Skip to content

feat(cardinal): authenticate game tokens scoped to organization/project - #1004

Open
ryanditjia wants to merge 15 commits into
mainfrom
ryandi/game-player-auth
Open

ryanditjia wants to merge 15 commits into
mainfrom
ryandi/game-player-auth

Conversation

@ryanditjia

@ryanditjia ryanditjia commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Cardinal authenticates commands, queries, and event streams with a game token from Argus Auth, and identifies the caller by the stable player ID in its sub claim. A guest who later saves progress to an account keeps the same ID, so game state keyed by it carries over.

Companion to monorepo #778, which issues these tokens. Design: ADR-068.

What changes

  • Token validation. A token must be signed by Auth's keys (EdDSA, fetched from <auth URL>/auth/jwks), be unexpired, have a non-empty sub, and have aud equal to the shard's organization/project. Tokens for another game and ordinary account tokens are rejected. The issuer is not checked: there is one issuer, and its public URL differs from the in-cluster URL Cardinal uses.
  • User becomes Player. PlayerFromContext replaces UserFromContext. Game systems still read the caller from cmd.Persona, which now carries the player ID; the wire field is not renamed here.
  • Dev mode. With CARDINAL_AUTH_MODE=DEV, the caller is taken from the X-Player-ID header (was X-Email).
  • CLI MCP. send_command sends X-Player-ID, from a new player_id argument that defaults to mcp-dev-player.
  • Docs. docs/cardinal/client-integration.mdx shows the Unity SDK 0.5 auth API.

Rollout

Deploy Auth from #778 first. A game moves to this engine release and Unity SDK 0.5 together: clients on the older SDK send tokens this version rejects.

Verification

  • go test ./pkg/cardinal/... ./cli/... passes after rebasing onto main.
  • Tests cover an untrusted signature, a non-EdDSA algorithm, a wrong or missing audience, a missing or past expiry, a missing subject, and the dev header.

Known limitation

Expiry is checked when a request or stream starts. An already-open stream is not cut off at expiry; the Unity SDK closes it client-side.

🤖 Generated with Claude Code

@claude

claude Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Code Review in progress

  • Gather context (diff, CLAUDE.md, related files)
  • Review auth changes in pkg/cardinal/service.go
  • Review tests
  • Post findings

View job run · ryandi/game-player-auth

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review completed against the latest diff

Shadow auto-approve: would not auto-approve because issues were found.

Re-trigger cubic

Comment thread pkg/cardinal/auth_internal_test.go
Comment thread pkg/cardinal/service.go

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Shadow auto-approve: would not auto-approve because issues were found.

Re-trigger cubic

Comment thread pkg/cardinal/auth_internal_test.go
Comment thread pkg/cardinal/auth_internal_test.go
Comment thread pkg/cardinal/service.go

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Shadow auto-approve: would not auto-approve because issues were found.

Re-trigger cubic

Comment thread pkg/cardinal/service.go
@ryanditjia ryanditjia changed the title feat(cardinal): authenticate stable game player identities feat(cardinal): authenticate players with game-scoped access tokens Sep 24, 2026
@ryanditjia
ryanditjia force-pushed the ryandi/game-player-auth branch from eafce1b to 949b9ec Compare September 29, 2026 16:13
@ryanditjia ryanditjia changed the title feat(cardinal): authenticate players with game-scoped access tokens feat(auth): add game player tokens and renewable CLI sessions Sep 29, 2026
@ryanditjia ryanditjia changed the title feat(auth): add game player tokens and renewable CLI sessions feat(cardinal): authenticate game tokens scoped to organization/project Oct 1, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 4 files (changes from recent commits).

Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.

Re-trigger cubic

@ryanditjia
ryanditjia force-pushed the ryandi/game-player-auth branch from 9ac3b9a to e2cb5e4 Compare October 1, 2026 16:52
@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

❌ 1 Tests Failed:

Tests completed Failed Passed Skipped
1665 1 1664 7
View the top 1 failed test(s) by shortest run time
github.com/argus-labs/world-engine/pkg/cardinal::TestAuthenticatorArgusAcceptsGamePlayerToken
Stack Traces | 0s run time
=== RUN   TestAuthenticatorArgusAcceptsGamePlayerToken
    auth_internal_test.go:23: 
        	Error Trace:	.../pkg/cardinal/auth_internal_test.go:23
        	Error:      	Received unexpected error:
        	            	HTTP error: 404 - 404 Not Found
        	            		cardinal.TestAuthenticatorArgusAcceptsGamePlayerToken:.../pkg/cardinal/auth_internal_test.go:22
        	            		cardinal.newAuthenticatorArgus:.../pkg/cardinal/service.go:758
        	Test:       	TestAuthenticatorArgusAcceptsGamePlayerToken
--- FAIL: TestAuthenticatorArgusAcceptsGamePlayerToken (0.00s)

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 6 files (changes from recent commits).

Shadow auto-approve: would not auto-approve because issues were found.
Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread docs/cardinal/client-integration.mdx Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Shadow auto-approve: would not auto-approve because issues were found.
Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread pkg/cardinal/service.go

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 1 file (changes from recent commits).

Shadow auto-approve: would not auto-approve because issues were found.
Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread docs/cardinal/client-integration.mdx
ryanditjia and others added 11 commits October 4, 2026 19:58
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Shards reach Auth through an internal URL that differs from the public
issuer. Signature, audience, and expiry still bind the token to Auth and
this project.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…DK API

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@ryanditjia
ryanditjia force-pushed the ryandi/game-player-auth branch from 3254b70 to 820fd5d Compare October 4, 2026 13:00
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 2 files (changes from recent commits).

Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.

Re-trigger cubic

… SDK 0.4"

This reverts commit 1289c71.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 2 files (changes from recent commits).

Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.

Re-trigger cubic

…rom shard addresses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.

Re-trigger cubic

…erves

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.

Re-trigger cubic

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants