feat(cardinal): authenticate game tokens scoped to organization/project - #1004
ryanditjia wants to merge 15 commits into
Conversation
There was a problem hiding this comment.
Review completed against the latest diff
Shadow auto-approve: would not auto-approve because issues were found.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 3 files
Shadow auto-approve: would not auto-approve because issues were found.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 2 files (changes from recent commits).
Shadow auto-approve: would not auto-approve because issues were found.
Re-trigger cubic
eafce1b to
949b9ec
Compare
There was a problem hiding this comment.
0 issues found across 4 files (changes from recent commits).
Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.
Re-trigger cubic
9ac3b9a to
e2cb5e4
Compare
❌ 1 Tests Failed:
View the top 1 failed test(s) by shortest run time
To view more test analytics, go to the Test Analytics Dashboard |
There was a problem hiding this comment.
All reported issues were addressed across 6 files (changes from recent commits).
Shadow auto-approve: would not auto-approve because issues were found.
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 2 files (changes from recent commits).
Shadow auto-approve: would not auto-approve because issues were found.
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 1 file (changes from recent commits).
Shadow auto-approve: would not auto-approve because issues were found.
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Shards reach Auth through an internal URL that differs from the public issuer. Signature, audience, and expiry still bind the token to Auth and this project. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…DK API Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
3254b70 to
820fd5d
Compare
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.
Re-trigger cubic
… SDK 0.4" This reverts commit 1289c71. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.
Re-trigger cubic
…rom shard addresses Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.
Re-trigger cubic
…erves Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Shadow auto-approve: would not auto-approve. Auto-approval skipped because cubic reviewed only this push, not the earlier force-push. Comment @cubic review to review the whole pull request.
Re-trigger cubic

Cardinal authenticates commands, queries, and event streams with a game token from Argus Auth, and identifies the caller by the stable player ID in its
subclaim. A guest who later saves progress to an account keeps the same ID, so game state keyed by it carries over.Companion to monorepo #778, which issues these tokens. Design: ADR-068.
What changes
<auth URL>/auth/jwks), be unexpired, have a non-emptysub, and haveaudequal to the shard'sorganization/project. Tokens for another game and ordinary account tokens are rejected. The issuer is not checked: there is one issuer, and its public URL differs from the in-cluster URL Cardinal uses.UserbecomesPlayer.PlayerFromContextreplacesUserFromContext. Game systems still read the caller fromcmd.Persona, which now carries the player ID; the wire field is not renamed here.CARDINAL_AUTH_MODE=DEV, the caller is taken from theX-Player-IDheader (wasX-Email).send_commandsendsX-Player-ID, from a newplayer_idargument that defaults tomcp-dev-player.docs/cardinal/client-integration.mdxshows the Unity SDK 0.5 auth API.Rollout
Deploy Auth from #778 first. A game moves to this engine release and Unity SDK 0.5 together: clients on the older SDK send tokens this version rejects.
Verification
go test ./pkg/cardinal/... ./cli/...passes after rebasing ontomain.Known limitation
Expiry is checked when a request or stream starts. An already-open stream is not cut off at expiry; the Unity SDK closes it client-side.
🤖 Generated with Claude Code