6 Commits
Author SHA1 Message Date
FrankandClaude Sonnet 5 ba45e06972 Remove |raw from login error message rendering
Not exploitable today - the only custom auth message data is a
hardcoded resend link - but |raw on a translated exception message is
a latent XSS pattern if a future change ever threads user input
through the auth exception's message data. Twig's default
autoescaping is sufficient here.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-10 21:41:53 +02:00
FrankandClaude Sonnet 5 2913b8d2a2 Add CSRF protection, login throttling, and invite-code rate limiting
The admin panel already checked CSRF tokens on destructive actions,
but the player-facing raw HTML forms (create/join/leave/start
session, toggle ready, lobby chat, feedback) had none - cookie
SameSite=Lax blunts classic cross-site auto-submit attacks but isn't
a substitute for real tokens. Adds matching csrf_token()/
isCsrfTokenValid() checks to all of them.

Also adds login_throttling (5 attempts/15 min) to stop unlimited
password guessing, and a per-user rate limiter (10/min) on the
invite-code join endpoint, since invite codes are only 32-bit and
had no protection against brute-forcing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-10 21:41:47 +02:00
FrankandClaude Sonnet 5 335697e520 Update dependencies to patch known CVEs
composer audit reported 37 advisories across 15 packages, including
high-severity ones in symfony/security-http. Ran composer update
within the existing 7.4.* constraints - composer audit now reports
zero advisories. Also adds symfony/rate-limiter, needed for login
throttling and invite-code rate limiting in the next commit.

Flex removed a stale, non-functional sendgrid notifier config left
over from before the app switched to Mailgun as part of the sync.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-10 21:41:36 +02:00
FrankandClaude Sonnet 5 daa37390d0 Fix path traversal via username in session log file paths
Registration only validated username with NotBlank, so a username
like "../../../../public/x" got concatenated directly into a
filesystem path for both writing (game activity logs) and reading
(admin log viewer) - reachable from the public webroot since public/
is a few directories up from where those logs are stored.

Adds a character-set validator (letters, numbers, underscore, hyphen)
to registration and admin user editing going forward, and sanitizes
at the point of use (Player::getLogFileBasename()) so any
already-stored unsafe username can't escape the log directory either.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-10 21:41:25 +02:00
FrankandClaude Sonnet 5 a9cb0fa57f Turn admin lobby chat panel into a tab
The lobby chat was a standalone card sitting above the per-player log
tabs. Folds it into the same tab bar as the first (default-active)
tab instead, so the session log view has one consistent tab strip.
The tab-switching script now toggles by an .admin-tab-panel class
instead of assuming every panel's id starts with "player-", since
that's no longer true.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-10 16:48:06 +02:00
FrankandClaude Sonnet 5 2bfc2aca1a Keep pregame lobby chat open for an hour after the game ends
The chat used to disappear the moment a session left CREATED status.
Sessions now record a finishedAt timestamp when they're won or lost,
and the lobby (with chat) stays reachable via /game/{session} for an
hour afterward instead of immediately redirecting to the win/lose
feedback page. The lobby template shows a distinct "game finished"
header with a link to that feedback page during this window.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-10 16:47:57 +02:00
26 changed files with 678 additions and 435 deletions
+1 -1
View File
@@ -5,7 +5,7 @@ document.addEventListener('DOMContentLoaded', () => {
}
const activate = (id) => {
document.querySelectorAll('[id^="player-"]').forEach(el => el.style.display = 'none');
document.querySelectorAll('.admin-tab-panel').forEach(el => el.style.display = 'none');
const target = document.getElementById(id);
if (target) {
target.style.display = 'block';
+1
View File
@@ -34,6 +34,7 @@
"symfony/process": "7.4.*",
"symfony/property-access": "7.4.*",
"symfony/property-info": "7.4.*",
"symfony/rate-limiter": "7.4.*",
"symfony/runtime": "7.4.*",
"symfony/security-bundle": "7.4.*",
"symfony/serializer": "7.4.*",
Generated
+376 -317
View File
File diff suppressed because it is too large Load Diff
+6
View File
@@ -15,6 +15,12 @@ framework:
storage_factory_id: session.storage.factory.native
save_path: '%kernel.project_dir%/var/sessions/%kernel.environment%'
rate_limiter:
invite_code_join:
policy: 'sliding_window'
limit: 10
interval: '1 minute'
when@prod:
framework:
session:
+12 -13
View File
@@ -1,13 +1,12 @@
framework:
notifier:
chatter_transports:
texter_transports:
sendgrid: '%env(MAILER_DSN)%'
channel_policy:
# use chat/slack, chat/telegram, sms/twilio or sms/nexmo
urgent: ['email']
high: ['email']
medium: ['email']
low: ['email']
admin_recipients:
- { email: admin@example.com }
framework:
notifier:
chatter_transports:
texter_transports:␍
channel_policy:
# use chat/slack, chat/telegram, sms/twilio or sms/nexmo
urgent: ['email']
high: ['email']
medium: ['email']
low: ['email']
admin_recipients:
- { email: admin@example.com }
+3
View File
@@ -22,6 +22,9 @@ security:
enable_csrf: true
username_parameter: username
password_parameter: password
login_throttling:
max_attempts: 5
interval: '15 minutes'
logout:
path: app_logout
# where to redirect after logout
+26
View File
@@ -0,0 +1,26 @@
<?php
declare(strict_types=1);
namespace DoctrineMigrations;
use Doctrine\DBAL\Schema\Schema;
use Doctrine\Migrations\AbstractMigration;
final class Version20260810130000 extends AbstractMigration
{
public function getDescription(): string
{
return 'Add finished_at column to session table';
}
public function up(Schema $schema): void
{
$this->addSql('ALTER TABLE session ADD finished_at DATETIME DEFAULT NULL');
}
public function down(Schema $schema): void
{
$this->addSql('ALTER TABLE session DROP finished_at');
}
}
+2 -3
View File
@@ -54,11 +54,10 @@ final class GameAdminController extends AbstractController
{
$playersLogs = [];
foreach ($session->getPlayers() as $player) {
$username = $player->getUser()->getUsername();
$logFile = $this->projectDir . '/var/log/sessions/' . $session->getId() . '/' . $username . '.txt';
$logFile = $this->projectDir . '/var/log/sessions/' . $session->getId() . '/' . $player->getLogFileBasename() . '.txt';
$playersLogs[] = [
'username' => $username,
'username' => $player->getUser()->getUsername(),
'logs' => file_exists($logFile) ? file_get_contents($logFile) : '',
];
}
@@ -35,6 +35,7 @@ final class GameAdminSessionController extends AbstractController
}
$session->setStatus(SessionStatus::LOST);
$session->setFinishedAt(new \DateTime());
$em->flush();
$this->addFlash('success', sprintf('Session #%d closed.', $session->getId()));
@@ -43,6 +43,7 @@ final class GameApiController extends AbstractController
if ($session->getStatus() === SessionStatus::PLAYING) {
if ($session->getTimer() !== null && $now >= $session->getTimer()) {
$session->setStatus(SessionStatus::LOST);
$session->setFinishedAt(new \DateTime());
$this->entityManager->persist($session);
$this->entityManager->flush();
$isFinished = true;
+48 -7
View File
@@ -22,6 +22,8 @@ use Symfony\Component\Routing\Annotation\Route;
use Symfony\Component\Security\Http\Attribute\IsGranted;
use Symfony\Component\ExpressionLanguage\Expression;
use Symfony\Component\DependencyInjection\Attribute\Autowire;
use Symfony\Component\DependencyInjection\Attribute\Target;
use Symfony\Component\RateLimiter\RateLimiterFactoryInterface;
final class GameController extends AbstractController
{
@@ -39,13 +41,20 @@ final class GameController extends AbstractController
GameRepository $gameRepository,
SessionRepository $sessionRepository,
GameDashboardService $dashboardService,
Security $security
Security $security,
#[Target('invite_code_join')]
RateLimiterFactoryInterface $inviteCodeJoinLimiter
): Response {
$user = $security->getUser();
$isAdmin = $this->isGranted('ROLE_ADMIN');
if ($request->isMethod('POST')) {
if ($request->request->has('create_session')) {
if (!$this->isCsrfTokenValid('create_session', $request->request->get('_token'))) {
$this->addFlash('error', 'Invalid CSRF token.');
return $this->redirectToRoute('game_dashboard');
}
$gameId = $request->request->get('game_id');
$game = $gameRepository->find($gameId);
@@ -55,6 +64,17 @@ final class GameController extends AbstractController
}
}
} elseif ($request->request->has('join_session')) {
if (!$this->isCsrfTokenValid('join_session', $request->request->get('_token'))) {
$this->addFlash('error', 'Invalid CSRF token.');
return $this->redirectToRoute('game_dashboard');
}
$limiter = $inviteCodeJoinLimiter->create($user->getUserIdentifier());
if (!$limiter->consume(1)->isAccepted()) {
$this->addFlash('error', 'Too many attempts. Please wait a moment and try again.');
return $this->redirectToRoute('game_dashboard');
}
$inviteCode = $request->request->get('invite_code');
if ($dashboardService->joinSession($inviteCode, $user)) {
$this->addFlash('success', 'Joined session successfully!');
@@ -70,6 +90,11 @@ final class GameController extends AbstractController
return $this->redirectToRoute('game_dashboard');
}
if (!$this->isCsrfTokenValid('create_invite_' . $session->getId(), $request->request->get('_token'))) {
$this->addFlash('error', 'Invalid CSRF token.');
return $this->redirectToRoute('game_dashboard');
}
$inviteCode = $dashboardService->generateInviteCode($session, $user, $isAdmin);
if ($inviteCode) {
$this->addFlash('success', 'Invite link created: ' . $inviteCode);
@@ -79,6 +104,11 @@ final class GameController extends AbstractController
$session = $sessionRepository->find($sessionId);
if ($session) {
if (!$this->isCsrfTokenValid('leave_session_' . $session->getId(), $request->request->get('_token'))) {
$this->addFlash('error', 'Invalid CSRF token.');
return $this->redirectToRoute('game_dashboard');
}
if ($dashboardService->leaveSession($session, $user)) {
$this->addFlash('success', 'Left session successfully.');
} else {
@@ -90,6 +120,11 @@ final class GameController extends AbstractController
$session = $sessionRepository->find($sessionId);
if ($session) {
if (!$this->isCsrfTokenValid('start_session_' . $session->getId(), $request->request->get('_token'))) {
$this->addFlash('error', 'Invalid CSRF token.');
return $this->redirectToRoute('game_dashboard');
}
if ($dashboardService->startSession($session)) {
$this->addFlash('success', 'Session started! Screens have been assigned.');
} else {
@@ -127,7 +162,9 @@ final class GameController extends AbstractController
$player = $playerRepository->findOneBy(['session' => $session, 'user' => $user]);
if ($request->isMethod('POST') && $request->request->has('toggle_ready')) {
if (!$user->isVerified()) {
if (!$this->isCsrfTokenValid('toggle_ready_' . $session->getId(), $request->request->get('_token'))) {
$this->addFlash('error', 'Invalid CSRF token.');
} elseif (!$user->isVerified()) {
$this->addFlash('error', 'You must verify your email address before you can mark yourself as ready.');
} else {
$dashboardService->toggleReady($session, $user);
@@ -137,19 +174,23 @@ final class GameController extends AbstractController
}
if ($request->isMethod('POST') && $request->request->has('expire_ready')) {
$dashboardService->expireOwnReadyIfDue($session, $user);
if ($this->isCsrfTokenValid('expire_ready_' . $session->getId(), $request->request->get('_token'))) {
$dashboardService->expireOwnReadyIfDue($session, $user);
}
return $this->redirectToRoute('game', ['session' => $session->getId()]);
}
if ($request->isMethod('POST') && $request->request->has('send_message')) {
$dashboardService->postLobbyMessage($session, $user, (string) $request->request->get('content', ''));
if ($this->isCsrfTokenValid('send_message_' . $session->getId(), $request->request->get('_token'))) {
$dashboardService->postLobbyMessage($session, $user, (string) $request->request->get('content', ''));
}
return $this->redirectToRoute('game', ['session' => $session->getId()]);
}
// Lazily pick up readiness changes from other players since our last request
$dashboardService->checkAllPlayersReady($session);
if ($session->getStatus() === SessionStatus::CREATED) {
if ($dashboardService->isLobbyChatOpen($session)) {
return $this->render('game/lobby.html.twig', [
'session' => $session,
'messages' => $dashboardService->getLobbyMessages($session),
@@ -215,7 +256,7 @@ final class GameController extends AbstractController
$user = $security->getUser();
$player = $playerRepository->findOneBy(['session' => $session, 'user' => $user]);
if ($request->isMethod('POST')) {
if ($request->isMethod('POST') && $this->isCsrfTokenValid('game_feedback_' . $session->getId(), $request->request->get('_token'))) {
$difficulty = $request->request->get('difficulty');
$entertaining = $request->request->get('entertaining');
$theme = $request->request->get('theme');
@@ -247,7 +288,7 @@ final class GameController extends AbstractController
$user = $security->getUser();
$player = $playerRepository->findOneBy(['session' => $session, 'user' => $user]);
if ($request->isMethod('POST')) {
if ($request->isMethod('POST') && $this->isCsrfTokenValid('game_feedback_' . $session->getId(), $request->request->get('_token'))) {
$difficulty = $request->request->get('difficulty');
$entertaining = $request->request->get('entertaining');
$theme = $request->request->get('theme');
+15
View File
@@ -66,4 +66,19 @@ class Player
return $this;
}
/**
* A filesystem-safe basename derived from the player's username, for use when
* building per-player log file paths. Usernames are validated to only contain
* safe characters at registration time, but this sanitizes defensively too, so
* a path segment can never traverse outside its intended directory regardless
* of what ends up stored on the user.
*/
public function getLogFileBasename(): string
{
$username = $this->user?->getUsername() ?? '';
$safe = preg_replace('/[^A-Za-z0-9_-]/', '_', $username);
return $safe !== null && $safe !== '' ? $safe : ('player-' . $this->id);
}
}
+15
View File
@@ -31,6 +31,9 @@ class Session
#[ORM\Column(type: Types::DATETIME_MUTABLE)]
private ?\DateTimeInterface $created = null;
#[ORM\Column(type: Types::DATETIME_MUTABLE, nullable: true)]
private ?\DateTimeInterface $finishedAt = null;
#[ORM\OneToMany(mappedBy: 'session', targetEntity: Player::class)]
private Collection $players;
@@ -97,6 +100,18 @@ class Session
return $this;
}
public function getFinishedAt(): ?\DateTimeInterface
{
return $this->finishedAt;
}
public function setFinishedAt(?\DateTimeInterface $finishedAt): static
{
$this->finishedAt = $finishedAt;
return $this;
}
/**
* @return Collection<int, Player>
*/
+25 -1
View File
@@ -24,6 +24,7 @@ final class GameDashboardService
{
private const READY_TIMEOUT_SECONDS = 60;
private const LOBBY_MESSAGE_MAX_LENGTH = 500;
private const LOBBY_CHAT_GRACE_PERIOD_SECONDS = 3600;
public function __construct(
private readonly GameRepository $gameRepository,
@@ -302,9 +303,32 @@ final class GameDashboardService
return $this->lobbyMessageRepository->findForSession($session);
}
/**
* The lobby chat is open while a session is still gathering players, and stays
* open for a grace period after the game ends so players can wrap up the
* conversation before it disappears.
*/
public function isLobbyChatOpen(Session $session): bool
{
if ($session->getStatus() === SessionStatus::CREATED) {
return true;
}
if (!in_array($session->getStatus(), [SessionStatus::WON, SessionStatus::LOST], true)) {
return false;
}
$finishedAt = $session->getFinishedAt();
if ($finishedAt === null) {
return false;
}
return (new \DateTime())->getTimestamp() - $finishedAt->getTimestamp() < self::LOBBY_CHAT_GRACE_PERIOD_SECONDS;
}
public function postLobbyMessage(Session $session, User $user, string $content): ?LobbyMessage
{
if ($session->getStatus() !== SessionStatus::CREATED) {
if (!$this->isLobbyChatOpen($session)) {
return null;
}
+2 -2
View File
@@ -107,14 +107,13 @@ class GameResponseService
private function logSessionActivity(Player $player, string $content): void
{
$sessionId = $player->getSession()->getId();
$username = $player->getUser()->getUsername();
$logDir = $this->projectDir . '/var/log/sessions/' . $sessionId;
if (!is_dir($logDir)) {
mkdir($logDir, 0777, true);
}
$logFile = $logDir . '/' . $username . '.txt';
$logFile = $logDir . '/' . $player->getLogFileBasename() . '.txt';
$timestamp = date('Y-m-d H:i:s');
$logMessage = sprintf("[%s] %s\n", $timestamp, $content);
@@ -1118,6 +1117,7 @@ class GameResponseService
}
$session->setStatus(SessionStatus::WON);
$session->setFinishedAt(new \DateTime());
$this->entityManager->persist($session);
$this->entityManager->flush();
+9 -1
View File
@@ -16,6 +16,7 @@ use Symfony\Component\OptionsResolver\OptionsResolver;
use Symfony\Component\Validator\Constraints\Email;
use Symfony\Component\Validator\Constraints\Length;
use Symfony\Component\Validator\Constraints\NotBlank;
use Symfony\Component\Validator\Constraints\Regex;
class AdminUserType extends AbstractType
{
@@ -26,7 +27,14 @@ class AdminUserType extends AbstractType
'constraints' => [new NotBlank(), new Email()],
])
->add('username', TextType::class, [
'constraints' => [new NotBlank(), new Length(min: 2, max: 180)],
'constraints' => [
new NotBlank(),
new Length(min: 2, max: 32),
new Regex(
pattern: '/^[A-Za-z0-9_-]+$/',
message: 'Username may only contain letters, numbers, underscores, and hyphens.',
),
],
])
->add('plainPassword', PasswordType::class, [
'mapped' => false,
+6
View File
@@ -16,6 +16,7 @@ use Symfony\Component\OptionsResolver\OptionsResolver;
use Symfony\Component\Validator\Constraints\IsTrue;
use Symfony\Component\Validator\Constraints\Length;
use Symfony\Component\Validator\Constraints\NotBlank;
use Symfony\Component\Validator\Constraints\Regex;
class RegistrationFormType extends AbstractType
{
@@ -26,6 +27,11 @@ class RegistrationFormType extends AbstractType
->add('username', TextType::class, [
'constraints' => [
new NotBlank(message: 'Please enter a username'),
new Length(min: 3, max: 32, minMessage: 'Your username should be at least {{ limit }} characters', maxMessage: 'Your username cannot be longer than {{ limit }} characters'),
new Regex(
pattern: '/^[A-Za-z0-9_-]+$/',
message: 'Your username may only contain letters, numbers, underscores, and hyphens.',
),
],
])
->add('plainPassword', RepeatedType::class, [
-9
View File
@@ -262,15 +262,6 @@
"config/routes/security.yaml"
]
},
"symfony/sendgrid-mailer": {
"version": "7.3",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "4.4",
"ref": "224aedffb66812dc2b0965dabc14d5f800941da6"
}
},
"symfony/stimulus-bundle": {
"version": "2.30",
"recipe": {
+74 -56
View File
@@ -10,9 +10,58 @@
<h1 style="margin: 0 0 0.25rem; font-size: 1.5rem; color: #0f172a;">{{ session.game.name }} — Session #{{ session.id }}</h1>
<p style="margin: 0 0 1.5rem; color: #64748b; font-size: 0.9rem;">{{ session.status.value }} · {{ session.players|length }} player(s) · Created {{ session.created|date('Y-m-d H:i') }}</p>
<div style="background: #fff; border-radius: 8px; box-shadow: 0 1px 3px rgba(0,0,0,.07); padding: 1.25rem; margin-bottom: 1.5rem;">
<h2 style="margin: 0 0 1rem; font-size: 1.1rem; color: #0f172a;">Pregame lobby chat</h2>
{# Tab buttons #}
<div style="display: flex; gap: 0; margin-bottom: 0; border-bottom: 1px solid #e2e8f0; overflow-x: auto; -webkit-overflow-scrolling: touch;">
<button
data-tab-target="lobby-chat-tab"
id="tab-lobby-chat"
style="
flex-shrink: 0;
white-space: nowrap;
padding: 0.6rem 1.25rem;
border: 1px solid #3b82f6;
border-bottom: 1px solid #fff;
background: #fff;
color: #1e40af;
font-size: 0.9rem;
font-weight: 600;
cursor: pointer;
border-radius: 6px 6px 0 0;
margin-bottom: -1px;
"
>Lobby Chat</button>
{% for playerLog in playersLogs %}
<button
data-tab-target="player-{{ loop.index }}"
id="tab-{{ loop.index }}"
style="
flex-shrink: 0;
white-space: nowrap;
padding: 0.6rem 1.25rem;
border: 1px solid #e2e8f0;
border-bottom: 1px solid #e2e8f0;
background: #f8fafc;
color: #64748b;
font-size: 0.9rem;
font-weight: 400;
cursor: pointer;
border-radius: 6px 6px 0 0;
margin-bottom: -1px;
"
>{{ playerLog.username }}</button>
{% endfor %}
</div>
{# Tab content #}
<div id="lobby-chat-tab" class="admin-tab-panel" style="
display: block;
background: #fff;
border: 1px solid #e2e8f0;
border-top: none;
border-radius: 0 0 8px 8px;
padding: 1.25rem;
box-shadow: 0 1px 3px rgba(0,0,0,.07);
">
{% if lobbyMessages is empty %}
<p style="margin: 0; color: #94a3b8;">No lobby chat messages for this session.</p>
{% else %}
@@ -28,59 +77,28 @@
{% endif %}
</div>
{% if playersLogs is empty %}
<div style="background: #fff; border-radius: 8px; padding: 2rem; text-align: center; color: #94a3b8; box-shadow: 0 1px 3px rgba(0,0,0,.07);">
No players in this session.
{% for playerLog in playersLogs %}
<div id="player-{{ loop.index }}" class="admin-tab-panel" style="
display: none;
background: #fff;
border: 1px solid #e2e8f0;
border-top: none;
border-radius: 0 0 8px 8px;
padding: 1.25rem;
box-shadow: 0 1px 3px rgba(0,0,0,.07);
">
<pre style="
background: #1e293b;
color: #e2e8f0;
padding: 1rem;
border-radius: 6px;
overflow-x: auto;
white-space: pre-wrap;
word-break: break-word;
font-size: 0.85rem;
line-height: 1.5;
margin: 0;
">{{ playerLog.logs ?: 'No logs found for this player.' }}</pre>
</div>
{% else %}
{# Tab buttons #}
<div style="display: flex; gap: 0; margin-bottom: 0; border-bottom: 1px solid #e2e8f0; overflow-x: auto; -webkit-overflow-scrolling: touch;">
{% for playerLog in playersLogs %}
<button
data-tab-target="player-{{ loop.index }}"
id="tab-{{ loop.index }}"
style="
flex-shrink: 0;
white-space: nowrap;
padding: 0.6rem 1.25rem;
border: 1px solid {{ loop.first ? '#3b82f6' : '#e2e8f0' }};
border-bottom: {{ loop.first ? '1px solid #fff' : '1px solid #e2e8f0' }};
background: {{ loop.first ? '#fff' : '#f8fafc' }};
color: {{ loop.first ? '#1e40af' : '#64748b' }};
font-size: 0.9rem;
font-weight: {{ loop.first ? '600' : '400' }};
cursor: pointer;
border-radius: 6px 6px 0 0;
margin-bottom: -1px;
"
>{{ playerLog.username }}</button>
{% endfor %}
</div>
{# Tab content #}
{% for playerLog in playersLogs %}
<div id="player-{{ loop.index }}" style="
display: {{ loop.first ? 'block' : 'none' }};
background: #fff;
border: 1px solid #e2e8f0;
border-top: none;
border-radius: 0 0 8px 8px;
padding: 1.25rem;
box-shadow: 0 1px 3px rgba(0,0,0,.07);
">
<pre style="
background: #1e293b;
color: #e2e8f0;
padding: 1rem;
border-radius: 6px;
overflow-x: auto;
white-space: pre-wrap;
word-break: break-word;
font-size: 0.85rem;
line-height: 1.5;
margin: 0;
">{{ playerLog.logs ?: 'No logs found for this player.' }}</pre>
</div>
{% endfor %}
{% endif %}
{% endfor %}
{% endblock %}
+5
View File
@@ -17,6 +17,7 @@
<div class="card-body">
{% if availableGames is not empty %}
<form method="post">
<input type="hidden" name="_token" value="{{ csrf_token('create_session') }}">
<select name="game_id" class="form-select mb-3">
{% for game in availableGames %}
<option value="{{ game.id }}">
@@ -40,6 +41,7 @@
<div class="card-header bg-secondary text-white">Join Session</div>
<div class="card-body">
<form method="post" class="d-flex gap-2">
<input type="hidden" name="_token" value="{{ csrf_token('join_session') }}">
<input type="text" name="invite_code" class="form-control" placeholder="Enter Invite Code" required>
<button type="submit" name="join_session" class="btn btn-primary text-nowrap">Join Session</button>
</form>
@@ -81,6 +83,7 @@
<code>{{ inviteCode }}</code>
{% else %}
<form method="post" class="d-inline">
<input type="hidden" name="_token" value="{{ csrf_token('create_invite_' ~ session.id) }}">
<input type="hidden" name="session_id" value="{{ session.id }}">
<button type="submit" name="create_invite" class="btn btn-sm btn-outline-secondary">Generate Invite</button>
</form>
@@ -91,12 +94,14 @@
{% if session.status.value == 'created' %}
{% if session.players|length >= session.game.numberOfPlayers %}
<form method="post" class="d-inline">
<input type="hidden" name="_token" value="{{ csrf_token('start_session_' ~ session.id) }}">
<input type="hidden" name="session_id" value="{{ session.id }}">
<button type="submit" name="start_session" class="btn btn-sm btn-success">Start Session</button>
