Skip to content
Open
Show file tree
Hide file tree
Changes from 222 commits
Commits
Show all changes
269 commits
Select commit Hold shift + click to select a range
7cfb959
Update main.js
TheRealKCFan20 Jul 17, 2026
d636b58
Update loader.js
TheRealKCFan20 Jul 17, 2026
cc7d68a
Update main.js
TheRealKCFan20 Jul 17, 2026
3f46c1b
Update meat.js
TheRealKCFan20 Jul 17, 2026
a63664e
Update main.js
TheRealKCFan20 Jul 17, 2026
34f7830
Create deno.yml
TheRealKCFan20 Jul 17, 2026
6bd46a9
Update README.md
TheRealKCFan20 Jul 17, 2026
adbba68
Update README.md
TheRealKCFan20 Jul 17, 2026
8c37f4d
Update README.md
TheRealKCFan20 Jul 17, 2026
4e8f528
Update README.md
TheRealKCFan20 Jul 17, 2026
e317bd4
Update README.md
TheRealKCFan20 Jul 17, 2026
1c8dd6a
Update README.md
TheRealKCFan20 Jul 17, 2026
8216440
chrome.png has been readded.
TheRealKCFan20 Jul 17, 2026
6e1876c
Update platform.js
TheRealKCFan20 Jul 17, 2026
a4d0963
Update README.md
TheRealKCFan20 Jul 17, 2026
d18990b
Update README.md
TheRealKCFan20 Jul 18, 2026
e27bf14
Update README.md
TheRealKCFan20 Jul 18, 2026
57c6150
Update README.md
TheRealKCFan20 Jul 18, 2026
9757986
Update README.md
TheRealKCFan20 Jul 18, 2026
6d9a53c
Update README.md
TheRealKCFan20 Jul 18, 2026
aad7d08
Update README.md
TheRealKCFan20 Jul 18, 2026
7c46efd
Update README.md
TheRealKCFan20 Jul 18, 2026
dc034cb
Update README.md
TheRealKCFan20 Jul 18, 2026
833d9ea
Update README.md
TheRealKCFan20 Jul 18, 2026
2832c5d
Update README.md
TheRealKCFan20 Jul 18, 2026
c9eb296
Update README.md
TheRealKCFan20 Jul 18, 2026
508f131
Update README.md
TheRealKCFan20 Jul 18, 2026
79bec70
Update README.md
TheRealKCFan20 Jul 18, 2026
53f7c4b
Update README.md
TheRealKCFan20 Jul 18, 2026
8e019ff
Update LICENSE
TheRealKCFan20 Jul 18, 2026
6b22310
Update README.md
TheRealKCFan20 Jul 18, 2026
7ab8860
Update bonziData.js
TheRealKCFan20 Jul 18, 2026
18de771
Update bonziData.js
TheRealKCFan20 Jul 18, 2026
eac8d07
Update bonziData.js
TheRealKCFan20 Jul 18, 2026
3499c49
Create RULES.md
TheRealKCFan20 Jul 18, 2026
8756f03
Update RULES.md
TheRealKCFan20 Jul 18, 2026
29d6f3c
Update RULES.md
TheRealKCFan20 Jul 18, 2026
ec38d20
Update RULES.md
TheRealKCFan20 Jul 18, 2026
ed99296
Update README.md
TheRealKCFan20 Jul 18, 2026
6314b35
Create rules-template.html
TheRealKCFan20 Jul 18, 2026
3122999
Rename rules-template.html to rules.template.html
TheRealKCFan20 Jul 18, 2026
e50cc4f
Update RULES.md
TheRealKCFan20 Jul 18, 2026
a50aa50
Update RULES.md
TheRealKCFan20 Jul 18, 2026
2020fad
Update RULES.md
TheRealKCFan20 Jul 18, 2026
ba11266
Update RULES.md
TheRealKCFan20 Jul 18, 2026
2233992
Update RULES.md
TheRealKCFan20 Jul 18, 2026
2b67d28
Updated the files.
TheRealKCFan20 Jul 18, 2026
ec4bcd8
Update RULES.md
TheRealKCFan20 Jul 19, 2026
65e101c
Update README.md
TheRealKCFan20 Jul 19, 2026
7147821
Update bonzi.es2015
TheRealKCFan20 Jul 19, 2026
a3f21f5
Update README.md
TheRealKCFan20 Jul 19, 2026
df0635d
Update README.md
TheRealKCFan20 Jul 19, 2026
d1ba278
Update Gruntfile.js
TheRealKCFan20 Jul 19, 2026
5438b24
Update bonzi.es2015
TheRealKCFan20 Jul 19, 2026
8e2199f
Update bonzi.scss
TheRealKCFan20 Jul 19, 2026
4e258e3
Update bonzi.es2015
TheRealKCFan20 Jul 19, 2026
3cde82d
Update index.html
TheRealKCFan20 Jul 19, 2026
18c2c31
Create static.yml
TheRealKCFan20 Jul 19, 2026
2b4be6f
Update settings.example.json
TheRealKCFan20 Jul 20, 2026
0426a11
Update README.md
TheRealKCFan20 Jul 20, 2026
1e33250
Update README.md
TheRealKCFan20 Jul 20, 2026
4fbf595
Update README.md
TheRealKCFan20 Jul 20, 2026
c945fca
Update README.md
TheRealKCFan20 Jul 20, 2026
00d4a41
Update README.md
TheRealKCFan20 Jul 20, 2026
9ca386b
Update README.md
TheRealKCFan20 Jul 20, 2026
8992a6b
Update RULES.md
TheRealKCFan20 Jul 20, 2026
442db65
Create logo3.png
TheRealKCFan20 Jul 20, 2026
39d8a9d
Rename logo3.png to logo2.png
TheRealKCFan20 Jul 20, 2026
f502730
Update index.html
TheRealKCFan20 Jul 20, 2026
da5d01b
Update README.md
TheRealKCFan20 Jul 20, 2026
650b6b4
Update speakWorker.js
TheRealKCFan20 Jul 21, 2026
4ec0f1a
Update Gruntfile.js
TheRealKCFan20 Jul 21, 2026
84343b0
Update console.js
TheRealKCFan20 Jul 21, 2026
dc044ba
Update package.json
TheRealKCFan20 Jul 21, 2026
34eb5d0
Update Gruntfile.js
TheRealKCFan20 Jul 21, 2026
7c676ac
Update package.json
TheRealKCFan20 Jul 21, 2026
c95d0ff
Update Gruntfile.js
TheRealKCFan20 Jul 21, 2026
c5fd99a
Update index.js
TheRealKCFan20 Jul 21, 2026
d71eb80
Update meat.js
TheRealKCFan20 Jul 21, 2026
b17d557
Update index.js
TheRealKCFan20 Jul 21, 2026
8a5a2c1
Update ban.js
TheRealKCFan20 Jul 21, 2026
b071454
Update index.html
TheRealKCFan20 Jul 21, 2026
e43315d
Update package.json
TheRealKCFan20 Jul 21, 2026
c179636
Update package.json
TheRealKCFan20 Jul 21, 2026
220eda7
Update Gruntfile.js
TheRealKCFan20 Jul 21, 2026
1607ef4
Update package.json
TheRealKCFan20 Jul 21, 2026
f1a1e44
Update Gruntfile.js
TheRealKCFan20 Jul 21, 2026
ed25408
Update index.html
TheRealKCFan20 Jul 21, 2026
cf2ef35
Update README.md
TheRealKCFan20 Jul 21, 2026
0450773
Update README.md
TheRealKCFan20 Jul 21, 2026
2dd73eb
Update README.md
TheRealKCFan20 Jul 21, 2026
541e7f9
Update README.md
TheRealKCFan20 Jul 21, 2026
078ff72
Update bonziData.js
TheRealKCFan20 Jul 21, 2026
82cf70f
Update Gruntfile.js
TheRealKCFan20 Jul 21, 2026
9830ac1
Update README.md
TheRealKCFan20 Jul 21, 2026
4871f62
Create CHANGELOG.md
TheRealKCFan20 Jul 21, 2026
5d80d41
Create changelog.template.html
TheRealKCFan20 Jul 21, 2026
8bd9a96
Update Gruntfile.js
TheRealKCFan20 Jul 21, 2026
e2871a1
Update README.md
TheRealKCFan20 Jul 21, 2026
97f4890
Update bg.png
TheRealKCFan20 Jul 22, 2026
0722a56
Update bonzi.es2015
TheRealKCFan20 Jul 22, 2026
d936bed
Update logo.mobile.png and logo.png
TheRealKCFan20 Jul 22, 2026
07406e1
Update logo.png
TheRealKCFan20 Jul 22, 2026
11365dd
Update README.md
TheRealKCFan20 Jul 22, 2026
7580256
oops
TheRealKCFan20 Jul 24, 2026
e6a53d5
Update RULES.md
TheRealKCFan20 Jul 24, 2026
ddc5e60
I forgot about this thing
TheRealKCFan20 Jul 24, 2026
7613bea
Update platform.js
TheRealKCFan20 Jul 24, 2026
0e792e5
Update README.md
TheRealKCFan20 Jul 24, 2026
4e335be
Update google-play-badge.png
TheRealKCFan20 Jul 24, 2026
4e10186
Update README.md
TheRealKCFan20 Jul 24, 2026
37ec3e5
Update platform.js
TheRealKCFan20 Jul 24, 2026
2755d43
Create note.txt
TheRealKCFan20 Jul 24, 2026
4ab2645
Add files via upload
TheRealKCFan20 Jul 24, 2026
71f5d2d
Update README.md
TheRealKCFan20 Jul 24, 2026
763c249
Update README.md
TheRealKCFan20 Jul 24, 2026
1371869
Update README.md
TheRealKCFan20 Jul 24, 2026
49abe77
Update README.md
TheRealKCFan20 Jul 24, 2026
f1e0e08
Update README.md
TheRealKCFan20 Jul 24, 2026
1813058
Update README.md
TheRealKCFan20 Jul 24, 2026
1c8a500
Update README.md
TheRealKCFan20 Jul 24, 2026
2aa8414
Update README.md
TheRealKCFan20 Jul 24, 2026
be3f9ce
Update index.html
TheRealKCFan20 Jul 26, 2026
7adee7a
oops
TheRealKCFan20 Jul 26, 2026
1b3e5dc
oops (again)
TheRealKCFan20 Jul 26, 2026
e8e79a1
Update index.html
TheRealKCFan20 Jul 27, 2026
6b7ae6d
Update README.md to remove logo and add Grunt
TheRealKCFan20 Aug 3, 2026
427e223
Reformat README.md with updated content
TheRealKCFan20 Aug 3, 2026
cfd6478
Add title and tagline to README
TheRealKCFan20 Aug 3, 2026
1aa36ef
Fix typo in README.md
TheRealKCFan20 Aug 3, 2026
026122d
Update '/notice' command description in README
TheRealKCFan20 Aug 3, 2026
013131b
Revise usage instructions and formatting in README
TheRealKCFan20 Aug 3, 2026
62b2e70
Fix formatting and update dependencies in README
TheRealKCFan20 Aug 3, 2026
663ba51
Update README with revised update message
TheRealKCFan20 Aug 3, 2026
042b6ba
Clarify parody status of BonziWORLD website
TheRealKCFan20 Aug 3, 2026
4f43d5b
Update README with project description
TheRealKCFan20 Aug 3, 2026
e4df8a9
Revise usage steps in README.md
TheRealKCFan20 Aug 3, 2026
c3d0d23
Add clarification about name character limit
TheRealKCFan20 Aug 3, 2026
e8732aa
Clarify max participants in public and private lobbies
TheRealKCFan20 Aug 3, 2026
c3bb566
Revise acknowledgment message in README
TheRealKCFan20 Aug 3, 2026
b4500af
Add user count display in room info section
TheRealKCFan20 Aug 3, 2026
bf505a9
Remove user count and update kick message
TheRealKCFan20 Aug 3, 2026
cd5fb08
Replace socket.io-1.4.5.js with socket.io.js
TheRealKCFan20 Aug 3, 2026
bc09ec5
Set login page to display by default
TheRealKCFan20 Aug 3, 2026
34cc564
Clarify lobby capacity limits in README
TheRealKCFan20 Aug 3, 2026
e1749e3
Delete src/www/img/thumbnails/note.txt
TheRealKCFan20 Aug 3, 2026
bb61817
Reformat README.md with Markdown syntax
TheRealKCFan20 Aug 3, 2026
f9fd897
Fix formatting and add optional Grunt dependency
TheRealKCFan20 Aug 3, 2026
b65410b
Reformat README.md with proper markdown syntax
TheRealKCFan20 Aug 3, 2026
dc629d7
Create FUNDING.yml for sponsorship options
TheRealKCFan20 Aug 3, 2026
d7ada95
Update README with nginx server setup instructions
TheRealKCFan20 Aug 3, 2026
e0379c0
Restore README.md content
TheRealKCFan20 Aug 3, 2026
1f4a5c4
Fix formatting issues in README.md
TheRealKCFan20 Aug 3, 2026
22ee708
Update README.md
TheRealKCFan20 Aug 3, 2026
0c57b81
Fix README: replace mismatched YouTube link with an nginx reverse-pro…
TheRealKCFan20 Aug 3, 2026
61cc642
Revise README with updated links and tutorial
TheRealKCFan20 Aug 3, 2026
45040a9
Revise nginx tutorial link in README
TheRealKCFan20 Aug 3, 2026
9aef544
Fix link title for Nginx reverse proxy tutorial
TheRealKCFan20 Aug 3, 2026
cfd762f
Add nginx reverse proxy tutorial to README
TheRealKCFan20 Aug 3, 2026
9783d86
Update README to remove nginx section
TheRealKCFan20 Aug 3, 2026
40e8d90
Readd tutorial link to server setup instructions
TheRealKCFan20 Aug 3, 2026
3d6c198
Update bee event list with animations and cleanup
TheRealKCFan20 Aug 3, 2026
6a07000
Update iframe dimensions for YouTube embed
TheRealKCFan20 Aug 3, 2026
5d2d7e8
Fix text formatting in notice method
TheRealKCFan20 Aug 3, 2026
ec0c9ce
Update README with public lobby capacity details
TheRealKCFan20 Aug 4, 2026
c2666f0
Add Winston to the list of dependencies
TheRealKCFan20 Aug 4, 2026
f6f4a0d
Update public lobby participant limit explanation
TheRealKCFan20 Aug 4, 2026
2bafe25
Fix formatting for private lobby limit
TheRealKCFan20 Aug 4, 2026
2043bbf
Update files via upload
TheRealKCFan20 Aug 4, 2026
16f0409
Add 'sorry' image to old readme directory
TheRealKCFan20 Aug 4, 2026
fa74819
Delete src/www/img/readme/old/sorry
TheRealKCFan20 Aug 4, 2026
959bf4d
Add new file wat.txt with placeholder content
TheRealKCFan20 Aug 4, 2026
fe1f632
Changed the logo back to normal.
TheRealKCFan20 Aug 4, 2026
7a8f17c
oops
TheRealKCFan20 Aug 4, 2026
67cf6a3
Update fmt.Println message from 'Hello' to 'Goodbye'
TheRealKCFan20 Aug 4, 2026
4de4b1e
Update print statement from 'Hello' to 'Goodbye'
TheRealKCFan20 Aug 4, 2026
05b0db6
