("display_name", "VARCHAR(48)"),
|
|
("bio", "VARCHAR(280)"),
|
|
("gender", "VARCHAR(16)"),
|
|
("avatar_form", "VARCHAR(16)"),
|
|
("avatar_hue", "INTEGER"),
|
|
):
|
|
await conn.execute(
|
|
text(f"ALTER TABLE users ADD COLUMN IF NOT EXISTS {column} {ddl}")
|
|
)
|
|
await conn.execute(text(
|
|
"ALTER TABLE users ADD COLUMN IF NOT EXISTS "
|
|
"profile_public BOOLEAN NOT NULL DEFAULT true"
|
|
))
|
|
|
|
# Defense-in-depth: purchase_unlock() already enforces one row per
|
|
# (user, unlock_key) via a row-locked check-then-insert, so this
|
|
# constraint should never actually find a conflict on a live DB.
|
|
# `ADD CONSTRAINT` has no IF NOT EXISTS form, so the guard is a
|
|
# catalog check instead — safe to run on every startup.
|
|
await conn.execute(text(
|
|
"DO $$ BEGIN "
|
|
"IF NOT EXISTS ("
|
|
" SELECT 1 FROM pg_constraint WHERE conname = 'uq_unlocks_user_key'"
|
|
") THEN "
|
|
" ALTER TABLE unlocks ADD CONSTRAINT uq_unlocks_user_key UNIQUE (user_id, unlock_key); "
|
|
"END IF; "
|
|
"END $$;"
|
|
))
|
|
cleanup_task = asyncio.create_task(_session_cleanup_loop())
|
|
try:
|
|
yield
|
|
finally:
|
|
cleanup_task.cancel()
|
|
with contextlib.suppress(asyncio.CancelledError):
|
|
await cleanup_task
|
|
|
|
|
|
app = FastAPI(title="Quantumancy", lifespan=lifespan)
|
|
app.include_router(auth_router)
|
|
app.include_router(codex_router)
|
|
app.include_router(conditions_router)
|
|
app.include_router(device_router)
|
|
app.include_router(inventory_router)
|
|
app.include_router(messages_router)
|
|
app.include_router(profile_router)
|
|
app.include_router(seances_router)
|
|
# Registered before the SPA catch-all below, or /robots.txt and
|
|
# /sitemap.xml would be served index.html instead.
|
|
app.include_router(seo_router)
|
|
app.include_router(shop_router)
|
|
app.include_router(ws_router)
|
|
|
|
|
|
@app.get("/healthz")
|
|
async def healthz():
|
|
return {"status": "ok"}
|
|
|
|
|
|
app.mount(
|
|
"/assets",
|
|
StaticFiles(directory=FRONTEND_DIST / "assets", check_dir=False),
|
|
name="frontend-assets",
|
|
)
|
|
app.mount(
|
|
"/audio",
|
|
StaticFiles(directory=AUDIO_DIR, check_dir=False),
|
|
name="spirit-audio",
|
|
)
|
|
|
|
|
|
@app.get("/{full_path:path}")
|
|
async def serve_spa(full_path: str):
|
|
index_file = FRONTEND_DIST / "index.html"
|
|
if not index_file.exists():
|
|
raise HTTPException(
|
|
status_code=503,
|
|
detail="Frontend not built. Run `npm run build` in frontend/ and restart.",
|
|
)
|
|
|
|
# Vite emits root-level static files (favicon.ico, favicon.svg,
|
|
# apple-touch-icon.png, og-image.png, …) straight into dist/ rather than
|
|
# dist/assets/ — the only mounted static dir. Without this, requests for
|
|
# them fall through to the SPA fallback below and get index.html back
|
|
# instead of the actual file (browsers silently ignore it; social-media
|
|
# link-preview crawlers fetching og:image get an HTML page).
|
|
if full_path:
|
|
dist_root = FRONTEND_DIST.resolve()
|
|
candidate = (dist_root / full_path).resolve()
|
|
if candidate.is_file() and dist_root in candidate.parents:
|
|
return FileResponse(candidate)
|
|
|
|
return FileResponse(index_file)
|