Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .github/workflows/verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ jobs:
run: pnpm --dir services/auth-bridge run check

- name: Audit bridge dependencies
run: pnpm --dir services/auth-bridge audit --audit-level high
run: pnpm --dir services/auth-bridge audit --audit-level low

spacetimedb-module:
runs-on: ubuntu-latest
Expand Down Expand Up @@ -147,7 +147,8 @@ jobs:
run: |
pnpm --dir spacetimedb run verify
npm run stdb:verify-bindings
npm run stdb:verify-worker-migration
npm run stdb:verify-additive-migration

- name: Audit module dependencies
run: pnpm --dir spacetimedb audit --audit-level high
run: pnpm --dir spacetimedb audit --audit-level low
22 changes: 20 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,14 @@ dist
.DS_Store
coverage
*.local
.cache/warpkeep-assets/
.cache/warpkeep-tools/
/pnpm-lock.yaml
/pnpm-workspace.yaml

# Machine-local caches and deployment state.
.cache/
.wrangler/
.dev.vars*
!.dev.vars.example

# Local credentials, operator output, and recovery residue must never be staged.
credentials.json
Expand All @@ -17,6 +23,18 @@ credentials.json
*.key
*.p12
*.pfx
*.jks
*.keystore
*.crt
*.cer
*.jwk
*.token
id_rsa*
id_ed25519*
admin-secret*
secret.json
secrets.json
.secrets/
*.log
*.har
*.trace
Expand Down
21 changes: 21 additions & 0 deletions ASSETS-LICENSE.md
Original file line number Diff line number Diff line change
Expand Up @@ -292,6 +292,27 @@ The live integration mounts the card as decorative inspection art
only; it grants no resource, currency, reward, entitlement, map-placement, or
Wood authority. No Pages deployment is authorized by this record.

## Hegemony Worker inspection artwork

On 2026-07-19, the Warpkeep project owner supplied a transparent Worker
illustration for the reviewed Worker UI slice. That authorization covers this
exact checked-in derivative in the public Warpkeep repository and an eventual
official `warpkeep.com` Pages runtime only after separately approved deployment.
It is use authorization only: it does not establish ownership, grant a public
open-content licence or general redistribution rights, or create worker,
resource, route, cargo, reward, settlement, or SpacetimeDB authority.

| Intended use | Repository file | Technical record |
| --- | --- | --- |
| Decorative Worker inspection artwork | `public/images/realm/hegemony-worker-record.webp` | 1024×1024 transparent WebP, 86,984 bytes, SHA-256 `ff758ecbf520b05ccf0a2fa490bcafa6c564514de5ee56ef5a720fd6da24193e`; prepared from the supplied transparent PNG through the exact recorded Sharp 0.35.3 encoding. |

The supplied source is not committed. Its exact hash, the runtime decoded-RGBA
hash, alpha profile, visible bounds, processing settings, and narrow UI-only
boundary are recorded in the dated [Worker inspection-art record](docs/reference/resources/2026-07-19-hegemony-worker/record-art/manifest.json).
The runtime file remains `LicenseRef-Warpkeep-Provenance-Required` and is loaded
only as same-origin decorative art by `WorkerInspectionPanel`; it does not
provide or imply identity, ownership, balance, command, or gameplay authority.

## Hegemony Logging Camp runtime assets

On 2026-07-18, the Warpkeep project owner supplied the named Logging Camp
Expand Down
17 changes: 16 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,20 @@ full engineering record.

## [Unreleased]

## [0.3.14] — 2026-07-22

- Made the Realm recover from temporary graphics interruptions while preserving
selection and camera intent, and let castles continue at compact detail when
optional richer models cannot load.
- Gave river and ocean surfaces gentle motion and selectable, read-only public
records, including source-to-mouth river navigation. Reduced-motion play
keeps the water still.
- Refined the Lowlands toward a clearer green palette and denser grass coverage
without changing authoritative terrain, ownership, or resource rules.
- Staged a server-authoritative four-worker foundation behind inactive migration
and activation gates. Workers are not live in Alpha 0.3.14; the existing
expedition flow remains in place.

## [0.3.13] — 2026-07-19

- Let the old scattered lakes return to lowland while preserving twelve
Expand Down Expand Up @@ -111,7 +125,8 @@ full engineering record.
Lowlands, a first keep, Farcaster sign-in, and an admission-gated shared-world
foundation.

[Unreleased]: https://github.com/ael-dev3/Warpkeep/compare/v0.3.13...HEAD
[Unreleased]: https://github.com/ael-dev3/Warpkeep/compare/v0.3.14...HEAD
[0.3.14]: https://github.com/ael-dev3/Warpkeep/compare/v0.3.13...v0.3.14
[0.3.13]: https://github.com/ael-dev3/Warpkeep/compare/v0.3.12...v0.3.13
[0.3.12]: https://github.com/ael-dev3/Warpkeep/compare/v0.3.11...v0.3.12
[0.3.11]: https://github.com/ael-dev3/Warpkeep/compare/v0.3.8...v0.3.11
Expand Down
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

## What is this?

Genesis 001 is a persistent, invite-only 10,000-cell Lowlands realm with 100 permanent castle sites kept close to its founding district. Each founder signs in with a verified Farcaster identity, receives one durable keep, and privately holds Food / Wood / Stone / Gold. Food, Wood, and Stone are governed by authoritative terrain yield, while dedicated expeditions can gather all four resources. Alpha 0.3.13 is live but early; founders can explore its coast, twelve rivers, clustered forests, and resource sites, follow their supply wagons, and return to a world that remembers them, while the intended core strategy loop is not playable yet. Warpkeep is a one-person experiment—not a finished MMO or financial product; there are no token rewards, no financial promises, and joining does not earn an airdrop or financial return or guarantee a reward or future value.
Genesis 001 is a persistent, invite-only 10,000-cell Lowlands realm with 100 permanent castle sites kept close to its founding district. Each founder signs in with a verified Farcaster identity, receives one durable keep, and privately holds Food / Wood / Stone / Gold. Food, Wood, and Stone are governed by authoritative terrain yield, while dedicated expeditions can gather all four resources. Alpha 0.3.14 is live but early; founders can explore its coast, twelve rivers, clustered forests, and resource sites, follow their supply wagons, and return to a world that remembers them, while the intended core strategy loop is not playable yet. Warpkeep is a one-person experiment—not a finished MMO or financial product; there are no token rewards, no financial promises, and joining does not earn an airdrop or financial return or guarantee a reward or future value.

![Development preview of Genesis 001 showing the Lowlands and an open Wheat Farm inspection panel.](docs/reference/screenshots/2026-07-22-realm-wheat-farm-preview/warpkeep-realm-wheat-farm-preview-f3b1f7e598c543d6.png)

Expand All @@ -27,7 +27,7 @@ Open the local URL Vite prints; shared Alpha access stays off by default. Contri

