Expand description
The stable error codes. Codes are part of the public API from 0.1.0: they are never renamed and never change meaning; new ones may be added.
Constants§
- BAD_
REQUEST - The request is malformed (not JSON, wrong types, missing fields). HTTP 400.
- BANNED
- The account is banned. HTTP 403; WebSocket close 4003.
- CONFLICT
- The request conflicts with the current state. HTTP 409.
- EMAIL_
NOT_ VERIFIED - The action needs a verified email address. HTTP 403.
- EMAIL_
TAKEN - The email address is already registered. HTTP 409. A deliberate trade-off: it tells an attacker that the address has an account (enumeration), but a game needs a clear answer at sign-up; the server rate-limits registration to bound the damage.
- FORBIDDEN
- Authenticated, but not allowed to do this. HTTP 403.
- HOOK_
TIMEOUT - A server hook did not answer in time. HTTP 503.
- INTERNAL
- An unexpected server error; the message never contains internal details. HTTP 500.
- INVALID_
CREDENTIALS - Email + password did not match an account (deliberately not saying which). HTTP 401.
- INVALID_
TOKEN - A one-time token (email verification, password reset) is unknown, used or expired. HTTP 400.
- METHOD_
NOT_ ALLOWED - The HTTP method is not allowed on this route (the
Allowheader lists the allowed ones). HTTP 405. - NOT_
A_ MEMBER - The caller is not a member of the chat room (join it first). HTTP 403.
- NOT_
FOUND - The thing does not exist (or the caller may not know that it does). HTTP 404.
- PAYLOAD_
TOO_ LARGE - The request body (or a WebSocket message, or a stored value) is too large. HTTP 413.
- QUOTA_
EXCEEDED - A per-user quota is used up (e.g. the number of stored objects). HTTP 403.
- RATE_
LIMITED - Too many requests;
detailsmay hold{"retry_after_ms":N}. HTTP 429. - REAUTHENTICATION_
REQUIRED - The action needs a recent login (e.g. linking or unlinking a login provider): log in again, then retry. HTTP 403.
- REFRESH_
TOKEN_ REUSED - The refresh token was already used, outside the grace window
(
REFRESH_REUSE_GRACE_SECS): the whole token family is revoked (possible theft); log in again. Clients refresh single-flight and keep the old pair until the new one is stored. HTTP 401. - ROOM_
FULL - The chat room is full. HTTP 409.
- STEAM_
AUTH_ FAILED - The Steam ticket was refused by Steam (or Steam could not be asked). HTTP 401.
- TOKEN_
EXPIRED - The access token expired: refresh it and retry (on the WebSocket handshake: refresh, then connect again). HTTP 401.
- UNAUTHORIZED
- No valid credentials (missing, unknown or revoked token). HTTP 401.
- UNAVAILABLE
- The server is overloaded or shutting down; retry later. HTTP 503.
- UNKNOWN_
TYPE - The WebSocket request’s
typeis not known to the server. (WebSocket only.) - UNSUPPORTED_
MEDIA_ TYPE - The request body has an unsupported media type (JSON routes need
content-type: application/json). HTTP 415. - UNSUPPORTED_
PROTOCOL - The client speaks a protocol version the server does not support;
detailsholds{"supported_min":N,"supported_max":N}. HTTP 400 on plain HTTP routes ONLY. On the WebSocket endpoint never 400 (the client would retry forever): seeversion(upgrade, then close 4010). - VALIDATION_
FAILED - The request is well-formed but some fields break a rule;
detailsis aValidationDetails. HTTP 422. - VERSION_
CONFLICT - Optimistic concurrency: the object’s version is not the expected one;
detailsis aVersionConflict:{"current_version":N}(absent when the object does not exist), plus"index":ifor the failing item of a batch. HTTP 409.