One-paste connect line from Chronicle, and report the module version - #121
Merged
Merged
Conversation
Every REST request carries X-Chronicle-Module-Version. A GM can paste Chronicle's connect line into a client-scoped setting that fills URL, campaign ID and the client-scoped API key, then clears itself. Contract docs now mark /calendar/advance, /advance-time and /import retired (410) and document POST /calendar. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UexL55BkZcztyC1eezXKfn
An older Chronicle's CORS allow-list lacks X-Chronicle-Module-Version, so a cross-origin preflight carrying it is refused. The API client retries such a request once without the header and stops sending it for the session; the dashboard's raw probes no longer send it. The connect-line hint and README now point at Manage > Apps & game system, where Chronicle shows it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UexL55BkZcztyC1eezXKfn
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Key Maker · project thread
Fixes: none (module half of keyxmakerx/Chronicle#893)
Security implication: The pasted line carries an API key. It goes only into the existing CLIENT-scoped
apiKeysetting; the line itself sits in a client-scoped setting that is masked as a password field and cleared straight after applying. Only a GM can apply it, and the line and key are never logged.Consumer-verified: Chronicle builds the line in
internal/plugins/campaigns/foundry_connect.goBuildFoundryConnectLine(keyxmakerx/Chronicle#954). It reads the header ininternal/plugins/syncapi/middleware.go(moduleVersionFromHeader,^[0-9A-Za-z.+\-]{1,32}$) and allows it in CORS ininternal/middleware/cors.go.Foundry compatibility: n/a for live checks. Not run in a Foundry world here; the live check is keyxmakerx/Chronicle#966.
Mockup: Sign-offs card "Before and after: the Foundry row on Apps & game system", approved.
What this changes
Before: Connecting Foundry meant copying Chronicle's address, the campaign ID and an API key into three separate settings. Chronicle couldn't tell which module version was calling.
After:
Why
keyxmakerx/Chronicle#893. Old keys keep working (the owner's choice), so pasting a new line never disconnects anything else.
Load-bearing lines
scripts/_connect-line.mjsparseConnectLine:chronicle://maps to https andchronicle+http://maps to http./c/<id>is the base path;keyis the query param.scripts/settings.mjsapplyConnectLine:scripts/_module-version.mjsandapi-client.mjs:fetchanduploadMedia, and caller headers win.TypeErroron a request that carried the header retries once without it and drops it for the session, so installing this release before updating Chronicle doesn't break sync. The dashboard's raw probes never send it.calendar_route_retired) andPOST /calendar(201{created, warnings}, 409 when a calendar exists), matching Chronicle#954.Test plan
node --test tools/test-*.mjs: 967 tests, 967 pass, 0 fail.node --checkon every changed script.tools/test-connect-line.mjs(6 accept and 12 reject cases, plus settings wiring) andtools/test-module-version-header.mjs(builder, live reader, the header-less retry and per-session drop, the fetch-path pins).Tenet self-check
.ai.md, API-CONTRACT.md, README and CLAUDE.md describe it.🤖 Generated with Claude Code
https://claude.ai/code/session_01UexL55BkZcztyC1eezXKfn
Generated by Claude Code