| State | Today |
| --- | --- |
| ✅ Live | Alpha 0.3.13 is live and invite-only. |
| ✅ Live | Alpha 0.3.14 is live and invite-only. |
| ✅ World | Genesis 001 persists 10,000 cells, a coastline, twelve one-cell rivers, and 100 permanent castle sites near the founding district. Founders return to one durable keep, explore the Lowlands up to its fog, and inspect nearby founders through their public username / portrait / castle. The same authoritative world waits across sessions. |
| ✅ Authority | FID is the durable identity; handles and portraits are bounded presentation metadata. Farcaster sign-in uses a browser-bound, least-privilege bridge. The browser presents. The server decides admission and ownership. It also owns resources, timers, and saved state. |
| ✅ Resources | Each keep privately holds Food / Wood / Stone / Gold. Food, Wood, and Stone come from authoritative terrain yield and can also be gathered at Wheat Farms, Logging Camps, and Stone Quarries; Gold comes from Gold Mines. The resource rail shows stored and ready amounts, and hover, focus, or tap explains current behavior. The browser never invents balances. |
Expand All @@ -52,7 +52,7 @@ Open the local URL Vite prints; shared Alpha access stays off by default. Contri
- **Architecture:** The [technical architecture](docs/technical-architecture.md) explains what the browser shows and what the server decides.
- **Roadmap:** The [roadmap](docs/design/roadmap.md) and [game direction](docs/design/warpkeep-direction.md) separate today's game from later plans.
- **Authentication:** The [Farcaster integration](docs/farcaster-integration.md) guide covers sign-in, privacy, and public configuration.
- **Release:** The [Alpha 0.3.13 release notes](CHANGELOG.md#0313--2026-07-19) record exactly what is live.
- **Release:** The [Alpha 0.3.14 release notes](CHANGELOG.md#0314--2026-07-22) record exactly what is live.
- **Licensing:** [LICENSING.md](LICENSING.md) explains release rules; [asset provenance](ASSETS-LICENSE.md) records where media came from and what permissions apply.
- **Contributing:** [CONTRIBUTING.md](CONTRIBUTING.md) covers checks and provenance; the [Realm Council issue forms](https://github.com/ael-dev3/Warpkeep/issues/new/choose) accept privacy-safe bugs and ideas.
- **Security:** Report sensitive issues privately through [SECURITY.md](SECURITY.md), never through a public issue.
Expand Down
39 changes: 39 additions & 0 deletions docs/design/realm-renderer-recovery.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# Realm renderer recovery

The Realm keeps a real WebGL scene as the source of truth once it has become
ready. The renderer lifecycle is explicit: `probing`, `loading`, `ready`,
`recovering`, `static-unsupported`, and `failed`.

`static-unsupported` is reserved for a device that cannot create WebGL before
the first successful scene. It is an accessible, bounded illustrated view; it
is never a post-ready error surface. A renderer construction error, failed
castle assembly, castle-count mismatch, or synchronization failure remains an
explicit loading/recovery/failed state instead of silently replacing a real
world with a full-world SVG.

Context loss calls `preventDefault`, pauses ambient work and rendering, and
retains React selection, camera intent, and the scene attestation. Pointer,
wheel, label-click, and camera input are synchronously suspended while the
context is lost so a partially disposed scene cannot consume a gesture. The
restored event starts a bounded scene rebuild and records loss/restore counts on
the canvas for DOM diagnostics. If the browser does not restore the context in
time, the user sees an explicit retry surface. All renderer surfaces share one
cached, non-destructive WebGL2 capability probe. No capability check calls
`WEBGL_lose_context` or otherwise tears down a context; a probe only reads the
optional texture-size limit.

Castle loading is staged: Compact is mandatory and retried once for transient
transport failures after a deterministic short yield; Balanced and High are
optional upgrades. A missing optional LOD records the active quality in
`data-realm-castle-active-lod` and continues with Compact. Pairing, integrity,
and Compact failures are reported with stable failure codes for telemetry and
QA. Each controlled load is assigned a monotonic renderer generation. Scene
callbacks carry that generation and stale callbacks from a disposed scene are
ignored by both the React boundary and the pure lifecycle reducer. The DOM
exposes the active generation and the last generation that rendered a
successful frame, making recovery assertions deterministic. A ready renderer
can never transition into static compatibility mode.

The recovery contract is intentionally frontend-only. Durable world state,
authorization, and SpacetimeDB subscriptions remain outside the renderer and
are never mutated by recovery code.
2 changes: 1 addition & 1 deletion docs/design/roadmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
Warpkeep is building a persistent strategy world one playable loop at a time.
Dates and feature order may change as the Alpha is tested.

## Live now — Alpha 0.3.13
## Live now — Alpha 0.3.14

- Farcaster-gated entry to the persistent Genesis 001 realm
- 10,000 world cells and 100 permanent castle sites near the founding district
Expand Down
15 changes: 13 additions & 2 deletions docs/farcaster-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
Warpkeep uses standard website Sign In with Farcaster (SIWF). It is not a Mini
App, Quick Auth, wallet connection, or a client-only permanent identity system.

