Skip to content

Shop room: players open a shop from its journal entry - #170

Merged
keyxmakerx merged 1 commit into
mainfrom
claude/project-thread-5tj6tg
Oct 4, 2026
Merged

keyxmakerx merged 1 commit into
mainfrom
claude/project-thread-5tj6tg

Conversation

@keyxmakerx

Copy link
Copy Markdown
Owner

Fixes #169
Security implication: players get a new way to ask the GM's client for a shop room. The GM's client serves it only when that player can see the shop's journal entry but not edit it, because a player who owns an entry could write its shop link themselves. Goods are the same player-filtered list Chronicle's room route returns. Buying still runs as the player's matched Chronicle member.
Consumer-verified: Chronicle internal/plugins/syncapi/shop_api_handler.go GetShopRoom leaves out dm_only and player-hidden goods.
Foundry compatibility: hooks renderJournalEntrySheet (v13/v14) and renderJournalSheet (v12). Not yet run in a live world; the TESTING.md checks cover it.
Mockup: Sign-offs card "Shops in Foundry: open a shop from its journal entry" (foundry-shop-journal, v2). This PR waits on that card.

What this changes

Before: players could see a shop only while the GM was showing it from the Chronicle Sync window.

After: a shop's journal entry has an Open shop button in its title bar. The GM's button opens the GM room. A player's button opens the room on that player's screen only, and their basket works the same as before. With no GM online, the window says "The shop is closed". When the GM stops showing a shop, a room the player opened from the journal stays open. The GM's "Show to players" button is unchanged.

Why

Key Maker asked for the shop to live in its journal entry and be visible only to players who have access to it (#169).

How it works: the player's client sends a new open request over the existing encrypted relay (_shop-room-data.mjs accepts it with no body). ShopWidget._relayBuy checks the player's access to the journal. It then answers from the GM's open window, or from an unrendered room kept for that purpose. A room answer is allowed a larger size cap (MAX_ROOM_REPLY_CHARS), which no caller can raise. Buying is allowed for a shown shop, or for one whose journal the player can see.

Known limit: a room a player opened from the journal doesn't update live when someone else buys. It refreshes after that player's own purchase, or when they reopen it.

Test plan

  • node --test tools/test-*.mjs: 1173 pass, 0 fail, 2 skipped (the vendored-copy check needs CHRONICLE_DIR; with it set, test-shop-room is 16/16)
  • New tests: an open request carries nothing but the shop; a room answer fits the room cap, a buying answer keeps the small cap, and no caller can lift the cap
  • Manual checks in a Foundry world: new lines in TESTING.md → Shop Widget
  • CI passes

Tenet self-check

  • T-B1 security: the trust boundary is the GM's client. The sender is Foundry's socket sender, journal access is checked on the GM side, and replies are encrypted to the request's key
  • T-B2 plugin isolation: module only
  • T-B3 production UI: matches the signed mockup once the card is approved
  • T-B4 docs: .ai.md and TESTING.md updated

Generated by Claude Code

Shop journals get an "Open shop" title-bar button. The GM's opens the GM
room; a player's asks the active GM's client for the room, which serves it
only when that player can see the journal entry but not edit it. With no GM
online the window says the shop is closed. A player's journal-opened room
stays open when the GM stops showing the shop.

Fixes #169

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JRAx4Ex5fEHkxVB5Yaqw86
@keyxmakerx
keyxmakerx marked this pull request as ready for review October 4, 2026 23:35
@keyxmakerx
keyxmakerx merged commit b4c7906 into main Oct 4, 2026
3 checks passed
@keyxmakerx
keyxmakerx deleted the claude/project-thread-5tj6tg branch October 4, 2026 23:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Shop room: players open a shop from its journal entry

2 participants