Fix typo in README commands description
TheRealKCFan20 Aug 4, 2026
6e21ff3
Add subtitle to README
TheRealKCFan20 Aug 5, 2026
ce76b63
Revise README title and subtitle
TheRealKCFan20 Aug 5, 2026
b53c7e2
Fix heading format in README.md
TheRealKCFan20 Aug 5, 2026
24c3d2b
Update README header by removing subtitle
TheRealKCFan20 Aug 5, 2026
d6a81ce
Fix typos in README.md
TheRealKCFan20 Aug 5, 2026
d202a0c
Fix typo in README about project discontinuation
TheRealKCFan20 Aug 5, 2026
eedc9db
Fix typo in README regarding public availability
TheRealKCFan20 Aug 5, 2026
cc8de63
Update changelog entry for version 1.6.1
TheRealKCFan20 Aug 6, 2026
771f4f1
Update sanitization rules in README
TheRealKCFan20 Aug 6, 2026
8acfe7f
Update Sass to Scss/Sass in dependencies
TheRealKCFan20 Aug 6, 2026
1abd9fb
Update content and formatting in RULES.md
TheRealKCFan20 Aug 6, 2026
de69cab
Refactor rules for clarity and conciseness
TheRealKCFan20 Aug 6, 2026
29e3909
Fix login button: call login directly instead of loadTest to avoid st…
TheRealKCFan20 Aug 6, 2026
2d118b3
Change loading interval from 100ms to 1000ms (1 second)
TheRealKCFan20 Aug 6, 2026
c043b75
Fix login button: change click handler from login() to loadTest()
TheRealKCFan20 Aug 6, 2026
6c849ec
Update iframe dimensions in bonzi.es2015
TheRealKCFan20 Aug 10, 2026
b76a53e
Add unbojih.png
UnbojihTheGamer Aug 11, 2026
6cd9b4a
Update README.md
UnbojihTheGamer Aug 11, 2026
2603aa2
Update CHANGELOG.md
UnbojihTheGamer Aug 11, 2026
bb8395f
NEW COLOR!
UnbojihTheGamer Aug 11, 2026
985e4ed
Update README.md
UnbojihTheGamer Aug 11, 2026
b3c2f98
I forgot about that!
UnbojihTheGamer Aug 11, 2026
f1847cf
Update README.md
UnbojihTheGamer Aug 11, 2026
90b502f
Update README.md
UnbojihTheGamer Aug 11, 2026
7a5ce6c
i tried
UnbojihTheGamer Aug 11, 2026
226d504
Add Render deployment steps to README
TheRealKCFan20 Aug 11, 2026
c01539b
Update README.md
UnbojihTheGamer Aug 11, 2026
0352d37
Update README.md
UnbojihTheGamer Aug 11, 2026
1b00b3a
Update README.md
UnbojihTheGamer Aug 11, 2026
7b6ffff
Update Deno workflow branches to 1.6.1
TheRealKCFan20 Aug 11, 2026
581e7bc
Update branch version in static.yml workflow
TheRealKCFan20 Aug 11, 2026
abd5c1d
Update README to remove personal note
TheRealKCFan20 Aug 11, 2026
eb0a02d
Update README to remove gratitude statement
TheRealKCFan20 Aug 11, 2026
66eb708
Update README.md
UnbojihTheGamer Aug 12, 2026
0b63e99
oops
UnbojihTheGamer Aug 13, 2026
c54c690
Revise project discontinuation message
TheRealKCFan20 Aug 13, 2026
a586e7a
Clean up launch.json by removing comments
TheRealKCFan20 Aug 14, 2026
ff2b4b1
Fix typo in project discontinuation statement
TheRealKCFan20 Aug 14, 2026
244b09e
According to all known laws of aviation, there is no way a bee should…
TheRealKCFan20 Aug 14, 2026
0cea9f5
Add build folder
TheRealKCFan20 Aug 14, 2026
336028b
Update README to remove client setup section
TheRealKCFan20 Aug 14, 2026
0663db7
Remove build folder
TheRealKCFan20 Aug 14, 2026
3157719
Update repository URL in README setup instructions
TheRealKCFan20 Aug 14, 2026
5a19ca5
Update contact email in README.md
TheRealKCFan20 Aug 14, 2026
2732afd
Change copyright to The Real Klasky Csupo Fan 20, Inc.
TheRealKCFan20 Aug 14, 2026
30b401f
Update copyright notice in README.md
TheRealKCFan20 Aug 14, 2026
a9dc46c
Create CNAME
TheRealKCFan20 Aug 14, 2026
23fa7dc
Delete CNAME
TheRealKCFan20 Aug 14, 2026
dcb8ac4
Add Jekyll GitHub Pages deployment workflow
TheRealKCFan20 Aug 14, 2026
2a69aea
Delete .github/workflows/static.yml
TheRealKCFan20 Aug 14, 2026
ccd6d9e
Add GitHub Actions workflow for static content deployment
TheRealKCFan20 Aug 14, 2026
f4e793e
Delete .github/workflows/deno.yml
TheRealKCFan20 Aug 14, 2026
47f6ed1
Add initial platform.css file
TheRealKCFan20 Aug 14, 2026
57c9a8f
Delete empty comment in platform.css
TheRealKCFan20 Aug 14, 2026
d1da611
Readd Deno CI workflow for linting and testing
TheRealKCFan20 Aug 15, 2026
fe36652
Add GitHub Actions workflow for npm package publishing
TheRealKCFan20 Aug 15, 2026
91fcbfd
Add Node.js CI workflow for testing and building
TheRealKCFan20 Aug 15, 2026
2a0b15f
Add GitHub Actions workflow for Node.js with Webpack
TheRealKCFan20 Aug 15, 2026
05d364c
Update README.md
BonziPOPE Aug 16, 2026
c85f64b
Update README.md
BonziPOPE Aug 16, 2026
b4ed109
Update README.md
BonziPOPE Aug 16, 2026
fd6105b
Update README.md
BonziPOPE Aug 16, 2026
594c008
Update README to include virus script reference
TheRealKCFan20 Aug 16, 2026
04c138a
Update README.md for clarity on repository status
TheRealKCFan20 Aug 16, 2026
a028104
Update README.md
BonziPOPE Aug 17, 2026
9d88b15
Add CI workflow for TheRealKCFan20
TheRealKCFan20 Aug 17, 2026
286cdea
Revise project status and disassociation statement
TheRealKCFan20 Aug 17, 2026
40e4748
Update README to remove irrelevant complaints section
TheRealKCFan20 Aug 17, 2026
39a0c8a
Update README with creator details and release date
TheRealKCFan20 Aug 17, 2026
eba383f
Fix wording and remove redundant phrases in README
TheRealKCFan20 Aug 17, 2026
d36fa0f
Update README with optional room ID clarification
TheRealKCFan20 Aug 17, 2026
b3fd877
Improve wording in contact email section
TheRealKCFan20 Aug 17, 2026
0635b42
Fix typo in email response warning
TheRealKCFan20 Aug 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .github/FUNDING.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# These are supported funding model platforms

github: # Replace with up to 4 GitHub Sponsors-enabled usernames e.g., [user1, user2]
patreon: # Replace with a single Patreon username
open_collective: # Replace with a single Open Collective username
ko_fi: # Replace with a single Ko-fi username
tidelift: # Replace with a single Tidelift platform-name/package-name e.g., npm/babel
community_bridge: # Replace with a single Community Bridge project-name e.g., cloud-foundry
liberapay: # Replace with a single Liberapay username
issuehunt: # Replace with a single IssueHunt username
lfx_crowdfunding: # Replace with a single LFX Crowdfunding project-name e.g., cloud-foundry
polar: # Replace with a single Polar username
buy_me_a_coffee: # Replace with a single Buy Me a Coffee username
thanks_dev: # Replace with a single thanks.dev username
custom: # Replace with up to 4 custom sponsorship URLs e.g., ['link1', 'link2']
42 changes: 42 additions & 0 deletions .github/workflows/deno.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# This workflow uses actions that are not certified by GitHub.
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
# documentation.

# This workflow will install Deno then run `deno lint` and `deno test`.
# For more information see: https://github.com/denoland/setup-deno

name: Deno

on:
push:
branches: ["1.6.0"]
pull_request:
branches: ["1.6.0"]

permissions:
contents: read

jobs:
test:
runs-on: ubuntu-latest

steps:
- name: Setup repo
uses: actions/checkout@v4
Comment on lines +25 to +26

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu
printf '%s\n' '--- checkout steps ---'
cat -n .github/workflows/deno.yml | sed -n '18,36p'
cat -n .github/workflows/static.yml | sed -n '25,43p'
printf '%s\n' '--- credential-related workflow settings ---'
rg -n -C 3 'persist-credentials|checkout@|GITHUB_TOKEN|git config|upload-artifact|artifact' .github/workflows

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 2976


🌐 Web query:

actions/checkout v4 persist-credentials false default GITHUB_TOKEN .git/config documentation

💡 Result:

In GitHub Actions, the actions/checkout action (including version 4) uses the persist-credentials input to control whether the authentication token (such as GITHUB_TOKEN) or SSH key is configured in the local Git environment [1][2]. Default Behavior: By default, persist-credentials is set to true [2]. When enabled, the action configures the authentication credentials into the local Git environment so that subsequent steps in the same job can execute authenticated Git commands (e.g., git push, git fetch) without needing to manually provide credentials again [1][3]. How it works with.git/config: In actions/checkout v4, the credentials are typically associated with the repository's Git configuration, which allows the runner's Git commands to automatically use the token [1][4]. Because these credentials persist on the runner's disk during the job, there is a risk that subsequent steps might inadvertently leak them—for example, if a step archives or uploads the workspace directory (including the .git folder) as a build artifact [5][4]. Using persist-credentials: false: Setting persist-credentials: false in your workflow YAML prevents the action from configuring these credentials [1][5]. This is a security best practice if your job does not require subsequent authenticated Git operations, as it reduces the attack surface for credential leakage [4]. Example configuration: - uses: actions/checkout@v4 with: persist-credentials: false If you disable this, any subsequent Git commands in your workflow that require authentication will fail unless you manually configure alternative credentials [3]. Note on newer versions: In newer iterations of actions/checkout (such as v6+), the mechanism has been updated to store credentials in a separate file within $RUNNER_TEMP rather than directly inside .git/config to improve security, though persist-credentials: false remains the recommended way to opt out of credential persistence entirely [6][4].

Citations:


🏁 Script executed:

#!/bin/bash
set -eu
printf '%s\n' '--- complete workflow bodies ---'
cat -n .github/workflows/deno.yml
cat -n .github/workflows/static.yml
printf '%s\n' '--- repository references to workflow commands and artifacts ---'
rg -n -C 2 'deno test|deno fmt|run:|upload-pages-artifact|upload-artifact|tar|zip|\.git' .github README.md 2>/dev/null || true

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 4600


🌐 Web query:

actions/upload-pages-artifact v3 excludes .git directory artifact source code

💡 Result:

Yes, the actions/upload-pages-artifact action (including version v3) unconditionally excludes the.git directory from the generated artifact [1][2][3]. The action operates as a composite action that archives your static files into a tarball before uploading [2][4]. During this archiving process, the action explicitly uses command-line tar flags to exclude the.git directory and the.github directory, regardless of other configuration settings [2][3]. Specifically, the action's implementation includes the following exclusion patterns in its archival step [2]: --exclude=.git --exclude=.github Even if you enable the include-hidden-files input, which allows other hidden files (those starting with a dot) to be included in the artifact, the.git and.github directories remain unconditionally excluded [1][3].

Citations:


Disable persisted GitHub credentials in the Deno workflow checkout.

deno test -A can read the persisted GITHUB_TOKEN from the Git configuration. Add persist-credentials: false to .github/workflows/deno.yml.

The Pages artifact action excludes .git, so this concern is not confirmed for .github/workflows/static.yml.

🧰 Tools
🪛 zizmor (1.29.0)

[warning] 25-26: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

📍 Affects 2 files
  • .github/workflows/deno.yml#L25-L26 (this comment)
  • .github/workflows/static.yml#L32-L33
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/deno.yml around lines 25 - 26, Update the checkout step
using actions/checkout@v4 in .github/workflows/deno.yml at lines 25-26 to set
persist-credentials to false. Make no direct change to the checkout step in
.github/workflows/static.yml at lines 32-33, since the Pages artifact excludes
.git.

Source: Linters/SAST tools


- name: Setup Deno
# uses: denoland/setup-deno@v1
uses: denoland/setup-deno@61fe2df320078202e33d7d5ad347e7dcfa0e8f31 # v1.1.2
with:
deno-version: v1.x

# Uncomment this step to verify the use of 'deno fmt' on each commit.
# - name: Verify formatting
# run: deno fmt --check

- name: Run linter
run: deno lint

- name: Run tests
run: deno test -A
Comment on lines +41 to +42

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu

printf '%s\n' '--- workflow ---'
cat -n .github/workflows/deno.yml

printf '%s\n' '--- repository files relevant to Deno tests ---'
git ls-files | rg '(^|/)(deno\.jsonc?|deno\.lock|.*\.(ts|tsx|js|jsx)$)' | head -200

printf '%s\n' '--- workflow triggers and permissions ---'
rg -n -C 3 '^(on:|  pull_request|  push|permissions:|  permissions:|deno test|uses:)' .github/workflows/deno.yml

printf '%s\n' '--- test commands and permission-sensitive APIs ---'
rg -n -C 2 'deno test|Deno\.(read|write|env|listen|connect|run|Command|serve)|fetch\(' . --glob '!node_modules' --glob '!dist' --glob '!build' | head -300

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 2643


🏁 Script executed:

#!/bin/bash
set -eu

printf '%s\n' '--- complete tracked-file inventory ---'
git ls-files | sed -n '1,300p'

printf '%s\n' '--- test-like files and Deno configuration ---'
git ls-files | rg -i '(^|/)(deno\.json(c)?|.*(^|[_./-])test([s._/-]|$).*\.(js|jsx|ts|tsx|mjs|cjs)$|.*_test\.(js|jsx|ts|tsx|mjs|cjs)$)' || true

printf '%s\n' '--- all permission-sensitive calls in tracked source files ---'
git grep -n -E 'Deno\.(read|write|env|listen|connect|run|Command|serve|open|remove|mkdir|create|chmod|chown|symlink|link|stat|lstat|readTextFile|writeTextFile)|fetch\(' -- '*.js' '*.jsx' '*.ts' '*.tsx' '*.mjs' '*.cjs' || true

printf '%s\n' '--- repository metadata and workflow history summary ---'
git ls-files -z | xargs -0 grep -Il -E 'deno test|Deno\.test|_test\.(js|ts)' 2>/dev/null || true
git status --short

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 5116


🌐 Web query:

Deno CLI documentation -A allow-all permissions deno test

💡 Result:

To run tests in Deno with full system permissions, you can use the --allow-all flag, which is synonymous with the -A flag [1][2]. When executing tests with the Deno CLI, passing --allow-all or -A disables the security sandbox for the test process, granting it unrestricted access to system resources such as the file system, network, and environment variables [1][2]. Example command: deno test --allow-all Key points regarding permissions and deno test: 1. Permission Inheritance: Deno runs code in a secure sandbox by default [2]. Any permission required by your test code must be explicitly granted via CLI flags (e.g., --allow-read, --allow-net) when running deno test [3][2]. 2. Scoping: It is recommended to use granular permissions (e.g., --allow-read=/tmp) rather than --allow-all to maintain the security benefits of the Deno runtime [2]. 3. Configuration Files: You can define sets of permissions in your deno.json file and reference them using the -P flag when running deno test, which provides a more manageable way to handle complex permission requirements across different environments [4]. 4. Documentation Tests: If you are running documentation tests (tests embedded in code comments), these also respect the permissions granted to the parent deno test process. They cannot be granted broader permissions than those provided to the initial command [5]. For more details on specific permission types and the security model, refer to the official Deno documentation on permissions [1][6].

Citations:


Restrict Deno test permissions.