Alpha 0.3.13 uses backend protocol 3 and authentication contract v2; admission
Alpha 0.3.14 uses backend protocol 3 and authentication contract v2; admission
remains gated. Production configuration and founder identities belong in the
private operator record, not this guide. This document describes the contract
but does not authorize admission or a production change.
Expand All @@ -30,6 +30,12 @@ that boundary and never enter the session family or player JWT. The bridge
accepts only the configured `FARCASTER_DOMAIN` and exact
`FARCASTER_SIWE_URI`.

Production proof verification uses two official Farcaster verifier instances
backed by distinct public HTTPS RPC origins. Both must succeed with the same
canonical FID. A provider outage, partial result, or disagreement fails closed
as temporarily unavailable. A single RPC endpoint is permitted only for an
explicit development profile and must be loopback-local.

The intended production coordinates remain:

```txt
Expand Down Expand Up @@ -82,6 +88,11 @@ URLs, or logs:
- player/admin/resolver JWTs;
- signing keys, session-cookie key, RPC credential, or admin secret.

The private admin configuration attestation exposes only domain-separated
SHA-256 fingerprints of the normalized RPC URLs and the active signing public
key's RFC 7638 thumbprint. Those values make endpoint or key drift detectable
without returning an RPC URL, credential, or private scalar.

After a fresh signature and an exchange whose bridge-verified FID exactly
matches it, the browser may write a tab-scoped `sessionStorage` presentation
cache. It contains only the sanitized public FID, username, display name, and
Expand Down Expand Up @@ -238,7 +249,7 @@ VITE_WARPKEEP_OIDC_AUDIENCE=warpkeep-spacetimedb

The Worker configuration is documented in
[`services/auth-bridge/README.md`](../services/auth-bridge/README.md). Its
checked-in `PUBLIC_AUTH_ENABLED` remains false, while the recorded Alpha 0.3.13
checked-in `PUBLIC_AUTH_ENABLED` remains false, while the recorded Alpha 0.3.14
production override is true. Before any future enable, the server-only v2
configuration attestation must match the reviewed issuer, origins, SIWF
coordinates, key ID, Maincloud coordinates, S256 binding, 600-second access
Expand Down
1 change: 1 addition & 0 deletions docs/legal/license-inventory.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ public license or expand the recorded reuse and redistribution terms.
| `/public/images/realm/hegemony-gold-mine-record.webp` | Transparent decorative Gold Mine inspection-card artwork | Not present | `LicenseRef-Warpkeep-Provenance-Required`; no separate public open license asserted | On 2026-07-18, the project owner authorized the exact background-cleaned derivative for PR #49 and the reviewed Gold Wagon integration in the public Warpkeep GitHub repository, plus an eventual official `warpkeep.com` Pages runtime only after separately approved deployment; this is not deployment approval or Gold Mine economic authority | The dated Gold Mine inspection-art record pins the supplied input, generated/chroma inputs, exact output, alpha audit, UI-only boundary, and authorization scope | Preserve the exact hash and decorative-only use; do not infer a node placement, gathering action, balance, reward, Marks linkage, public relicensing, or general redistribution authority |
| `/public/images/realm/hegemony-wheat-farm-record.webp` | Transparent decorative Wheat Farm inspection-card artwork | Not present | `LicenseRef-Warpkeep-Provenance-Required`; no separate public open license asserted | On 2026-07-18, the project owner authorized the exact background-cleaned derivative for PR #57 in the public Warpkeep GitHub repository, plus an eventual official `warpkeep.com` Pages runtime only after separately approved deployment; this is not deployment approval or Food economic authority | The dated Wheat Farm inspection-art record pins the supplied input, generated/chroma inputs, exact output, alpha audit, UI-only boundary, and authorization scope | Preserve the exact hash and decorative-only use; do not infer a Food-site placement, gathering action, balance, reward, Marks linkage, public relicensing, or general redistribution authority |