</form>
{% endif %}
{% if session.timer == 0 %}
<form method="post" class="d-inline">
<input type="hidden" name="_token" value="{{ csrf_token('leave_session_' ~ session.id) }}">
<input type="hidden" name="session_id" value="{{ session.id }}">
<button type="submit" name="leave_session" class="btn btn-sm btn-outline-danger" onclick="return confirm('Are you sure you want to leave this session?')">Leave Session</button>
</form>
+44 -24
View File
@@ -1,38 +1,57 @@
{% extends 'layout/site.html.twig' %}
{% block title %}Waiting for players - {{ session.game.name }}{% endblock %}
{% set isCreated = session.status.value == 'created' %}
{% set isFinished = session.status.value in ['won', 'lost'] %}
{% block title %}{{ isCreated ? 'Waiting for players' : 'Post-game chat' }} - {{ session.game.name }}{% endblock %}
{% block body %}
<div class="row justify-content-center">
<div class="col-md-8">
<div class="card shadow-sm mb-4">
<div class="card-header bg-primary text-white">
<h3 class="card-title mb-0">Waiting for more players to join</h3>
</div>
<div class="card-body">
<h4>{{ session.game.name }}</h4>
<p>Share the invite code with your friends. Feel free to chat below while you wait &mdash; no need to reload the page.</p>
<div class="alert alert-info">
<strong>Players joined:</strong> {{ session.players|length }} / {{ session.game.numberOfPlayers }}
{% if isCreated %}
<div class="card shadow-sm mb-4">
<div class="card-header bg-primary text-white">
<h3 class="card-title mb-0">Waiting for more players to join</h3>
</div>
<div class="card-body">
<h4>{{ session.game.name }}</h4>
<p>Share the invite code with your friends. Feel free to chat below while you wait &mdash; no need to reload the page.</p>
<ul class="list-group mb-3">
{% for sessionPlayer in session.players %}
<li class="list-group-item">{{ sessionPlayer.user.username }}</li>
{% endfor %}
</ul>
<div class="alert alert-info">
<strong>Players joined:</strong> {{ session.players|length }} / {{ session.game.numberOfPlayers }}
</div>
{% if session.players|length >= session.game.numberOfPlayers %}
<form method="post" action="{{ path('game_dashboard') }}" class="mb-3">
<input type="hidden" name="session_id" value="{{ session.id }}">
<button type="submit" name="start_session" class="btn btn-success">Start Session</button>
</form>
{% endif %}
<ul class="list-group mb-3">
{% for sessionPlayer in session.players %}
<li class="list-group-item">{{ sessionPlayer.user.username }}</li>
{% endfor %}
</ul>
<a href="{{ path('game_dashboard') }}" class="btn btn-outline-secondary btn-sm">Back to Dashboard</a>
{% if session.players|length >= session.game.numberOfPlayers %}
<form method="post" action="{{ path('game_dashboard') }}" class="mb-3">
<input type="hidden" name="_token" value="{{ csrf_token('start_session_' ~ session.id) }}">
<input type="hidden" name="session_id" value="{{ session.id }}">
<button type="submit" name="start_session" class="btn btn-success">Start Session</button>
</form>
{% endif %}
<a href="{{ path('game_dashboard') }}" class="btn btn-outline-secondary btn-sm">Back to Dashboard</a>
</div>
</div>
</div>
{% elseif isFinished %}
<div class="card shadow-sm mb-4">
<div class="card-header {{ session.status.value == 'won' ? 'bg-success' : 'bg-secondary' }} text-white">
<h3 class="card-title mb-0">{{ session.status.value == 'won' ? 'You won!' : 'Game over' }}</h3>
</div>
<div class="card-body">