This pull_request job executes contributor-controlled test files. -A (--allow-all) disables Deno’s sandbox. Run deno test without -A, or grant only required scoped --allow-* permissions.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/deno.yml around lines 41 - 42, Update the “Run tests” step
in the pull_request workflow to remove the unrestricted -A permission flag. Run
deno test without broad permissions, or specify only the narrowly scoped
--allow-* permissions required by the test suite.

43 changes: 43 additions & 0 deletions .github/workflows/static.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# Simple workflow for deploying static content to GitHub Pages
name: Deploy static content to Pages

on:
# Runs on pushes targeting the default branch
push:
branches: ["1.6.0"]

# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:

# Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages
permissions:
contents: read
pages: write
id-token: write

# Allow only one concurrent deployment, skipping runs queued between the run in-progress and latest queued.
# However, do NOT cancel in-progress runs as we want to allow these production deployments to complete.
concurrency:
group: "pages"
cancel-in-progress: false

jobs:
# Single deploy job since we're just deploying
deploy:
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Pages
uses: actions/configure-pages@v5
- name: Upload artifact
uses: actions/upload-pages-artifact@v3
with:
# Upload entire repository
path: '.'
Comment on lines +36 to +40

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Upload the generated site, not the repository.

The supplied src/Gruntfile.js context defines the web output as build/www. This workflow does not run the client build and uploads . instead. GitHub Pages will receive the repository tree rather than the generated web root.

Build the client before uploading and set the artifact path to build/www.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/static.yml around lines 36 - 40, Update the workflow
around the Upload artifact step to run the client build using the repository’s
existing build configuration before artifact upload, then change the
upload-pages-artifact path from the repository root to build/www so GitHub Pages
receives the generated site.

- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v5
21 changes: 21 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright © 2000-2026 Felipe Angelo, Inc.

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
117 changes: 74 additions & 43 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,43 +1,74 @@
# BonziWORLD Patched

This respository is a fork of the [original](https://github.com/heyjoeway/BonziWORLD). It will be updated frequently to be fully secure and fix problems with either the server or the client.

This project was discontinued by heyjoeway due to his time being taken up by other responsibilities.

All the source code for the server and client is publically available here. If you want to run your own BonziWORLD, by all means go ahead. Do whatever you'd like with this code. Just try to put me somewhere in the credits.

## Dependencies
- Node.js and npm
- Ruby
- Sass
- Git
- Cordova (Optional)

## Setup
In a terminal/command prompt, navigate to where you'd like BonziWORLD to be placed and run the following:
```
git clone https://github.com/Seamusmario/BonziWORLD-patched
cd BonziWORLD-patched
```

### Client
```
cd src
npm install
grunt build_www
cd ..
```

### Server
```
cd server
npm install
node index.js
```
After this, BonziWORLD will be accessible on port 3000. (http://localhost:3000/)

## Disclaimer
I'm not responsible if you screw up anything with your computer while setting this up. I have no idea how you would, but someone will find a way. I also will not provide support for installing dependencies. If you have everything installed properly, the above commands will work.

## License
MIT
# BonziWORLD

This repository is a fork of the [original](https://github.com/heyjoeway/BonziWORLD), [patched](https://github.com/duckduckstab1/BonziWORLD-patched), and [fully patched](https://github.com/Rafafrias20[...]

This project was discontinued by heyjoeway due to his time being taken up by other repositories.

All the source code for the server and client is publicly available here. If you want to run your own BonziWORLD, by all means go ahead. Do whatever you'd like with this code. _Just try to put me some[...]

## Dependencies
- Node.js and npm
- Ruby
- Scss/Sass
- Git
- Cordova (Optional)
- Grunt
- Winston

## Setup
In a terminal and/or command prompt, navigate to where you'd like BonziWORLD to be placed and run the following:
```
git clone https://github.com/felipeangeloben-create/BonziWORLD
cd BonziWORLD
```

### Client
```
cd src
npm install
grunt build_www
cd ..
```

### Server
```
cd server
npm install
node index.js
```
### Server (nginx)
<pre><span><code>Check out this <a href="https://www.youtube.com/watch?v=krcYPrjIDzU" alt="Tutorial" title="Tutorial">tutorial</a> below.
</code></span></pre>

### Deploy GitHub Project on Render
You can deploy this project on Render (https://render.com) for automatic builds and hosted runtime. The steps below guide you through a simple Web Service deployment that builds the client and runs the Node server.

1. Create a Render account and connect your GitHub account.
2. In Render, click New -> Web Service and select the `felipeangeloben-create/BonziWORLD` repository (choose the branch you want to deploy).
3. Configure the service:
- Environment: Node
- Build Command:
```bash
# from the repository root, build the client and install server deps
bash -lc "cd src && npm install && npx grunt build_www && cd ../server && npm install"
```
- Start Command:
```bash
node server/index.js
```
- Instance Type / Plan: choose according to your traffic needs (Free tier available on Render).
4. Environment variables (optional): If your server expects any secrets or environment variables (e.g. session secrets, API keys), add them under Environment in Render.
5. Port handling: Render provides a PORT environment variable for web services. Ensure `server/index.js` uses `process.env.PORT || 3000` when binding the HTTP server. If it does not, update the server code to read `process.env.PORT` so Render can route traffic properly.
6. Deploy: click Create Web Service. Render will run the build command and start the service. Subsequent pushes to the selected branch will trigger automatic deploys.

Notes:
- The build command above uses `npx grunt` so you don't need a global Grunt CLI install on Render. If your repo defines npm scripts to build the client or start the server, you can replace the Build/Start commands with those scripts.
- If you need HTTPS, custom domains, or background workers, Render provides those features in the service settings.

After that, BonziWORLD will be accessible on port 3000. (http://localhost:3000/)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Correct the Render port and URL instructions.

Line 61 tells maintainers to change server/index.js to use process.env.PORT || 3000, but server/index.js:48-72 already uses process.env.PORT || settings.port. Document the existing behavior instead.

Line 68 places http://localhost:3000/ after the Render deployment steps. That URL applies to local execution. Direct Render users to the service URL shown by Render.

Proposed documentation fix
-5. Port handling: Render provides a PORT environment variable for web services. Ensure `server/index.js` uses `process.env.PORT || 3000` when binding the HTTP server. If it does not, update the server code to read `process.env.PORT` so Render can route traffic properly.
+5. Port handling: Render provides the `PORT` environment variable. `server/index.js` reads `process.env.PORT || settings.port`, so no additional port change is required.