| `/public/images/realm/hegemony-logging-camp-record.webp` | Transparent decorative Logging Camp inspection-card artwork | Not present | `LicenseRef-Warpkeep-Provenance-Required`; no separate public open license asserted | On 2026-07-19, the project owner authorized the exact background-cleaned derivative for PR #62 in the public Warpkeep GitHub repository, plus an eventual official `warpkeep.com` Pages runtime only after separately approved deployment; this is not merge or deployment approval or Wood economic authority | The dated Logging Camp inspection-art record pins the supplied RGB preview, local alpha-matte input, exact output, alpha/spill audit, UI-only boundary, and authorization scope | Preserve the exact hash and decorative-only use; do not infer a Wood-site placement, gathering action, balance, reward, Marks linkage, public relicensing, or general redistribution authority |
| `/public/images/realm/hegemony-worker-record.webp` | Transparent decorative Worker inspection artwork | Not present | `LicenseRef-Warpkeep-Provenance-Required`; no separate public open license asserted | On 2026-07-19, the project owner supplied the exact transparent Worker illustration for the reviewed Worker UI slice in this public repository and an eventual official `warpkeep.com` Pages runtime only after separately approved deployment; this is not merge, deployment, worker activation, or economic authority | The dated Worker inspection-art record pins the supplied source hash, exact runtime hash, decoded-RGBA hash, alpha audit, visible bounds, same-origin UI-only boundary, and authorization scope | Preserve the exact hash and decorative-only use; do not infer worker identity, ownership, command, route, cargo, balance, reward, settlement, public relicensing, or general redistribution authority |
| `/public/images/realm/hegemony-stone-quarry-record.webp` | Transparent decorative Stone Quarry inspection-card artwork | Not present | `LicenseRef-Warpkeep-Provenance-Required`; no separate public open license asserted | On 2026-07-19, the project owner authorized the exact background-cleaned derivative for draft PR #65 in the public Warpkeep GitHub repository, plus an eventual official `warpkeep.com` Pages runtime only after separately approved deployment; this is not deployment approval or Stone-site/economic authority | The dated Stone Quarry inspection-art record pins the supplied input, generated/chroma inputs, exact output, alpha audit, UI-only boundary, and authorization scope | Preserve the exact hash and decorative-only use; do not infer a node placement, gathering action, balance, reward, Marks linkage, public relicensing, or general redistribution authority |
| `/docs/reference/resources/2026-07-18-hegemony-gold-mine/runtime-candidates/**` | Historical Hegemony Gold Mine technical-review candidates | Not present | `LicenseRef-Warpkeep-Provenance-Required`; no separate public open license asserted | The owner supplied the exact three source inputs; their historical candidate bytes themselves do not authorize browser delivery, gameplay, deployment, or public relicensing | The candidate record pins supplied hashes and the known atlas-metadata discrepancy; the separate runtime record documents the reviewed promotion | Keep outside `public/` and never import candidate paths; preserve them as audit evidence for the separately named digest-bearing runtime outputs |
| `/public/models/hegemony/gathering-nodes/gold-mine/hegemony-gold-mine-*.glb` | Active Hegemony Gold Mine visual runtime LODs | Not present | `LicenseRef-Warpkeep-Provenance-Required`; no separate public open license asserted | On 2026-07-18, the project owner authorized the named reviewed outputs for the Gold Wagon integration in this public Warpkeep GitHub repository and an eventual official `warpkeep.com` Pages runtime after separately approved deployment; this is not deployment approval | The separate runtime record pins source inputs, exact output hashes, bounded Balanced/Compact atlas metadata normalization, orientation, and visual-only boundary | Preserve immutable hash-bearing paths; do not infer site placement, occupation, dispatch, travel, balance, reward, Marks linkage, public relicensing, or general redistribution authority |
Expand Down
Loading