<h4>{{ session.game.name }}</h4>
<p>The game has ended, but the chat is still open for a little while &mdash; feel free to keep talking.</p>
<a href="{{ path(session.status.value == 'won' ? 'game_won' : 'game_lost', {session: session.id}) }}" class="btn btn-primary btn-sm">View results</a>
<a href="{{ path('game_dashboard') }}" class="btn btn-outline-secondary btn-sm">Back to Dashboard</a>
</div>
</div>
{% endif %}
<div class="card shadow-sm">
<div class="card-header">
@@ -53,6 +72,7 @@
{% if player %}
<form method="post" class="d-flex gap-2">
<input type="hidden" name="_token" value="{{ csrf_token('send_message_' ~ session.id) }}">
<input type="text" name="content" class="form-control" placeholder="Type a message&hellip;" maxlength="500" required autocomplete="off">
<button type="submit" name="send_message" class="btn btn-primary">Send</button>
</form>
+1
View File
@@ -78,6 +78,7 @@
<div class="feedback-form mt-4">
<h5>Feedback</h5>
<form method="post">
<input type="hidden" name="_token" value="{{ csrf_token('game_feedback_' ~ session.id) }}">
<div class="mb-3">
<label for="difficulty" class="form-label">How would you rate the difficulty? (<span id="difficulty-val">5</span>/10)</label>
<input type="range" class="form-range" min="1" max="10" step="1" id="difficulty" name="difficulty" value="5" oninput="document.getElementById('difficulty-val').innerText = this.value">
+2
View File
@@ -63,6 +63,7 @@
</div>
{% endif %}
<form method="post" class="mt-4">
<input type="hidden" name="_token" value="{{ csrf_token('toggle_ready_' ~ session.id) }}">
<input type="hidden" name="toggle_ready" value="0">
<div class="form-check form-switch mb-3">
<input class="form-check-input" type="checkbox" id="toggle_ready" name="toggle_ready" value="1" onchange="this.form.submit()" {{ isReady ? 'checked' : '' }} {{ not app.user.verified ? 'disabled' : '' }}>
@@ -87,6 +88,7 @@
</div>
<form id="expire-ready-form" method="post" style="display:none">
<input type="hidden" name="_token" value="{{ csrf_token('expire_ready_' ~ session.id) }}">
<input type="hidden" name="expire_ready" value="1">
</form>
+1
View File
@@ -78,6 +78,7 @@
<div class="feedback-form mt-4">
<h5>Feedback</h5>
<form method="post">
<input type="hidden" name="_token" value="{{ csrf_token('game_feedback_' ~ session.id) }}">
<div class="mb-3">
<label for="difficulty" class="form-label">How would you rate the difficulty? (<span id="difficulty-val">5</span>/10)</label>
<input type="range" class="form-range" min="1" max="10" step="1" id="difficulty" name="difficulty" value="5" oninput="document.getElementById('difficulty-val').innerText = this.value">
+1 -1
View File
@@ -6,7 +6,7 @@
<form method="post">
{% if error %}
<div class="alert alert-danger">
{{ error.messageKey|trans(error.messageData, 'security')|raw }}
{{ error.messageKey|trans(error.messageData, 'security') }}
{% if error.messageData['%resend_link%'] is defined %}
<a href="{{ error.messageData['%resend_link%'] }}">Resend activation link</a>
{% endif %}
+1
View File
@@ -74,6 +74,7 @@ class SessionLoggingTest extends TestCase
$player->method('getUser')->willReturn($user);
$player->method('getSession')->willReturn($session);
$player->method('getScreen')->willReturn(1);
$player->method('getLogFileBasename')->willReturn('player1');
$this->security->method('getUser')->willReturn($user);
$this->playerService->method('GetCurrentlyActiveAsPlayer')->willReturn($player);