SSO Authentication Loop
1. Login Trigger
User clicks 'Login with KBS SSO' on the client dashboard.
โผ
2. Auth Redirect
Redirects user to Auth Server /login?client_id=game_id
โผ
3. Token Handshake
SSO sends authorization code back to Game Backend, which exchanges it for User JWT Profile.
โผ
4. Session Secure
Session serializes to SQLite DB. Writes secure HttpOnly session_id and csrf_token cookies to Client.
Multiplayer Polling Loop
1. Heartbeat Polling
Clients send POST to /presence every 3-5 seconds to refresh lobby status and retrieve active player lists.
โผ
2. Action Dispatch
Player actions are dispatched via POST /action which updates SQLite row state machines.
โผ
3. State Sync
Connected players poll GET /state every 1-2 seconds, fetching the updated JSON row from SQLite games table.