feat: in-game theme store — server catalog + verified downloads + install UI
Test / test (pull_request) Successful in 10m15s

Phase 1+2 of the theme-store roadmap: a free catalog served by
solitaire_server and an in-app browse/install flow, making custom
themes installable on Android for the first time (the manual
drop-a-zip flow can't reach the app-private themes dir there).

- solitaire_sync: ThemeCatalogEntry/ThemeCatalogResponse wire types
  (additive module; SyncPayload and SyncProvider untouched)
- solitaire_server: THEME_STORE_DIR scan at startup (meta-only
  theme.ron parse, sha256, 20 MiB cap, best-effort per archive);
  public GET /api/themes, /api/themes/{id}/download, /{id}/preview;
  compose volume + README_SERVER docs
- solitaire_data: ThemeStoreClient — catalog fetch + download with
  mandatory size/sha256 verification before bytes are released
- solitaire_engine: ThemeStorePlugin — 'Browse theme store' button in
  Settings → Cosmetic, modal catalog (leaderboard-style rebuild),
  download on AsyncComputeTaskPool, atomic .tmp+rename write into
  user_theme_dir, then the existing hardened import_theme pipeline and
  an in-place registry refresh

New deps: sha2 (workspace, server+data); ron/zip reused in server;
serde_json added to solitaire_sync dev-deps for DTO round-trip tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
funman300
2026-07-07 13:12:41 -07:00
parent 018b69285d
commit d87397b382
23 changed files with 1718 additions and 3 deletions
+19
View File
@@ -11,6 +11,7 @@ pub mod leaderboard;
pub mod middleware;
pub mod replays;
pub mod sync;
pub mod theme_store;
pub use auth::reset_password;
@@ -86,6 +87,10 @@ pub struct AppState {
pub pool: SqlitePool,
/// HS256 signing secret for JWT access and refresh tokens.
pub jwt_secret: String,
/// Theme-store catalog scanned once at startup.
/// [`theme_store::ThemeStore::empty`] when the server runs without
/// a store directory.
pub theme_store: Arc<theme_store::ThemeStore>,
}
/// Construct the full Axum [`Router`].
@@ -125,9 +130,20 @@ pub async fn build_test_pool() -> SqlitePool {
/// integration tests do not need to set `JWT_SECRET` in the environment.
#[doc(hidden)]
pub fn build_test_router(pool: SqlitePool) -> Router {
build_test_router_with_theme_store(pool, theme_store::ThemeStore::empty())
}
/// [`build_test_router`] with a caller-supplied theme store, for
/// integration tests exercising the theme endpoints.
#[doc(hidden)]
pub fn build_test_router_with_theme_store(
pool: SqlitePool,
theme_store: theme_store::ThemeStore,
) -> Router {
let state = AppState {
pool,
jwt_secret: "test_secret_32_chars_minimum_ok!".to_string(),
theme_store: Arc::new(theme_store),
};
build_router_inner(state, false)
}
@@ -195,6 +211,9 @@ fn build_router_inner(state: AppState, rate_limit: bool) -> Router {
.route("/api/daily-challenge", get(challenge::daily_challenge))
.route("/api/replays/recent", get(replays::recent))
.route("/api/replays/{id}", get(replays::get_by_id))
.route("/api/themes", get(theme_store::list))
.route("/api/themes/{id}/download", get(theme_store::download))
.route("/api/themes/{id}/preview", get(theme_store::preview))
.route("/health", get(health))
.nest_service("/avatars", ServeDir::new("avatars"));