Skip to content

bug: harden website chat sends (auth, 2000-char cap, no relay of rejected messages) - #435

Merged
lukepolo merged 2 commits into
mainfrom
bug/chat-send-hardening
Sep 29, 2026
Merged

lukepolo merged 2 commits into
mainfrom
bug/chat-send-hardening

Conversation

@lukepolo

@lukepolo lukepolo commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Hardens website chat sends: a message the room refused was still relayed into the live game over RCON, so any signed-in socket could print into any match.

  • Relay to the game server only when sendMessageToChat accepted the message
  • Re-check room membership on every send, not just on join (a player swapped out mid-match, a DM after an unfriend)
  • Keep strangers out of matchmaking match chat: is_organizer is NULL there, so the old === false check let everyone in
  • Ignore non-string, empty and unauthenticated sends; refuse over 2000 chars; clamp lines relayed to the game to 240 code points
  • Fall back to the player's own role or name when only one of them is cached; store source and a string steam_id on every message
  • New socket events: lobby:chat takes an optional requestId; chat:ack {requestId, messageId} and chat:error {code, max?, requestId?} out

Merge/deploy: 🔒 security. Pairs with 5stackgg/web#610.

Tests: every fix fails its test when reverted: refused-send relay, null-organizer join and send, per-send membership (lineup swap, DM after unfriend), role/name fallback, non-string crash, unauthenticated socket, 2000 cap, RCON clamp, BigInt steam id. Based on DEAFCS c76bba393

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant