fix(api): in-game identity resolution and link takeover ignore dead accounts

UserByMCUUID now resolves only live accounts: claim, menu, wake
authorization, op-login vouch and the QR link-status poll treat a
disabled or soft-deleted link holder exactly like an unlinked UUID
instead of a retired identity. VerifyLinkCode lets a soft-deleted
link be taken over by a fresh in-game code (the deleted account is
gone, e.g. a migrated source), while a disabled holder still 409s so
the lockout is not bypassable; failed attempts still do not consume
the code. Fake repo and pgint coverage pin both branches.
This commit is contained in:
Lemon-miaow committed 2026-09-23 05:40:29 +08:00
1 parent 3ffa3f5318
commit bb9798e32c
5 files changed
+182 -7

No files matched your search

+4
View File
@@ -251,6 +251,10 @@ type Repo interface {
// (spec §10 account_links), or ErrNotFound when the UUID is not linked. The
// internal-face wake uses it to apply the owner bypass for a player known only
// by UUID; an unlinked UUID simply falls through to the autostartPolicy gate.
// Only a LIVE account resolves (audit #33): a link whose account is disabled or
// soft-deleted carries no standing on the in-game doors — claim, menu, wake
// authorization, op-login vouch and the QR link-status poll all read a dead
// account exactly like an unlinked UUID, never as a retired identity.
UserByMCUUID(ctx context.Context, mcUUID string) (userID string, err error)
// RecordJoin updates last_active_at, clears reaper warnings, and auto-appends
// the UUID to the allowlist (spec §7 join-event, §9.4).