* [auth][api] accept the 20250424.01 client * [2025] unstable * 20250718.0 * correct one this time * stubs * more stubs * more stubs * [lists] add worker * [ai] route stubs * [api] player photo setting * [econ] add roomEconConfig route * [infra] update worker generators * [worker] add cards/moderation/platformnotification workers * [lists] updates to some endpoints * [clubs] stub out announcement endpoint, for now * [econ] stub out season endpoints for now * [chat] apps/chat stub out party endpoint not sure the shape yet * [api] stub out statsig and lockeditems * [doc] new services * [lists] stub the bulk endpoint * [datacollection] add placeholder service until we can kill it * [api] set gifting to lvl5 * update lock * [cdn] enable cache * [match] matchmake v2 * [lists] stub some lists * [ai] stubs * [rooms] new subroom save endpoint * [econ] add bulk purchase endpoint * [discovery] update featured creator to 1 for fun * [api] add photo settings flag * [chat] fixup chat permissions (sorta) * [auth] restrictions endpoint * [rooms] contributed endpoint * [api] fix outfit endpoint * [discovery] attempt to fix store * [chat] privacy endpoints * [api] cheered images * [rooms] add xp endpoint (disbaled) * [rooms] add xp endpoint (disabled) * update images-db for cheers * [rooms] add autocomplete endpoint * [cdn/img] increase cache ttl for statics * [api] bulk route for images * [accounts] add banner image * [api] add misc missing endpoints * [discovery] remove AI tab * [platformnotifications] stub some endpoints * [lists] add some more lists * [rooms] additional endpoints * [chat] stub a few privacy endpoints * [econ] stub some endpoints * misc db fixes * [api] tweak shape for images v6 * [rooms] dont show trending RROs
2.4 KiB
cdn
CDN Worker served on the cdn subdomain (cdn.recflare.net) — a Hono app that streams
the binary blobs the client downloads while playing out of the shared recflare-cdn R2
bucket, plus the JSON config files the client reads from /config/.
/config/:name serves static/config/<name>.json verbatim — RRPlusConfig_v3 and
SkuConfig_v1 today — with or without the .json in the path, since the game configs that
point at these files carry the extension and the client's older config calls don't. {name}
IS the filename: that directory is uploaded as Workers static assets and read through the
ASSETS binding, so publishing a config is dropping in a file, and run_worker_first keeps
the asset server from answering ahead of the Worker (nothing is reachable at its own asset
path). The files go out byte-for-byte, BOM included. /config/LoadingScreenTipData stays a
route of its own, bundled rather than an asset, because its file is named differently from
its path.
Objects are keyed by prefix — sigs/ (anti-cheat signatures), room/ (saved room
scenes, and room images by their bare ImageName), invention/ (invention data) — and
served as application/octet-stream; the worker never interprets what it hands back.
Reads are unauthenticated: a caller needs the exact key, which only comes from an
authenticated call to another worker.
This worker only reads. Uploads go through storage, which writes the same bucket, and
images are served by img.
API documentation
GET /openapi.json serves a spec generated from describeRoute blocks that sit
alongside each handler, with the schemas in src/openapi.ts. It's also aggregated into
the docs page www serves at /docs.
The spec is descriptive, not enforced — same rationale as the img/auth workers: a
reverse-engineered protocol, lenient handlers, no runtime validation. A test asserts
every route appears in the spec, so adding one without documenting it fails.
Conditional and range requests
Every asset route honours If-None-Match (→ 304) and a single Range (→ 206). The range
support is not an optimization: large-file downloaders fetch in chunks, and answering 200
where a 206 is expected corrupts the reassembled file — which surfaces as an anti-cheat
"Signatures don't match" failure rather than a download error.
Development
Run in dev mode
pnpm dev
Run tests
pnpm test
Deploy
pnpm turbo deploy