Skip to main content

Module codes

Module codes 

Source
Expand description

The stable error codes. Codes are part of the public API from 0.1.0: they are never renamed and never change meaning; new ones may be added.

Constants§

BAD_REQUEST
The request is malformed (not JSON, wrong types, missing fields). HTTP 400.
BANNED
The account is banned. HTTP 403; WebSocket close 4003.
CONFLICT
The request conflicts with the current state. HTTP 409.
EMAIL_NOT_VERIFIED
The action needs a verified email address. HTTP 403.
EMAIL_TAKEN
The email address is already registered. HTTP 409. A deliberate trade-off: it tells an attacker that the address has an account (enumeration), but a game needs a clear answer at sign-up; the server rate-limits registration to bound the damage.
FORBIDDEN
Authenticated, but not allowed to do this. HTTP 403.
HOOK_TIMEOUT
A server hook did not answer in time. HTTP 503.
INTERNAL
An unexpected server error; the message never contains internal details. HTTP 500.
INVALID_CREDENTIALS
Email + password did not match an account (deliberately not saying which). HTTP 401.
INVALID_TOKEN
A one-time token (email verification, password reset) is unknown, used or expired. HTTP 400.
METHOD_NOT_ALLOWED
The HTTP method is not allowed on this route (the Allow header lists the allowed ones). HTTP 405.
NOT_A_MEMBER
The caller is not a member of the chat room (join it first). HTTP 403.
NOT_FOUND
The thing does not exist (or the caller may not know that it does). HTTP 404.
PAYLOAD_TOO_LARGE
The request body (or a WebSocket message, or a stored value) is too large. HTTP 413.
QUOTA_EXCEEDED
A per-user quota is used up (e.g. the number of stored objects). HTTP 403.
RATE_LIMITED
Too many requests; details may hold {"retry_after_ms":N}. HTTP 429.
REAUTHENTICATION_REQUIRED
The action needs a recent login (e.g. linking or unlinking a login provider): log in again, then retry. HTTP 403.
REFRESH_TOKEN_REUSED
The refresh token was already used, outside the grace window (REFRESH_REUSE_GRACE_SECS): the whole token family is revoked (possible theft); log in again. Clients refresh single-flight and keep the old pair until the new one is stored. HTTP 401.
ROOM_FULL
The chat room is full. HTTP 409.
STEAM_AUTH_FAILED
The Steam ticket was refused by Steam (or Steam could not be asked). HTTP 401.
TOKEN_EXPIRED
The access token expired: refresh it and retry (on the WebSocket handshake: refresh, then connect again). HTTP 401.
UNAUTHORIZED
No valid credentials (missing, unknown or revoked token). HTTP 401.
UNAVAILABLE
The server is overloaded or shutting down; retry later. HTTP 503.
UNKNOWN_TYPE
The WebSocket request’s type is not known to the server. (WebSocket only.)
UNSUPPORTED_MEDIA_TYPE
The request body has an unsupported media type (JSON routes need content-type: application/json). HTTP 415.
UNSUPPORTED_PROTOCOL
The client speaks a protocol version the server does not support; details holds {"supported_min":N,"supported_max":N}. HTTP 400 on plain HTTP routes ONLY. On the WebSocket endpoint never 400 (the client would retry forever): see version (upgrade, then close 4010).
VALIDATION_FAILED
The request is well-formed but some fields break a rule; details is a ValidationDetails. HTTP 422.
VERSION_CONFLICT
Optimistic concurrency: the object’s version is not the expected one; details is a VersionConflict: {"current_version":N} (absent when the object does not exist), plus "index":i for the failing item of a batch. HTTP 409.