[rust] T6-2c: Rust CODE runs the character you are playing #43

Open
opened 2026-09-25 12:36:28 +02:00 by sleepy · 0 comments
Owner

The in-game Rust CODE pane spawns a separate bot process that logs in as the character pinned in the serve’s creds file (Rusty via dev/.local), so code written in CODE never targets the character the browser is playing.

Fix: the panel sends the game page’s current character id (real_id) with /run; al serve runs the child as that character (character override on the request). The character id is not secret — the auth token still comes only from the local creds file and never crosses the page, backend, or cookie.

Constraint (verified live): the game server allows one live session per character (node/server.js ingame guard, msince < 120 minutes). While the browser holds the character, the bot answers a plain cannot log in: … ingame — the same surface as any refused handshake. The bot plays the character while it is released (e.g. after the browser logs out, or on a second character of the same account).

Accept: gate green (Rust + node); live: /run with a character override really drives that character; the panel sends real_id and shows the refusal honestly when the browser holds it.

The in-game Rust CODE pane spawns a separate bot process that logs in as the character pinned in the serve’s creds file (Rusty via dev/.local), so code written in CODE never targets the character the browser is playing. Fix: the panel sends the game page’s current character id (real_id) with /run; al serve runs the child as *that* character (character override on the request). The character id is not secret — the auth token still comes only from the local creds file and never crosses the page, backend, or cookie. Constraint (verified live): the game server allows one live session per character (node/server.js ingame guard, msince < 120 minutes). While the browser holds the character, the bot answers a plain cannot log in: … ingame — the same surface as any refused handshake. The bot plays the character while it is released (e.g. after the browser logs out, or on a second character of the same account). Accept: gate green (Rust + node); live: /run with a character override really drives that character; the panel sends real_id and shows the refusal honestly when the browser holds it.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
sleepy/adventureland_mongodb#43
No description provided.