FakePlayer-CE.Build11
·
73 commits
to master
since this release
FakePlayer-CE.Build11
Ender Chest, PlaceholderAPI Expansion, Expanded HTTP API & Security Hardening
This release adds ender chest access for fake players, a large batch of new PlaceholderAPI placeholders, expands the built-in HTTP admin API from 5 to 18 endpoints with security hardening (header-only tokens, rate limiting, DNS-rebinding protection), introduces the replace_tools feature, broadens replenish, and fixes command tab-completion in non-English locales.
Highlights
- Ender Chest Access: new
/fp enderchest(alias/fp ec) opens a fake player's ender chest under the same world/permission rules as/fp invsee; shift-right-clicking a fake player also opens it. New permissionfakeplayer.command.enderchest. - More PlaceholderAPI Placeholders: added list placeholders (
%fakeplayer_list%,%fakeplayer_list_<index>%,%fakeplayer_isfake%) and fake-player attributes (%fakeplayer_name%,%fakeplayer_uuid%,%fakeplayer_world%, coordinates, health, food, level, gamemode, creator, spawn time, running actions, etc.). - Expanded HTTP Admin API (5 → 18 endpoints): new query
/statusand/info, control/action,/stop,/teleport,/look,/hold,/swap,/respawn,/cmd, and batch/kickall,/killall,/sayall; each is independently toggleable underhttp-admin.interface. replace_toolsFeature: non-Mending tools are replaced after breaking; Mending tools are replaced at a configured low-durability threshold.- Broadened
replenish:/fp drop//fp dropstackrefill the main hand after its last item is dropped; consumed milk/stews/honey/potions are refilled from their returned container.
Breaking Changes
- The HTTP token is now header-only —
Authorization: Bearer <token>is the only accepted auth method. The?token=query parameter is removed, so tokens no longer leak through URLs, proxy logs, browser history orRefererheaders.
Critical Fixes
- HTTP API security hardening: token comparison is now constant-time; any
tokenparameter is redacted from logs; JSON responses escape control characters; per-source-IP rate limiting and lockout;Host/Originchecks mitigate DNS rebinding; routing is exact-path;POSTis supported. - Command tab-completion in non-English locales: case conversions now use
Locale.ROOT, so/fpsuggestions are correct on servers with non-English locales (e.g. Turkishtr_TR).
Important Notes
config.ymlis bumped to version 20; existing configs keep working and fall back to defaults for the new keys.http-adminis disabled by default. Prefer theAuthorization: Bearerheader and restrict access at the firewall level; rate limiting defaults to 120 requests/min per IP, with a 60s lockout after 10 consecutive auth failures.
Usage
- Java: 21+ (Java 25 recommended for 26.x support)
- Server: Paper / Leaf 1.20.1+ (Purpur compatible)
- API: CommandAPI 12.0.0+ (Mandatory dependency)
Credits
- CE Maintenance: @EndlessPixel
- @ifloppy (PRs #10–#13:
replace_toolsfeature & broadenedreplenish)
FakePlayer-CE.Build11 —— 末影箱、PlaceholderAPI 扩展、HTTP 接口扩充与安全加固
本次更新为假人新增末影箱访问、一大批 PlaceholderAPI 占位符,将内置 HTTP 管理接口从 5 个扩展到 18 个并做了安全加固(令牌仅走请求头、限流、DNS rebinding 防护),新增 replace_tools 特性、扩展 replenish,并修复非英文区域下的指令补全。
核心特性
- 末影箱访问:新增
/fp enderchest(别名/fp ec)打开假人的末影箱,判定规则(同世界、权限)与/fp invsee一致;潜行右键假人也可直接打开。新增权限节点fakeplayer.command.enderchest。 - 扩充 PlaceholderAPI 占位符:新增列表占位符(
%fakeplayer_list%、%fakeplayer_list_<序号>%、%fakeplayer_isfake%)与假人属性(%fakeplayer_name%、%fakeplayer_uuid%、%fakeplayer_world%、坐标、血量、饥饿、等级、模式、创建者、生成时间、正在进行的动作等)。 - HTTP 管理接口扩充(5 → 18 个):新增查询类
/status、/info,控制类/action、/stop、/teleport、/look、/hold、/swap、/respawn、/cmd,以及批量/kickall、/killall、/sayall;各接口在http-admin.interface下独立开关。 replace_tools特性:非经验修补工具损坏后更换;经验修补工具在达到配置的低耐久阈值时更换。- 扩展
replenish:/fp drop//fp dropstack丢空主手最后一个物品后自动补货;消耗奶桶、炖菜、蜂蜜瓶、药水后从返回的容器补回原物。
破坏性变更
- HTTP 令牌改为只走请求头 —— 鉴权统一使用
Authorization: Bearer <token>,不再接受?token=查询参数,令牌不再出现在 URL、代理日志、浏览器历史与Referer中。
关键修复
- HTTP 接口安全加固:令牌改为定长比较;日志脱敏
token参数;响应转义控制字符;按来源 IP 限流与失败锁定;校验Host/Origin缓解 DNS rebinding;路径精确匹配;支持POST。 - 非英文区域指令补全:大小写转换现统一使用
Locale.ROOT,在土耳其语tr_TR等非英文区域服务端下/fp补全建议均正确。
重要说明
config.yml版本号提升至 20;旧配置可继续使用,新配置项自动采用默认值。http-admin默认关闭。建议优先使用Authorization: Bearer请求头并在防火墙层面限制来源;限流默认每 IP 120 请求/分钟,连续 10 次鉴权失败后锁定 60 秒。
使用要求
- Java: 21+(26.x 建议 Java 25)
- 服务端: Paper / Leaf 1.20.1+(兼容 Purpur)
- 前置依赖: CommandAPI 12.0.0 及以上(必需)
鸣谢
- CE 维护: @EndlessPixel
- @ifloppy(PR #10–#13:
replace_tools特性与扩展的replenish)