Skip to content

bug: check-in enforces the match's check-in setting - #490

Merged
lukepolo merged 1 commit into
mainfrom
bug/check-in-setting-enforcement
Oct 2, 2026
Merged

lukepolo merged 1 commit into
mainfrom
bug/check-in-setting-enforcement

Conversation

@lukepolo

@lukepolo lukepolo commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Players could check in by calling the check-in action directly even when the match's check-in setting didn't allow it, and enough of those check-ins pushed the match Live.

  • checkIntoMatch runs can_check_in for the caller's own session before anything else
  • Admins-only matches refuse non-admins, Captains matches refuse non-captains, and anyone outside the lineups is refused
  • It's the same rule the web uses to show the Check In button

From DEAFCS: DEAFCS/api-deafcs@047c9a60

checkIntoMatch only checked the match status, so in Admin mode a player
could still check in by calling the action directly (and enough of them
pushed the match Live), and in Captains mode any lineup player could.
It now evaluates can_check_in for the caller's own session.
@lukepolo
lukepolo merged commit 9cdefc0 into main Oct 2, 2026
2 checks passed
@lukepolo
lukepolo deleted the bug/check-in-setting-enforcement branch October 2, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant