Repository navigation
Conversation
…bled WebDoors WebDoorController used the caller-supplied game_id (or referer, default 'unknown') without checking it, so any user could create sessions, saves and leaderboard scores for arbitrary, disabled or uninstalled games. Resolve the id against the WebDoor manifests, config/webdoors.json and manifest requirements (as the listing and game page do) and return 404 errors.webdoor.game_unavailable before any query otherwise. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TITLE: WebDoor API: only serve sessions, saves and scores for installed, enabled WebDoors
Problem
WebDoorControllertakes the game from the caller-suppliedgame_idquery parameter, or the/webdoors/{id}/referer, and defaults to'unknown'. It never checks the value against the installed WebDoors orconfig/webdoors.json. Any authenticated user can create sessions, write save slots (up to the size limit) and submit leaderboard scores under:'unknown'bucket.Impact
Users can fill
webdoor_storage,webdoor_sessionsandwebdoor_leaderboardswith rows for games that don't exist or are switched off, and can post leaderboard scores for disabled games that show up again when the game is re-enabled.Repair
WebDoorController::resolveGameId()resolves the requested id (explicitgame_id, or the referer) againstWebDoorManifest::listManifests(), by directory orgame.id. It accepts the id only when the manifest has agameblock, the game is enabled inconfig/webdoors.json, and itsrequirementsare met. These are the same checks the WebDoor listing and game page use. The canonical manifest id is used for storage.The seven game-scoped methods (
getSession,listSaves,loadSave,saveGame,deleteSave,getLeaderboard,submitScore) return404errors.webdoor.game_unavailablebefore any query when it doesn't resolve. The new key is added to all six locales.docs/WebDoors.mddocuments the rule.Compatibility
Bundled WebDoors keep working:
game_id(the SDK);Requests without a resolvable game no longer fall into a shared
'unknown'bucket.Proof
tests/Unit/WebDoorGameAuthorizationTest.phpuses the real installed manifests, a controlledGameConfigand a recording PDO stub, with no database:game_idand via the referer, under its canonical id;Fails on the current branch (5 failures); passes with the change. The i18n syntax, missing-key and error-key checks pass, and the rest of
tests/Unitis unchanged.