Strict yyyy-MM-dd parse (matches /load/index round-trip format) — rejects
malformed input. data_headers.servertime is emitted by the standard
envelope, which is what the client reads into BirthDayUpdateServerTime.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
is_skip_gacha_effect, use_challenge_two_pick_premium_card, and
challenge_two_pick_sleeve_id all persist on ViewerInfo and round-trip
through /load/index.
The two challenge fields move from the global ChallengeConfig section to
ViewerInfo — they're viewer preferences, not server-wide policy. Premium
card defaults to 0; sleeve falls back to DefaultLoadoutConfig.SleeveId
(3000011) when unset. MatchContextBuilder's TK2 sleeve read switches to
the same viewer-scoped path.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
New ASP.NET Core 8 web project, standalone (no project references). Serves
the CDN-mirror tree from a configured root via UseStaticFiles mounted at
/dl/, with ServeUnknownFileTypes=true + DefaultContentType=octet-stream
since blob filenames are bare MD5 hashes with no extension and asset
extensions (.unity3d/.acb/.usm) aren't in the default MIME map.
Configuration: SVSIM_CONTENT_ROOT env var (or Content:Root in appsettings,
or --Content:Root cli arg) points at the asset root containing the dl/
subdirectory. The asset root is populated by data_dumps/scripts/
content_cdn_mirror.py in the outer repo (~22 GB Eng+Jpn).
Listens on port 5149 (distinct from EmulatedEntrypoint's 5148). Lightweight
request logging via inline middleware emits status/method/path/ms for every
request. /health returns "ok".
End-to-end smoke verified against the populated working copy at
4670rPsPMVlRTd2:
- Both lang tier-1s served (Eng 1013b / Jpn 955b), MD5s match live CDN.
- A category manifest (bg_assetmanifest Eng) served + verified.
- A 4.5 MB font asset bundle served + MD5-verified.
- A Jpn voice from Sound/Jpn/ served + MD5-verified.
- Hardlinked content (master_ai_ally_common.unity3d, hash shared across
langs) served identically from both Resource/Eng/ and Resource/Jpn/.
- 404 for missing blobs (correct).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Translation middleware now extracts viewer_id/steam_id/steam_session_ticket
from the decrypted msgpack dict into HttpContext.Items before the typed
DTO deserialize. The Steam handler reads from there instead of re-parsing
Request.Body — so authed action DTOs no longer need to inherit BaseRequest
to keep the auth fields alive through the msgpack→DTO→JSON pivot.
Retires the recurring footgun documented in
docs/superpowers/specs/2026-06-02-baseRequest-auth-footgun-improvement.md
(2026-05-25 basic-puzzle, 2026-05-28 deck-code, 2026-06-02 Phase 3 Bot,
2026-06-10 profile/index + item_acquire_history/info + user_mypage/update).
Pinned by AuthDecouplingTests — posts an encrypted msgpack body to
/profile/index (DTO does not inherit BaseRequest) through the real
translation middleware + auth handler and asserts 200. Adds an
EncryptedMsgpackHelper + useRealAuthHandler factory flag, reusable for
future wire-shape tests.
ProfileIndexRequest, ItemAcquireHistoryInfoRequest, and
UserMyPageUpdateRequest revert to the naked shape — the per-DTO
workarounds become vestigial under the new architecture.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Per feedback_wire_shape_tests: controller round-trip tests using the
same DTO can't catch wire-key/wire-type drift. Asserts parsing of and
snake_case emission for the period list + monthly ranking shapes.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Pure deterministic monthly period generator for the four ranking
families. Anchor dates derived from prod capture (2026-06-09): id=1 is
each family's launch month in JST; id=N is anchor + N-1 months. Used
by /ranking/get_viewable_ranking_period_list to render the period
picker and by per-family leaderboard endpoints to echo the requested
period back.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>