- mrpgi-vault (standalone crate): tiny signup/login/world-save service. Argon2 password hashes, random session cookies, JSON-file storage, naive per-IP rate limit, 4MB body cap. tiny_http, no framework, no db. Runs as a container on the dealgod network; nginx proxies /engine/api/ to it. - core: WorldBundle — a whole world (manifest + every room) as one JSON document, with World::to_bundle/apply_bundle. - web bridge: mrpgi_request_save / mrpgi_alloc / mrpgi_world_in exports + an mrpgi_world_saved JS plugin import; the page's SAVE button pulls the live world out of the running engine, LOAD swaps it back in. SAVE_REQUESTED is an AtomicBool on purpose — wasm's thread-less Mutex<bool> is a plain static to LLVM and release builds const-folded the read (the only writer is JS-visible, not IR-visible). - web UI: SIGN IN tab → create account (own username + password) / sign in / Save world / Load world / sign out. Session restores on revisit. Verified live end-to-end through Cloudflare: signup → save → reload → anonymous rejected; throwaway account removed after. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
19 lines
516 B
TOML
19 lines
516 B
TOML
[package]
|
|
name = "mrpgi-vault"
|
|
version = "0.1.0"
|
|
edition = "2021"
|
|
description = "The front door for monsterrobot.games/engine — tiny account + world-save service. Argon2 hashes, session cookies, JSON files on disk. No framework, no database."
|
|
|
|
# Standalone on purpose (not a member of the parent workspace): it ships to
|
|
# the VPS as a folder and builds there in a bare rust container.
|
|
[workspace]
|
|
|
|
[dependencies]
|
|
tiny_http = "0.12"
|
|
serde_json = "1"
|
|
argon2 = "0.5"
|
|
getrandom = "0.2"
|
|
|
|
[profile.release]
|
|
strip = true
|