-After that, BonziWORLD will be accessible on port 3000. (http://localhost:3000/)
+For local runs, open `http://localhost:3000/` when `settings.port` is 3000. For Render, open the public service URL provided by Render.
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
5. Port handling: Render provides a PORT environment variable for web services. Ensure `server/index.js` uses `process.env.PORT || 3000` when binding the HTTP server. If it does not, update the server code to read `process.env.PORT` so Render can route traffic properly.
6. Deploy: click Create Web Service. Render will run the build command and start the service. Subsequent pushes to the selected branch will trigger automatic deploys.
Notes:
- The build command above uses `npx grunt` so you don't need a global Grunt CLI install on Render. If your repo defines npm scripts to build the client or start the server, you can replace the Build/Start commands with those scripts.
- If you need HTTPS, custom domains, or background workers, Render provides those features in the service settings.
After that, BonziWORLD will be accessible on port 3000. (http://localhost:3000/)
5. Port handling: Render provides the `PORT` environment variable. `server/index.js` reads `process.env.PORT || settings.port`, so no additional port change is required.
6. Deploy: click Create Web Service. Render will run the build command and start the service. Subsequent pushes to the selected branch will trigger automatic deploys.
Notes:
- The build command above uses `npx grunt` so you don't need a global Grunt CLI install on Render. If your repo defines npm scripts to build the client or start the server, you can replace the Build/Start commands with those scripts.
- If you need HTTPS, custom domains, or background workers, Render provides those features in the service settings.
For local runs, open `http://localhost:3000/` when `settings.port` is 3000. For Render, open the public service URL provided by Render.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@README.md` around lines 61 - 68, Update the Render deployment instructions to
document that server/index.js already binds using process.env.PORT ||
settings.port, removing the request to modify it. Replace the post-deployment
localhost:3000 URL with guidance to use the service URL provided by Render,
while retaining localhost:3000 only for local execution.


## Disclaimer
I'm not responsible if you screw up anything with your computer while setting this up. I have no idea how you would, but someone will find a way. I also will not provide support for installing depende[...]

## License
MIT
17 changes: 8 additions & 9 deletions server/ban.js
Original file line number Diff line number Diff line change
Expand Up @@ -7,14 +7,13 @@ const io = require('./index.js').io;
let bans;

exports.init = function() {
fs.writeFile("./bans.json", "{}", { flag: 'wx' }, function(err) {
if (!err) console.log("Created empty bans list.");
try {
bans = require("./bans.json");
} catch(e) {
throw "Could not load bans.json. Check syntax and permissions.";
}
});
try {
let content = fs.readFileSync("./bans.json", "utf8").trim();
bans = content ? JSON.parse(content) : {};
} catch(e) {
bans = {};
}
fs.writeFileSync("./bans.json", JSON.stringify(bans));
Comment on lines +10 to +16

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Do not overwrite a ban list after a read or parse failure.

A malformed or unreadable bans.json sets bans to {}. Line 16 then overwrites the existing file. This removes all bans and permits previously banned clients to reconnect.

Only create a new file for ENOENT. Fail startup, or preserve and report the file, for other errors.

Proposed fix
 exports.init = function() {
+    let content;
     try {
-        let content = fs.readFileSync("./bans.json", "utf8").trim();
+        content = fs.readFileSync("./bans.json", "utf8").trim();
         bans = content ? JSON.parse(content) : {};
     } catch(e) {
+        if (e.code !== "ENOENT") throw e;
         bans = {};
     }
     fs.writeFileSync("./bans.json", JSON.stringify(bans));
 };
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
try {
let content = fs.readFileSync("./bans.json", "utf8").trim();
bans = content ? JSON.parse(content) : {};
} catch(e) {
bans = {};
}
fs.writeFileSync("./bans.json", JSON.stringify(bans));
let content;
try {
content = fs.readFileSync("./bans.json", "utf8").trim();
bans = content ? JSON.parse(content) : {};
} catch(e) {
if (e.code !== "ENOENT") throw e;
bans = {};
}
fs.writeFileSync("./bans.json", JSON.stringify(bans));
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@server/ban.js` around lines 10 - 16, Update the ban-list initialization
around the read/parse flow so only an ENOENT from reading bans.json creates an
empty list and permits writing a new file. For malformed JSON or any other read
error, preserve the existing file and fail startup or report the error instead
of assigning {} and reaching fs.writeFileSync; keep normal successful parsing
unchanged.

};

exports.saveBans = function() {
Expand Down Expand Up @@ -90,4 +89,4 @@ exports.kick = function(ip, reason) {

exports.isBanned = function(ip) {
return Object.keys(bans).indexOf(ip) != -1;
};
};
9 changes: 7 additions & 2 deletions server/console.js
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,12 @@ let commands = {
}

exports.listen = function() {
process.openStdin().addListener("data", function(input) {
// Only attach stdin listener when running interactively (TTY).
// In Replit's workflow runner stdin is a closed pipe; calling
// process.openStdin() there causes an immediate EOF that exits Node.
if (!process.stdin.isTTY) return;
process.stdin.resume();
process.stdin.addListener("data", function(input) {
try {
let list = input.toString().trim().split(" ");
let command = list[0].toLowerCase();
Expand All @@ -74,4 +79,4 @@ exports.listen = function() {
console.log(e);
}
});
}
}
11 changes: 8 additions & 3 deletions server/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,12 @@ if (settings.express.serveStatic)
var server = require('http').createServer(app);

// Init socket.io
var io = require('socket.io')(server);
var io = require('socket.io')(server, {
cors: {
origin: "*",
methods: ["GET", "POST"]
}
});
var port = process.env.PORT || settings.port;

exports.io = io;
Expand All @@ -57,7 +62,7 @@ const Ban = require('./ban.js');
Ban.init();

// Start actually listening
server.listen(port, function () {
server.listen(port, '0.0.0.0', function () {
console.log(
" Welcome to BonziWORLD!\n",
"Time to meme!\n",
Expand Down Expand Up @@ -86,4 +91,4 @@ Meat.beat();

// Console commands
const Console = require('./console.js');
Console.listen();
Console.listen();
14 changes: 8 additions & 6 deletions server/meat.js
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,9 @@ const Utils = require("./utils.js");
const io = require('./index.js').io;
const settings = require("./settings.json");
const sanitize = require('sanitize-html');
const Profanity = require('./profanity.js');

let roomsPublic = [];
let roomsPublic = ["default"];

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

ast-grep outline server/meat.js --items all
rg -n -C 6 'newRoom\s*\(|roomsPublic|["'\'']default["'\'']|prefs\.(public|private)' \
  server/meat.js server/index.js src/www/js/main.js

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 5727


Initialize the default room with public preferences before login.

src/www/js/main.js submits "default" explicitly. No startup path creates rooms.default; an explicit missing room is created during login with settings.prefs.private, while roomsPublic still marks it as public.

