fix(online): Harden login logging and the updater, fix splash focus - #627
Merged
x64-dev merged 7 commits intoSep 29, 2026
Conversation
tintinhamans
force-pushed
the
arctic/go/fix/auth-and-updater-hardening
branch
from
September 29, 2026 21:37
38c665a to
50addcd
Compare
tintinhamans
marked this pull request as ready for review
September 29, 2026 21:53
x64-dev
merged commit Sep 29, 2026
f72c95d
into
GeneralsOnlineDevelopmentTeam:main
5 of 6 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Small cleanup pass on login and the updater.
Login and anticheat tokens (and the auth response bodies that carry them) no longer go into the log in release builds, only their size. Debug builds still log the full values, same as the existing HTTP response redaction. That HTTP redaction also lowercased the whole logged response while looking for tokens, so it now checks a lowercase copy instead. The login page link now uses https. One lobby log call passed the response body as the format string, so it now goes in as an argument.
The updater download used the default 5 second request timeout, which is too short for a real download, so it gets a long one. The updater file name from the version check now has to be a bare file name, and the download is saved under that name so the launch step runs exactly the file that was written.
Two follow-ups to last week's changes are in here too. With the separate splash window the game window takes over focus inside the same app, so it never got WM_ACTIVATEAPP and stayed marked inactive (mouse moves ignored) until an alt-tab; it now also picks up activation from WM_ACTIVATE. And during a match, a peer that crashed was re-signalled for the rest of the game; retries now stop once the service drops that player from the lobby.