Repo is now a monorepo:
- server/: the kaya backend, unchanged in behaviour, plus:
- GET /api/me for SPA session detection
- last_move recorded on every play and broadcast in the game state, so
clients can show who played which card the moment they play it
- legal_moves per hand card for the player on turn (rules stay
server-side)
- static catch-all route serving the compiled SPA with index.html
fallback; Tortoise context now bound only for /api/* requests
- configurable OIDC post-login/logout redirects for dev against trunk
- web/: Sycamore 0.9 + WASM frontend (trunk): login via the OIDC flow,
lobby (create match / join by code), live game page over websocket with
card images (CC0 woodcut napoletane deck), capture picker, move banner,
game-over overlay, match history and leaderboard pages
- server/Dockerfile gains a rust+trunk stage building web/dist; the single
app image serves the SPA; compose builds from the repo root with
overridable ports/OIDC env
Verified end-to-end against the compose stack: four OIDC logins, game
creation, three joins by code, websocket play with broadcasts to all
players and out-of-turn rejection. 51 backend tests, mypy and cargo tests
all green.
26 lines
878 B
Python
26 lines
878 B
Python
"""Whoami endpoint: lets the single-page app detect the login state."""
|
|
from __future__ import annotations
|
|
|
|
from kaya.core import HttpContext
|
|
from kaya.openapi import operation
|
|
|
|
from ..app import app, oidc_mixin
|
|
from ..auth import display_name, require_auth
|
|
from ..http import send_json
|
|
|
|
|
|
@app.GET("/api/me")
|
|
@operation(summary="Current user",
|
|
description="Returns the authenticated user's identity from the "
|
|
"session; 401 when not logged in.",
|
|
tags=["auth"],
|
|
responses={
|
|
200: {"description": "The current user"},
|
|
401: {"description": "Not logged in"},
|
|
})
|
|
@require_auth
|
|
async def me(ctx: HttpContext) -> None:
|
|
user = oidc_mixin.get_user(ctx)
|
|
assert user is not None # enforced by @require_auth
|
|
await send_json(ctx, 200, {"sub": user.sub, "name": display_name(user)})
|