  • server/meat.js#L9-LL9: call newRoom("default", settings.prefs.public) during startup.
  • src/www/js/main.js#L41-L41: retain "default" after the server creates it as a public room.
📍 Affects 2 files
  • server/meat.js#L9-L9 (this comment)
  • src/www/js/main.js#L41-L41
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@server/meat.js` at line 9, Initialize the "default" room during server
startup via newRoom("default", settings.prefs.public) in server/meat.js lines
9-9, ensuring it uses public preferences before login. Retain the explicit
"default" submission in src/www/js/main.js lines 41-41; no change is required
there because it must continue targeting the server-created public room.

let rooms = {};
let usersAll = [];

Expand Down Expand Up @@ -168,7 +169,7 @@ let userCommands = {
});
},
"linux": "passthrough",
"pawn": "passthrough",
"intro": "passthrough",
"bees": "passthrough",
"color": function(color) {
if (typeof color != "undefined") {
Expand All @@ -189,14 +190,14 @@ let userCommands = {
this.public.color = "pope";
this.room.updateUser(this);
},
"asshole": function() {
this.room.emit("asshole", {
"stink": function() {
this.room.emit("stink", {
guid: this.guid,
target: sanitize(Utils.argsString(arguments))
});
},
"owo": function() {
this.room.emit("owo", {
"notice": function() {
this.room.emit("notice", {
guid: this.guid,
target: sanitize(Utils.argsString(arguments))
});
Expand Down Expand Up @@ -417,6 +418,7 @@ class User {
return;

let text = this.private.sanitize ? sanitize(data.text) : data.text;
text = Profanity.filter(text);
if ((text.length <= this.room.prefs.char_limit) && (text.length > 0)) {
this.room.emit('talk', {
guid: this.guid,
Expand Down
2 changes: 1 addition & 1 deletion server/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@
"fs-extra": "^7.0.1",
"merge": "^1.2.1",
"sanitize-html": "^1.20.0",
"socket.io": "^2.2.0",
"socket.io": "^4.6.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

ast-grep outline src/www/js_ext/lib/socket.io.js --items all
rg -n -C 3 'Socket\.IO|socket\.io|EIO=|protocol|allowEIO3' \
  src/www/js_ext/lib/socket.io.js server/index.js server/package.json

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 50388


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '--- server/package.json ---'
cat -n server/package.json

printf '%s\n' '--- server/index.js Socket.IO setup and usage ---'
rg -n -C 8 'require\(["'\'']socket\.io|io\s*=|io\.on|socket\.on|allowEIO3|cors' server/index.js

printf '%s\n' '--- bundled client fingerprints ---'
python3 - <<'PY'
from pathlib import Path
p = Path("src/www/js_ext/lib/socket.io.js")
s = p.read_text(errors="replace")
for needle in (
    'exports.protocol=',
    'parser.protocol=',
    'protocol=',
    'Socket.IO',
    'socket.io-client',
    'engine.io-client',
    'io=function',
    'Manager.prototype',
):
    positions = [i for i in range(len(s)) if s.startswith(needle, i)]
    print(needle, len(positions), positions[:5])
print("size", len(s))
PY

printf '%s\n' '--- dependency manifests ---'
git ls-files '*package*.json' '*lock*' | sort
rg -n -C 2 '"socket\.io"|socket\.io-client|engine\.io|allowEIO3' --glob '*package*.json' --glob '*lock*' .

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 6007


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '--- lockfile root and Socket.IO entries ---'
sed -n '1,45p' server/package-lock.json
sed -n '840,905p' server/package-lock.json

printf '%s\n' '--- client bundle usage ---'
rg -n -C 4 'js_ext/lib/socket\.io\.js|socket\.io\.js|io\(' src build www server --glob '*.html' --glob '*.js' --glob '*.json' 2>/dev/null || true

printf '%s\n' '--- bundle version/protocol markers ---'
python3 - <<'PY'
from pathlib import Path
import re
s = Path("src/www/js_ext/lib/socket.io.js").read_text(errors="replace")
patterns = {
    "engine_protocol_3": r'exports\.protocol=3',
    "engine_protocol_4": r'exports\.protocol=4',
    "socket_io_client_2_version": r'(?:version|VERSION)[^\\n]{0,80}2\.[0-9]+\.[0-9]+',
    "socket_io_client_4_version": r'(?:version|VERSION)[^\\n]{0,80}4\.[0-9]+\.[0-9]+',
    "socket_io_manager": r'Manager\.prototype',
}
for name, pattern in patterns.items():
    matches = list(re.finditer(pattern, s, re.I))
    print(name, len(matches))
    for m in matches[:3]:
        print(" ", repr(s[max(0, m.start()-80):m.end()+100]))
PY

printf '%s\n' '--- package-lock metadata ---'
python3 - <<'PY'
import json
from pathlib import Path
d = json.loads(Path("server/package-lock.json").read_text())
print("lockfileVersion:", d.get("lockfileVersion"))
print("root dependencies:", d.get("dependencies", {}).get("socket.io", {}))
PY

Repository: Rafafrias2012/BonziWORLD-patched

Length of output: 50389


Update the Socket.IO dependency set and browser bundle.

When the server installs Socket.IO 4, src/www/js_ext/lib/socket.io.js sends Engine.IO protocol 3 and is not compatible. server/package-lock.json also still resolves Socket.IO 2.2.0. Regenerate the lockfile, replace the bundle with a Socket.IO 4 client, and test the browser connection.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@server/package.json` at line 14, Update the Socket.IO dependency set by
regenerating server/package-lock.json from the Socket.IO 4 requirement, replace
src/www/js_ext/lib/socket.io.js with a compatible Socket.IO 4 browser client
bundle, and verify the browser connection succeeds against the server.

"winston": "^3.1.0"
}
}
Loading