Compare commits
2
Commits
6f7897b124
...
51678b4315
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
51678b4315 | ||
|
|
12d4b35404 |
@@ -18,7 +18,7 @@
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
botfights-arena:
|
botfights-arena:
|
||||||
image: localhost:3000/lfg2025/botfights:1.1.0
|
image: localhost:3000/lfg2025/botfights:1.2.0
|
||||||
container_name: botfights-arena
|
container_name: botfights-arena
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
ports:
|
||||||
@@ -26,8 +26,8 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- botfights-arena-data:/app/server/data
|
- botfights-arena-data:/app/server/data
|
||||||
# Explicit override (not just relying on the image's baked-in HEALTHCHECK):
|
# Explicit override (not just relying on the image's baked-in HEALTHCHECK):
|
||||||
# the currently published 1.1.0 tag predates the Dockerfile's HEALTHCHECK
|
# the currently published 1.1.0 tag predated the Dockerfile's HEALTHCHECK
|
||||||
# directive, so `docker ps` shows no health status without this.
|
# directive; kept for continuity across image rolls.
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "node", "-e", "fetch('http://localhost:9100/api/health').then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))"]
|
test: ["CMD", "node", "-e", "fetch('http://localhost:9100/api/health').then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))"]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
@@ -39,15 +39,15 @@ services:
|
|||||||
- PORT=9100
|
- PORT=9100
|
||||||
- FIGHT_LOOP_ENABLED=true
|
- FIGHT_LOOP_ENABLED=true
|
||||||
- PUBLIC_ARENA_URL=https://botfights.archipelago-foundation.org
|
- PUBLIC_ARENA_URL=https://botfights.archipelago-foundation.org
|
||||||
|
# TRUSTED_PROXY=1 since 2026-07-30: the arena now sits behind
|
||||||
|
# nginx-proxy-manager at https://botfights.archipelago-foundation.org
|
||||||
|
# (Let's Encrypt cert, live). The app trusts X-Forwarded-For from NPM
|
||||||
|
# for its per-IP rate limiting instead of the raw socket peer (which
|
||||||
|
# would otherwise see every request as coming from NPM's own IP).
|
||||||
- TRUSTED_PROXY=1
|
- TRUSTED_PROXY=1
|
||||||
# Auth — value comes from the host .env, never hardcoded here.
|
# Auth — value comes from the host .env, never hardcoded here.
|
||||||
# Generated on VPS2 with: openssl rand -hex 32 (see docs/arena-deployment.md)
|
# Generated on VPS2 with: openssl rand -hex 32 (see docs/arena-deployment.md)
|
||||||
- JWT_SECRET=${JWT_SECRET}
|
- JWT_SECRET=${JWT_SECRET}
|
||||||
# Deliberately OMITTED: TRUSTED_PROXY
|
|
||||||
# No NPM/reverse-proxy sits in front of this instance (plain HTTP on the
|
|
||||||
# raw port, user decision 2026-07-30 — no DNS/TLS this phase). Clients hit
|
|
||||||
# :9100 directly, so the app's rate-limit middleware must key off the real
|
|
||||||
# TCP socket peer IP, not a forwarded header a direct caller could forge.
|
|
||||||
- BOTFIGHTS_CREATOR_PUBKEYS=${BOTFIGHTS_CREATOR_PUBKEYS:-da5e0c1b646bdb13c2300f805b0ca3e5afe5b052c594ce78bac8978d21c3fa39}
|
- BOTFIGHTS_CREATOR_PUBKEYS=${BOTFIGHTS_CREATOR_PUBKEYS:-da5e0c1b646bdb13c2300f805b0ca3e5afe5b052c594ce78bac8978d21c3fa39}
|
||||||
# Deliberately OMITTED: this instance IS the upstream — never point it at
|
# Deliberately OMITTED: this instance IS the upstream — never point it at
|
||||||
# another arena.
|
# another arena.
|
||||||
|
|||||||
@@ -240,9 +240,22 @@ clean against the regenerated lockfile.
