Skip to content

v0.31.0

Choose a tag to compare

@dmitry-lebedev dmitry-lebedev released this 24 Jun 09:58
· 34 commits to main since this release

Added — platform sign-in (Google Play / Apple / Steam) through the token lifecycle

  • MetaTokenManager takes a custom full-login strategy: new MetaTokenManager(authUrl, storage, login: (url, ct) => MetaAuth.LoginWithPlatformAsync(url, "google", serverAuthCode, cancellation: ct)). A session reset / rejected-refresh now re-logs in via the right platform account instead of falling back to device login. The game obtains a fresh platform credential (e.g. a Google Play server auth code via the GPGS SDK) inside the delegate.
  • Server-side validation (IExternalAuthValidator → GoogleAuthValidator exchanges the server auth code with Google OAuth2 using the client secret) and refresh-token issuance on /login-platform were already in place; this wires platform sign-in into MetaTokenManager so it survives token expiry/rotation.

Added — recover from a server-rejected cached token

  • Set MetaClientOptions.AccessTokenSource (e.g. your MetaTokenManager) and the client auto-recovers: on an auth-type connect failure it invalidates the token and retries the connect once. Requires a provider-based connection (tokens.GetTokenAsync), not a fixed token string. It also seeds MetaClient.PlayerId from the token source when PlayerId isn't set — required for UserOwned entities (acquire the first token before constructing the client).
  • Primitives behind it: new IAccessTokenSource (PlayerId + Invalidate()); MetaTokenManager.Invalidate() forces re-acquire even if the cached token hasn't locally expired (e.g. the JWT signing key changed); MetaClientOptions.OnConnectAuthFailedAsync overrides the default retry policy.

Fixed

  • Unity auth now works when the access-token provider is invoked off the main thread (e.g. SignalR resolving it during its connect handshake): UnityMetaAuth marshals its UnityWebRequest login/refresh and PlayerPrefsTokenStorage marshals its PlayerPrefs read/write/clear onto Unity's main thread. Without this, off-thread acquisition threw "can only be called from the main thread" and fell back to the stale token. MetaTokenManager also adopts a freshly acquired token before persisting it, so a storage failure never discards it.