drive.file scope only grants access to files the app itself creates —
it deliberately can't see a file it didn't create, even one the
signed-in user can otherwise view. Drive's API returns 404 (not 403)
for a file outside the token's grant, which is indistinguishable from
a bad file ID — that's what surfaced as "File not found:
1tSG1BxqLwmMtwFnaHozaLqVsKlmk_QsCXRorIxQBcMo" on the very first API
call (confirmed nothing was created in Drive yet, matching a rejected
initial copy rather than a later step).
Added drive.readonly alongside drive.file: readonly covers reading
the pre-existing template to copy it, drive.file continues to cover
the generated copies and everything written to them afterward.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SBzcNkW7JcYipnAX6HfgmK
Duplicates the team's Google Sheets matchup-matrix template once per
opposing team at a loaded event, pre-filled with names, factions,
career win% (all already computed by this page), and cleaned army
lists. New "Which team is yours?" selector + Generate Matrix button,
team-events only.
- Auth: Google Identity Services token client (drive.file +
spreadsheets scopes) — the viewer signs in with their own Google
account via a real OAuth popup, no backend, no client secret.
- Template layout is located at runtime by searching each tab for its
own placeholder text ("Player N - Faction", "Opponent N") rather
than hardcoded A1 ranges, so it survives the template changing later.
Distinguishes the real input area from the template's own "mobile
matrix" mirror and reference sections (which repeat the same
placeholder text) by checking for literal typed values vs formulas —
CSV export can't tell these apart, only the real Sheets API response
can, which is how this was actually verified before writing this.
Auto-picks between the template's 5-man/8-man tab variants by team
size.
- List cleaning via a vendored copy of desjani's 40k-compactor
(src/vendor/40k-compactor/, see NOTICE.md) — it isn't actually
published to npm despite documenting `npm install 40k-compactor`
(verified: 404 against the registry under every plausible name), so
it can't be a normal dependency; vendored instead, MIT per direct
confirmation from the maintainer. Verified against 40k-compactor's
own sample list fixtures with real Node before committing.
- Generating a matrix needs the same BCP auth token already used for
faction/disposition backfill (list text is a subscriber-gated
endpoint) — reuses the existing token UI/storage as-is; missing
lists are reported, not a hard failure.
- nginx CSP updated (script/connect/frame-src) for Google's identity
script and the Drive/Sheets REST APIs.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SBzcNkW7JcYipnAX6HfgmK