Files
recflare/apps/api
Nexi 222547ee13 [api] audit fixes: account tests, dependencies and security hardening (#54)
* test(accounts): cover three username changes

* chore(deps): update vulnerable runtime dependencies

* fix(security): bound uploads and validate token subjects strictly

---------

Co-authored-by: Nexi (CWN) <communityshieldofficial@gmail.com>
2026-09-08 23:47:58 -04:00
..
2026-09-08 23:07:27 -04:00
2026-09-02 10:41:59 -04:00
2026-06-09 00:49:11 -04:00
2026-06-29 23:16:42 -04:00
2026-06-09 00:49:11 -04:00
2026-06-30 23:57:29 -04:00

api

Game API Worker served on the api subdomain. A Hono app serving the game's API surface. Database-backed queries and on-disk JSON files are stubbed for now — no real bindings yet.

Behavior

  • Auth-gated routes validate the Bearer JWT issued by the auth worker (same dev secret, see src/jwt.ts) and 401 when it's missing/invalid.
  • Static data is served verbatim:
    • src/default-avatar-items.tsGET /api/avatar/v4/items
    • src/default-settings.tsGET /api/settings/v2
  • DB-backed reads return empty collections / not-found.
  • File-backed reads return empty placeholders, each marked TODO: hydrate in src/api.app.ts (Workers have no filesystem — these will move to a binding or inline JSON later).

TODO before production

  • Wire a DB binding (D1/DO) for rooms, avatars, settings, gifts, balances, etc.
  • Hydrate the TODO: hydrate endpoints with real config/JSON.
  • Move the JWT secret to a shared secret binding (shared with auth).
  • Persist uploads from POST /api/images/v4/uploadsaved (e.g. R2).