Repository navigation
Make Spymasters necessary to guard secrets and receive reports - #111
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (10)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe espionage service now treats factions without an eligible, living Spymaster as unguarded. Unguarded factions expose exact information and do not receive reports about protected factions. Report access and generation require active Spymasters, and the office and report displays reflect these rules. ChangesSpymaster protection and intelligence reports
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant ObserverFaction
participant EspionageService
participant TargetFaction
participant CachedReports
ObserverFaction->>EspionageService: Request report refresh
EspionageService->>ObserverFaction: Check for active Spymaster
EspionageService->>TargetFaction: Check for active Spymaster
EspionageService->>CachedReports: Generate report when both factions qualify
Merge Risk: ⚪ Minimal · up to No actionable issue remains from this review. The change is mergeable after normal deployment checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The intended information-sharing change preserves the inspected management restrictions, but it also widens a character-name fallback that can reveal Minecraft account names to ordinary foreign viewers. Cached-report behavior is documented, while some live-menu and runtime behavior remains unconfirmed. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
Comment |
Factions without an eligible, living Spymaster now expose exact faction and guild information through the existing viewing bypass path. A faction without its own eligible Spymaster receives no daily reports about protected foreign factions, including previously cached findings. Its report header reads Absent and explains that no findings reach the vacant office's court.
This covers menus, full rosters, ledgers and wealth rankings. An eligible zero-aptitude Spymaster still protects information. Public viewing does not grant faction membership, office management, or private sabotage access; Minecraft account names remain exclusive to the staff bypass. Removal controls warn that faction and guild information will become public.
Unprotected targets and observers are excluded from daily report generation and staff regeneration. Existing appointment costs, stability settings and faction data formats remain unchanged; the deployment will preserve the user's reduced Main appointment penalties.
Validation: clean Java 21
mvn clean verifypassed all 2,692 tests, and runtime JAR validation passed. Regression coverage includes vacancy, permanent character death, departed members, ineligible solo leaders, zero aptitude, cached report suppression, exact rankings and management restrictions. TFMCDev01 menu checks passed for exact public faction/guild views, rosters, government, training, ledgers, read-only offices and the shared Absent report header. Probe factions were deleted, and aptitude/config checksums are unchanged. Dev used a combined build preserving its existing pending leader-character export changes (2,703 tests); the isolated PR build passed all 2,692 tests. CodeRabbit approved the latest commit e5e43f0.