|
|||||||
| Field | Value |
|
| Field | Value |
|
||||||
|---|---|
|
|---|---|
|
||||||
| Tag | `146.59.87.168:3000/lfg2025/botfights:1.2.0` |
|
| Tag | `146.59.87.168:3000/lfg2025/botfights:1.2.0` |
|
||||||
| Digest | `sha256:5470019a...c1b6` (short form; full digest recorded in `.planning/phases/09-botfights-platform-upgrade/09-05-SUMMARY.md` — re-derive any time with `skopeo inspect` above) |
|
| Digest | `sha256:854ea299...26e144` (short form; full digest recorded in `.planning/phases/09-botfights-platform-upgrade/09-05-SUMMARY.md` — re-derive any time with `skopeo inspect` above) |
|
||||||
| Built from | `botfight` repo `main` @ `2a343ac` (HEAD at build time, matches `origin/main`) |
|
| Built from | `botfight` repo `main` @ the commit carrying the `GET /api/fights/poll` route-order fix below (`2a343ac` + fix commit) |
|
||||||
| Local smoke test | `/api/health` → `{"status":"ok",...}`; `/api/docs/prompt` → 200 `text/markdown`; `/api/auth/me` (no auth) → 401 |
|
| Local smoke test | `/api/health` → `{"status":"ok",...}`; `/api/docs/prompt` → 200 `text/markdown`; `/api/auth/me` (no auth) → 401; `/api/fights/poll` (registered bot) → 200 `{"pending":false}` |
|
||||||
|
|
||||||
|
**Deviation fixed in the same build pass:** `GET /api/fights/poll` (the
|
||||||
|
polling protocol BOT-02's unified prompt documents) was pre-existing-broken
|
||||||
|
— a `GET /:id` dynamic route registered earlier in `server/src/routes/fights.ts`
|
||||||
|
shadowed the later-registered static `GET /poll` route, so any polling bot's
|
||||||
|
poll request was matched as a fight-id lookup for id `"poll"` and always
|
||||||
|
returned `404 {"error":"Fight not found."}`. Reproduced independently on a
|
||||||
|
throwaway container with a fresh DB (not an artifact of the arena's seeded
|
||||||
|
data) before fixing. Fixed by moving the `/poll` and `/poll/respond` route
|
||||||
|
registrations above `/:id` in the router. This was necessary to meet this
|
||||||
|
plan's own acceptance criterion (bot auth via `GET /api/fights/poll` against
|
||||||
|
the public arena) and to make BOT-02's unified prompt's polling-mode
|
||||||
|
documentation actually true.
|
||||||
|
|
||||||
## Rolling the image tag
|
## Rolling the image tag
|
||||||
|
|
||||||
|
|||||||
+56
-49
@@ -88,6 +88,62 @@ fightsRouter.get('/', async (c) => {
|
|||||||
return c.json(enriched)
|
return c.json(enriched)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
// --- Polling API (for bots that don't expose a public URL) ---
|
||||||
|
// NOTE: these two static routes (/poll, /poll/respond) MUST be registered
|
||||||
|
// before the dynamic GET /:id route below — Hono resolves same-shape
|
||||||
|
// single-segment routes in registration order, so a GET /:id registered
|
||||||
|
// first would otherwise shadow GET /poll (a literal request for
|
||||||
|
// GET /api/fights/poll would be matched as id="poll", a lookup that always
|
||||||
|
// 404s "Fight not found."). This was a real pre-existing bug: polling bots
|
||||||
|
// could never receive a challenge. Fixed 2026-07-31 (phase 09-05).
|
||||||
|
|
||||||
|
// Poll for a pending challenge (bot authenticates with id+secret)
|
||||||
|
fightsRouter.get('/poll', rateLimit(1_000, 30), async (c) => {
|
||||||
|
const botOrRes = await authenticateBot(c)
|
||||||
|
if (botOrRes instanceof Response) return botOrRes
|
||||||
|
const bot = botOrRes
|
||||||
|
const challenge = getPendingPollChallenge(bot.botId)
|
||||||
|
|
||||||
|
if (!challenge) {
|
||||||
|
return c.json({ pending: false })
|
||||||
|
}
|
||||||
|
|
||||||
|
return c.json({
|
||||||
|
pending: true,
|
||||||
|
fight_id: challenge.fightId,
|
||||||
|
round: challenge.roundNumber,
|
||||||
|
type: challenge.type,
|
||||||
|
challenge: challenge.prompt,
|
||||||
|
constraints: challenge.constraints,
|
||||||
|
opponent: challenge.opponent,
|
||||||
|
arena: challenge.arena,
|
||||||
|
arena_modifier: challenge.arenaModifier,
|
||||||
|
remaining_ms: challenge.remainingMs,
|
||||||
|
scoring: challenge.scoring,
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|
||||||
|
// Submit answer to a pending poll challenge
|
||||||
|
fightsRouter.post('/poll/respond', async (c) => {
|
||||||
|
const botOrRes = await authenticateBot(c)
|
||||||
|
if (botOrRes instanceof Response) return botOrRes
|
||||||
|
const bot = botOrRes
|
||||||
|
const parsed = respondSchema.safeParse(await c.req.json().catch(() => ({})))
|
||||||
|
|
||||||
|
if (!parsed.success) {
|
||||||
|
return c.json({ error: 'Answer is required (string, 1-2000 chars).' }, 400)
|
||||||
|
}
|
||||||
|
|
||||||
|
const { answer, trashTalk } = parsed.data
|
||||||
|
const accepted = submitPollResponse(bot.botId, answer, trashTalk)
|
||||||
|
|
||||||
|
if (!accepted) {
|
||||||
|
return c.json({ error: 'No pending challenge. Either timed out or no active fight.' }, 404)
|
||||||
|
}
|
||||||
|
|
||||||
|
return c.json({ accepted: true })
|
||||||
|
})
|
||||||
|
|
||||||
// Get a single fight with rounds and bot details
|
// Get a single fight with rounds and bot details
|
||||||
fightsRouter.get('/:id', async (c) => {
|
fightsRouter.get('/:id', async (c) => {
|
||||||
const id = c.req.param('id')
|
const id = c.req.param('id')
|
||||||
@@ -357,55 +413,6 @@ fightsRouter.post('/:fightId/respond/:botId', async (c) => {
|
|||||||
return c.json({ accepted: true, correct })
|
return c.json({ accepted: true, correct })
|
||||||
})
|
})
|
||||||
|
|
||||||
// --- Polling API (for bots that don't expose a public URL) ---
|
|
||||||
|
|
||||||
// Poll for a pending challenge (bot authenticates with id+secret)
|
|
||||||
fightsRouter.get('/poll', rateLimit(1_000, 30), async (c) => {
|
|
||||||
const botOrRes = await authenticateBot(c)
|
|
||||||
if (botOrRes instanceof Response) return botOrRes
|
|
||||||
const bot = botOrRes
|
|
||||||
const challenge = getPendingPollChallenge(bot.botId)
|
|
||||||
|
|
||||||
if (!challenge) {
|
|
||||||
return c.json({ pending: false })
|
|
||||||
}
|
|
||||||
|
|
||||||
return c.json({
|
|
||||||
pending: true,
|
|
||||||
fight_id: challenge.fightId,
|
|
||||||
round: challenge.roundNumber,
|
|
||||||
type: challenge.type,
|
|
||||||
challenge: challenge.prompt,
|
|
||||||
constraints: challenge.constraints,
|
|
||||||
opponent: challenge.opponent,
|
|
||||||
arena: challenge.arena,
|
|
||||||
arena_modifier: challenge.arenaModifier,
|
|
||||||
remaining_ms: challenge.remainingMs,
|
|
||||||
scoring: challenge.scoring,
|
|
||||||
})
|
|
||||||
})
|
|
||||||
|
|
||||||
// Submit answer to a pending poll challenge
|
|
||||||
fightsRouter.post('/poll/respond', async (c) => {
|
|
||||||
const botOrRes = await authenticateBot(c)
|
|
||||||
if (botOrRes instanceof Response) return botOrRes
|
|
||||||
const bot = botOrRes
|
|
||||||
const parsed = respondSchema.safeParse(await c.req.json().catch(() => ({})))
|
|
||||||
|
|
||||||
if (!parsed.success) {
|
|
||||||
return c.json({ error: 'Answer is required (string, 1-2000 chars).' }, 400)
|
|
||||||
}
|
|
||||||
|
|
||||||
const { answer, trashTalk } = parsed.data
|
|
||||||
const accepted = submitPollResponse(bot.botId, answer, trashTalk)
|
|
||||||
|
|
||||||
if (!accepted) {
|
|
||||||
return c.json({ error: 'No pending challenge. Either timed out or no active fight.' }, 404)
|
|
||||||
}
|
|
||||||
|
|
||||||
return c.json({ accepted: true })
|
|
||||||
})
|
|
||||||
|
|
||||||
// SSE stream for live fight events
|
// SSE stream for live fight events
|
||||||
fightsRouter.get('/:id/stream', (c) => {
|
fightsRouter.get('/:id/stream', (c) => {
|
||||||
const fightId = c.req.param('id')
|
const fightId = c.req.param('id')
|
||||||
|
|||||||
Reference in New Issue
Block a user