Skip to content

Harden local servers and prepare repo for public promotion - #4

Open
DatMoshu wants to merge 1 commit into
mainfrom
promo-readiness
Open

DatMoshu wants to merge 1 commit into
mainfrom
promo-readiness

Conversation

@DatMoshu

@DatMoshu DatMoshu commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Change

  1. Fit Lab server guard (tools/fit-lab/run.py): the handler moved into make_handler() (testable; argparse now under main()). Every GET/HEAD/POST is checked with the same Host/Origin rule as Content Studio (127.0.0.1:<port> / localhost:<port>, optional matching Origin) and gets 403 otherwise. list_directory returns 404, so /data/, /builds/ and web folders are never listed. /api/build, /api/renders and /api/mapping now run inside the try, so a missing or bad manifest.json returns a JSON error. Manifest reads use UTF-8.
  2. builds.py: a mapping without the item's part raises a ValueError naming the part, item and mapping instead of a bare StopIteration.
  3. Client staging: client_import.stage() checks anim.mul/anim.idx, and equipment.stage_equipment() checks those plus art.mul, artidx.mul and tiledata.mul, before anything is created. If staging fails after the output folder exists (it always comes from this call, because stage() refuses an existing folder), that folder is removed so a retry with the same output works.
  4. Rebuild cleanup: if the patch merge fails, rebuild.py removes staging/<id> (the copy step is now inside the try as well). The Fit Lab RenderIndex skips patch-only jobs (blocks in job.json, which only patch jobs carry), so a patch can't be listed as the newest render for an item.
  5. Encoding/file-handle sweep: encoding='utf-8' on the JSON read_text/write_text calls in tools/fit-lab/*.py, tools/uo-content/pipeline.py, rebuild.py, equipment.py and client_import.py. with blocks in tools/vd/vdtool.py and tools/vd/mul2vd.py.
  6. .gitignore: /.playwright-mcp/.
  7. Franchise names removed from the outfit-lab demos (git mv): build_mario.py to build_overalls.py, test_mario.py to test_overalls.py, and build/review/test_spartan.py to *_plate_armor.py. Launchers are now overalls-lab.bat and plate-armor-lab.bat, and both call _shared/common.bat. Workspace output folders are now overalls-lab and plate-armor-lab. Wording is now "plumber-style overalls" and "sci-fi plate armor", and the "Halo energy sword" labels (also in build_tracksuit.py) became generic. git grep -iE "mario|spartan|master chief" returns nothing.
  8. docs/handoff.md: commercial pack names, the backup export path and the backup branch name are removed, and item names are now generic ("a back item", "a torso item"). It also notes the patch-job and staging cleanup. ROADMAP.md is new: a public UO parity roadmap with done/partial/open status for render gates 1-5, the open items and where help is wanted, linked from the README.
  9. Community files: CODE_OF_CONDUCT.md (Contributor Covenant 2.1; reports through a private GitHub advisory or @DatMoshu, no email), SECURITY.md (loopback-only servers, GitHub private vulnerability reporting), and issue templates bug_report.yml, feature_request.yml, parity_gap.yml (action id, direction, slot, item, expected/actual, screenshot, with a reminder not to attach original client art) plus config.yml (blank issues off; Discussions and wiki links).
  10. README: CI and MIT badges, a <!-- hero-gif --> placeholder, a "Help wanted: toward UO parity" section linking ROADMAP.md, the wiki and CONTRIBUTING.md, and links to CODE_OF_CONDUCT/SECURITY.
  11. Tests: tests/unit/test_fit_lab_server.py covers a good Host passing, foreign Host/port/Origin getting 403 on GET and POST, no directory listings, and a JSON error for a missing manifest. tests/unit/test_client_staging.py covers each missing client file failing before any output folder exists, partial output being removed after a late failure (and the retry then succeeding), and a failed rebuild merge leaving no staging folder. test_fit_lab_renders.py gains a test that patch jobs are excluded.

Verification

  • python -m pytest -q: 118 passed, 1 skipped (client-dependent), 3 subtests passed
  • cd games\ultima-online\outfit-lab; python -m unittest -q: 15 tests OK (the existing ResourceWarning from outfit-lab/vd.py is unchanged)
  • python tools/agents/run.py --check: agent routers up to date
  • python tools/fit-lab/run.py serve --help still works

Not run: headless Blender builds and a live browser session against the lab. The server changes are covered by real HTTP requests in the unit tests, but no Blender render was made.

Risks and remaining work

  • The Fit Lab now refuses requests whose Host is not 127.0.0.1:<port>/localhost:<port>. A webview host that loads the lab under another host name would need to be added to that rule.
  • "lightsaber" names (fit_lightsaber and so on) are still in the outfit-lab code. They were outside this sweep.

🤖 Generated with Claude Code

- Fit Lab server: Host/Origin loopback guard (same rules as Content Studio) on
  GET/HEAD/POST, no directory listings under /data/ and /builds/, manifest and
  build-state errors returned as JSON, UTF-8 reads.
- builds.py: clear ValueError when an item's part is missing from the mapping.
- Client staging (client_import.stage, equipment.stage_equipment): check
  required client files before creating output; remove a partially written
  output folder on failure so retries work.
- rebuild.py: remove staging/<id> when a patch merge fails; the Fit Lab render
  index ignores patch-only jobs so they never show as the newest render.
- UTF-8 encoding for JSON read_text/write_text in fit-lab and uo-content;
  files closed with `with` in tools/vd.
- Rename franchise-named outfit-lab demos to generic overalls and sci-fi plate
  armor (scripts, tests, launchers, docs, workspace folders).
- docs/handoff.md: drop commercial pack names; add ROADMAP.md, CODE_OF_CONDUCT,
  SECURITY, issue templates (bug, feature, parity gap) and README badges and
  help-wanted section; ignore /.playwright-mcp/.
- Tests for the Fit Lab host guard, directory listing, staging cleanup, failed
  rebuild cleanup and patch-job exclusion.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T21:44:41.161258Z 135344e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 135344efb3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@@ -0,0 +1,9 @@
@echo off

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve CRLF in the new batch launchers

Both newly added launcher blobs use LF-only line endings, despite the project rule requiring .bat launchers to use CRLF. In source/archive checkouts without Git line-ending conversion, this violates the launcher format contract and can break Windows tooling that expects conventional batch-file endings; resave both this file and plate-armor-lab.bat with CRLF (or enforce it through .gitattributes).

AGENTS.md reference: AGENTS.md:L3-L7

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant