Onboarding overlay: on DOMContentLoaded the dashboard calls GET
/auth/status. If no profile exists, a full-screen setup card replaces
the normal UI (header, nav, and main are hidden). The user enters a
username and clicks Start Playing — POST /auth/local is called, then
the overlay hides and the Club tab loads normally. Pressing Enter in
the username field also submits. Validation: minimum 2 characters,
error message inline below the button.
Danger Zone in Settings tab: a red-bordered section with a Reset All
Progress button. Clicking opens a confirmation modal that requires the
user to type the word RESET before the action is enabled. On confirm,
POST /auth/reset is called, a toast is shown, and the page reloads
after 1.5 s — which triggers the onboarding flow again since the
profile was deleted.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
New Achievements tab (tab-achievements) shows all 18 achievement cards in
a responsive grid. Each card displays: icon, title, rarity badge (color-
coded: common=grey, rare=blue, epic=purple), description, reward coins, and
either a green "Unlocked <date>" label or a dimmed "Locked" state. Unlocked
achievements sort first (newest-first); locked sort alphabetically after.
Header nav button shows earned count badge next to "Achievements".
Match result handler reads achievements_unlocked from the Core response and
fires one toast per newly unlocked achievement immediately after match
submission. Level-up toasts continue to work independently.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Notifications tab now fully functional. Each notification shows a type
icon, colored left border (gold=level_up, green=objective, amber=warning,
red=expired, blue=season), bold title when unread, body text, timestamp,
and a per-item Mark read button for persistent notifications.
Header badge and the unread count label now use unread_count from the
Core response rather than total notification count.
A Mark all read button calls POST /notifications/read-all and refreshes
the list. Per-item PATCH /notifications/:id/read hides the button and
dims the card on success.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Each card in the Collection tab now shows a Sell button displaying the
quick-sell coin value (computed from overall rating using the same tiers
as the backend: 85+→1500c, 80-84→900c, 75-79→600c, 65-74→300c, <65→150c).
Clicking calls DELETE /collection/:id with a confirmation prompt, shows a
toast with the actual coins received, and refreshes both the collection
and the header coin counter. Loan cards show a disabled button instead
to prevent accidental early sale.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Match result display now shows a level-up row per level gained (new
level, coins granted, milestone pack) and fires a toast notification.
Settings/Profile card now uses xp_to_next_level and xp_for_next_level
from the enhanced GET /profile response so the XP bar accurately shows
progress within the current level rather than total XP %.
Squad View mode gains an All Squads panel below Chemistry listing every
saved squad (name + formation badge). Each row has a Delete button that
calls DELETE /squads/:id and refreshes the view. Squads are loaded via
GET /squads alongside the active squad on every Squad tab open.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Card Catalog — full card database browser using GET /cards with client-
side filters (name, position, rarity, nation, league, club, OVR range),
pagination in 80-card chunks, "Owned" green overlay/badge for cards
already in the collection (cross-referenced via GET /collection).
Settings/Profile — profile card with username, level, XP progress bar;
editable game settings (default match difficulty, preferred formation)
via GET/PUT /settings; confirmation flash on save.
Squad Builder — Squad tab gains a Build/View toggle. Build mode shows
11 starter slots (labelled by position for the selected formation) plus
7 bench slots; clicking any slot opens an inline search-picker filtered
to unused collection cards; GK slot highlighted; filled slots show
player name, OVR, and position with a one-click clear button; Save
Squad POSTs the full squad to Core (validates 11 starters required) then
switches back to View mode and refreshes the chemistry display.
Formations supported: 4-4-2, 4-3-3, 4-2-3-1, 4-1-2-1-2, 3-5-2, 5-3-2.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Matches — difficulty selector, generate opponent (shows AI squad rating
and formation), quick-score buttons (3-0 / 1-1 / 0-2), submit custom
score via POST /matches/result, inline reward display (coins, XP,
objective triggers, season points), live match history list.
Pack Store — lists all purchasable definitions from GET /packs/store
(name, description, cost, card count) with one-click Buy that calls
POST /packs/buy; coin balance refreshes after purchase.
SBC — renders all challenges with requirements as pills (min OVR,
required nations/leagues/clubs, same-club counts), card picker
(select from owned collection, click pill to remove), Submit fires
POST /sbc/submit and shows reward or validation failures; cards
re-loaded from Core after a successful submission.
Statistics — career stat grid (matches, W/D/L, win rate, goals, coin
totals, streaks, packs, SBCs), goals-by-position bar chart, paginated
match log with outcome badges and date, sourced from
GET /statistics and GET /statistics/history.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Four new tabs complete the dashboard UI for all existing Core endpoints:
Squad — view active squad with per-player chemistry dots and team
chemistry bar (colour-coded green/amber/red).
Draft — start a session with difficulty selector, pick from 5 candidates
per slot through all 11 positions, see picks accumulate in real time,
reward shown on completion.
Market — browse NPC listings with live search filter, one-click buy,
sell own cards with price input, cancel own listings; Refresh button
repopulates NPC inventory via POST /market/refresh.
Events — list all data-driven events with active/inactive state, bonus
effects summary (score/coin multipliers, extra market cards, pack
discounts), Activate/Deactivate buttons.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Single-page club management UI served by the bridge. The Core URL is
injected server-side so client JS calls Core directly without routing
through the proxy. Vanilla HTML/CSS/JS, dark theme matching admin.html.
Sections: Club (name/manager/coins/stats edit), Collection (filterable
card grid with stat bars + chemistry/training pills), Packs (open with
modal, history), Objectives (progress bars + one-click claim), Division
(W/D/L record, season progress, rivals weekly claim), FUT Champions
(current session with in-browser match simulation, claim, history),
Notifications (badge count in nav).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- GET /_bridge/cert.pem — serves the TLS CA cert as a downloadable PEM file
(only when TLS_ENABLED=true; 404 otherwise)
- GET /_bridge/guide — HTML setup page with hosts-file instructions, cert install
steps per OS, and troubleshooting tips
- ProxyState gains cert_pem field (Arc<Vec<u8>>); set via with_cert() builder
- main.rs generates cert before state construction so /_bridge/cert.pem can serve it;
both cert_pem and key_pem passed to serve_tls() for acceptor + state separately
- All 13 bridge tests pass, clippy clean
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- proxy.rs: forward_to_core() now accepts the incoming headers vec
and passes X-UT-SID, X-UT-PHISHING-TOKEN, and X-Request-ID through
to Core on every mapped request (#19, #20)
- TODO.md: mark #15-#20 as complete with implementation notes;
update test counts; clean up duplicate #15 entry
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- shaper.rs: shape_response() dispatches on core_path to wrap Core
JSON in FUT envelope format; shapes auth (/ut/auth → sid/pid/
phishingToken/persona envelope), profile, club, squad, market,
packs; unknown paths pass through unchanged
- proxy.rs: calls shape_response() on every successful Core response
before returning to the FIFA 23 client
- mapper.rs: expanded from 6 to 18 speculative FUT endpoint mappings
covering auth, profile/settings, club/usermassinfo, item/collection,
squad (GET+PUT), packs+purchase, transfer market+watchlist+bid,
objectives, events, squad battles, and match result submission
- admin.rs: GET /_bridge/captures/diff?a=<id>&b=<id> compares two
captures; reports method/path/status changes, header diffs, and
structured JSON body diffs (key-level for objects, length for others)
- main.rs: registers /_bridge/captures/diff route
- Unit tests: 4 shaper tests, 6 mapper tests (10 total, all passing)
- All 13 integration tests still passing
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
FIFA 23 reverse-engineering proxy and integration scaffold.
- Catch-all HTTP proxy that captures all incoming FIFA 23 traffic
- Known-route mapper (speculative FUT paths → Core API calls)
- Placeholder JSON responses for unmapped endpoints
- Admin endpoints: GET /_bridge/captures, GET /_bridge/unknown
- Capture persistence to captures/*.json for RE analysis
- 4 unit tests passing
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>