Preserve exact run links and reject malformed return-route queries
-
Preserve exact run links and reject malformed return-route queriesSign-in and return-route parsing was hardened: exact match/run links are canonicalized and preserved, and malformed or repeated query fields are rejected rather than silently dropped, preventing accidental navigation away from a requested exact run.
-
Add authenticated staff matchmaking controls and a public availability endpointStaff can now read and apply stored matchmaking configuration, pause/resume matchmaking and inspect parties/rooms through new admin APIs, and the website exposes a public /api/matchmaking/availability endpoint so visitors and connected users can see whether matchmaking is currently available and which regions are enabled.
-
Persist party chat, staff notices and matchmaking controlsParty chat is now archived, staff notices and message removal/restoration are stored as versioned moderation events, and matchmaking configuration/history is persisted so staff actions and moderated party messages are durable and recoverable.
-
Add public matchmaking analytics and clarify queue metricsThe API now exposes matchmaking analytics (UTC-windowed daily aggregates) with exact definitions for counts and the meaning of filled rooms and matched attempts so charts and labels show deterministic, documented metrics.
-
Preserve exact match/run return routes through Steam sign-inSign-in return URLs are now validated/canonicalized for exact match and run identifiers (and for staff reconciliation links) so returning from Steam preserves the intended exact match/run page and pending command IDs instead of being dropped or rewritten.
-
Show effective match results and attributable rating events on match and player pagesMatch pages and player profiles now surface public amendments (voids/corrections) and a merged rating ledger so you can see the effective result and the chronological, attributable rating events that affected a player's rating.
-
Add website player reporting with preserved immutable evidencePlayers can file reports tied to the exact archived run; every imported in-game report is stored as immutable evidence and reconciled into a staff case so allegations survive ingestion, repair and later moderation.
-
Send player display settings to game servers (levels, team names, staff badge and premium skins)The API now includes per-match display settings (player levels, team names, dashboard-admin SteamIDs for the developer badge and premium weapon-skin choices) so the game-server shows the same level, badge and chosen skins during matches.
-
Add platform settings, analytics and integrations APIAdd a versioned platform settings API (public GET /api/platform plus admin settings routes) that exposes a support email and three switches (registration open, public profiles, public statistics), and add staff analytics, integrations and readonly database/backup status endpoints; the API serves settings from an in-memory cache and enforces privacy for signed-out visitors, failing closed while settings are being recovered.
-
Publish content APIs for news, media, website copy and mapsPublish journalled content APIs for news articles (draft/schedule/publish/archive/history), a media library that validates and re-encodes uploads, versioned website copy, and the fixed eight-map catalogue with veto availability; add public routes (e.g. GET /api/news, /api/site, /api/maps, /api/media/:id) and document their strict bodies and errors β draft or unpublished images remain private and public images are served as WebP with immutable caching and ETag headers.
-
Remove the masthead motto and sidebar sloganThe site header and the art sidebar no longer show the previous marketing mottos, simplifying the masthead and sidebar visuals.
-
Remove !forcestart from the in-game !help textThe in-game !help message no longer lists the !forcestart command (it remains functional for admins but is no longer advertised in chat help).
-
Show match scoreboards without the KAST column and omit non-lethal smoke from weapon listsMatch scoreboards were adjusted to remove the KAST column so the tables fit more reliably, and the weapons lists now omit the smoke grenade and similar non-lethal entries from the kill-focused weapon tables.
-
Kick players not on a match roster when a roster is setWhen a match has a roster supplied by the website, any connected human whose SteamID isn't on that roster will be removed from the game (first via the server's RCON KickPlayer, then the game's idle kick), and roster_kick events are recorded in the logs.
-
Enforce platform settings in the website UIMake the site honour staff-set platform settings: show the staff support address as a mailto: link in Support, refuse new-account sign-ins with a clear 'registration-closed' notice when registration is paused, and, for signed-out visitors, require sign-in for profile/history/match-report reads or hide profile statistics and ranking statistics (the ladder falls back to an ELO-only sort and shows why); while the settings journal is being recovered these signed-out reads fail closed with a settings-unavailable response.
-
Render public news as Markdown and load site copy and map catalogue from the APIRender article bodies from the API's Markdown tokens into React elements (no HTML strings), require article images to come from the media library, and load the website copy and the eight-map catalogue from the API snapshot; pages fall back per-field to built-in copy when the route is missing or malformed so the site stays readable during rolling deployments.
-
Read level bands and active season from the API's competition snapshotMake Rankings and season copy driven by a shared competition snapshot from the API so the site displays the authoritative Level 1β10 bands and the active season; the site falls back to the built-in bands when the endpoint is missing and shows a notice instead of guessing when the policy is malformed.
69 internal changes in this release