Skip to content

FakePlayer-CE.Build11

Choose a tag to compare

@EndlessPixel EndlessPixel released this 23 Sep 02:48
· 73 commits to master since this release

FakePlayer-CE.Build11

Ender Chest, PlaceholderAPI Expansion, Expanded HTTP API & Security Hardening

This release adds ender chest access for fake players, a large batch of new PlaceholderAPI placeholders, expands the built-in HTTP admin API from 5 to 18 endpoints with security hardening (header-only tokens, rate limiting, DNS-rebinding protection), introduces the replace_tools feature, broadens replenish, and fixes command tab-completion in non-English locales.

Highlights

  • Ender Chest Access: new /fp enderchest (alias /fp ec) opens a fake player's ender chest under the same world/permission rules as /fp invsee; shift-right-clicking a fake player also opens it. New permission fakeplayer.command.enderchest.
  • More PlaceholderAPI Placeholders: added list placeholders (%fakeplayer_list%, %fakeplayer_list_<index>%, %fakeplayer_isfake%) and fake-player attributes (%fakeplayer_name%, %fakeplayer_uuid%, %fakeplayer_world%, coordinates, health, food, level, gamemode, creator, spawn time, running actions, etc.).
  • Expanded HTTP Admin API (5 → 18 endpoints): new query /status and /info, control /action, /stop, /teleport, /look, /hold, /swap, /respawn, /cmd, and batch /kickall, /killall, /sayall; each is independently toggleable under http-admin.interface.
  • replace_tools Feature: non-Mending tools are replaced after breaking; Mending tools are replaced at a configured low-durability threshold.
  • Broadened replenish: /fp drop / /fp dropstack refill the main hand after its last item is dropped; consumed milk/stews/honey/potions are refilled from their returned container.

Breaking Changes

  • The HTTP token is now header-only — Authorization: Bearer <token> is the only accepted auth method. The ?token= query parameter is removed, so tokens no longer leak through URLs, proxy logs, browser history or Referer headers.

Critical Fixes

  • HTTP API security hardening: token comparison is now constant-time; any token parameter is redacted from logs; JSON responses escape control characters; per-source-IP rate limiting and lockout; Host/Origin checks mitigate DNS rebinding; routing is exact-path; POST is supported.
  • Command tab-completion in non-English locales: case conversions now use Locale.ROOT, so /fp suggestions are correct on servers with non-English locales (e.g. Turkish tr_TR).

Important Notes

  • config.yml is bumped to version 20; existing configs keep working and fall back to defaults for the new keys.
  • http-admin is disabled by default. Prefer the Authorization: Bearer header and restrict access at the firewall level; rate limiting defaults to 120 requests/min per IP, with a 60s lockout after 10 consecutive auth failures.

Usage

  • Java: 21+ (Java 25 recommended for 26.x support)
  • Server: Paper / Leaf 1.20.1+ (Purpur compatible)
  • API: CommandAPI 12.0.0+ (Mandatory dependency)

Credits


FakePlayer-CE.Build11 —— 末影箱、PlaceholderAPI 扩展、HTTP 接口扩充与安全加固

本次更新为假人新增末影箱访问、一大批 PlaceholderAPI 占位符,将内置 HTTP 管理接口从 5 个扩展到 18 个并做了安全加固(令牌仅走请求头、限流、DNS rebinding 防护),新增 replace_tools 特性、扩展 replenish,并修复非英文区域下的指令补全。

核心特性

  • 末影箱访问:新增 /fp enderchest(别名 /fp ec)打开假人的末影箱,判定规则(同世界、权限)与 /fp invsee 一致;潜行右键假人也可直接打开。新增权限节点 fakeplayer.command.enderchest。
  • 扩充 PlaceholderAPI 占位符:新增列表占位符(%fakeplayer_list%、%fakeplayer_list_<序号>%、%fakeplayer_isfake%)与假人属性(%fakeplayer_name%、%fakeplayer_uuid%、%fakeplayer_world%、坐标、血量、饥饿、等级、模式、创建者、生成时间、正在进行的动作等)。
  • HTTP 管理接口扩充(5 → 18 个):新增查询类 /status、/info,控制类 /action、/stop、/teleport、/look、/hold、/swap、/respawn、/cmd,以及批量 /kickall、/killall、/sayall;各接口在 http-admin.interface 下独立开关。
  • replace_tools 特性:非经验修补工具损坏后更换;经验修补工具在达到配置的低耐久阈值时更换。
  • 扩展 replenish:/fp drop / /fp dropstack 丢空主手最后一个物品后自动补货;消耗奶桶、炖菜、蜂蜜瓶、药水后从返回的容器补回原物。

破坏性变更

  • HTTP 令牌改为只走请求头 —— 鉴权统一使用 Authorization: Bearer <token>,不再接受 ?token= 查询参数,令牌不再出现在 URL、代理日志、浏览器历史与 Referer 中。

关键修复

  • HTTP 接口安全加固:令牌改为定长比较;日志脱敏 token 参数;响应转义控制字符;按来源 IP 限流与失败锁定;校验 Host/Origin 缓解 DNS rebinding;路径精确匹配;支持 POST。
  • 非英文区域指令补全:大小写转换现统一使用 Locale.ROOT,在土耳其语 tr_TR 等非英文区域服务端下 /fp 补全建议均正确。

重要说明

  • config.yml 版本号提升至 20;旧配置可继续使用,新配置项自动采用默认值。
  • http-admin 默认关闭。建议优先使用 Authorization: Bearer 请求头并在防火墙层面限制来源;限流默认每 IP 120 请求/分钟,连续 10 次鉴权失败后锁定 60 秒。

使用要求

  • Java: 21+(26.x 建议 Java 25)
  • 服务端: Paper / Leaf 1.20.1+(兼容 Purpur)
  • 前置依赖: CommandAPI 12.0.0 及以上(必需)

鸣谢