Repository navigation
v1.7.0
简体中文 | English | Official Documentation
Architecture: Modular Refactoring
- Introduced
PluginContextas central service container - Split monolithic
WebServer(~1800 lines) into 20+ single-responsibilityHttpHandlerclasses underweb/handler/ - Extracted
ConfigManager,I18nManager,OpsManager,ResourceManagerintocore/package - Added
ApiRouterfor centralized route registration - Added
VmcCommandExecutorfor in-game admin commands (/vmc approve/reject/ban/unban/delete/list/info) - Added
PlayerLoginListenerwith plugin-mode whitelist enforcement and status-based kick messages - Unified admin handler authentication via
AdminAuthUtil
Identifier Migration: UUID -> Username
- Removed UUID as primary user identifier; username is now the sole key across all layers
- Updated
UserDao,FileUserDao,MysqlUserDaoto use username-based lookups - Added
getUserByEmail,getUserByUsernameExacttoUserDaointerface - Added convenience default methods:
banUser,unbanUser,getUsers,getTotalUsers, etc.
Admin Login Refactoring
- Replaced static
admin.passwordconfig with player-data-based authentication - Admin login now verifies against registered player credentials; only server OPs can access admin panel
- Login supports both username and email lookup with AuthMe password integration
Security Enhancements
- Introduced
PasswordUtilwith SHA-256 + salt hashing (AuthMe-compatible$SHA$format) - Plaintext password fallback now logs a warning to encourage migration
- Unified admin endpoint authentication through
AdminAuthUtil - Added query parameter URL decoding to prevent injection via encoded characters
- Proxy error handling changed from fail-open to fail-close (deny login), fixing security vulnerability
API Endpoint Restructuring
- RESTful API paths:
/api/admin/users,/api/admin/user/approve,/api/admin/user/reject, etc. - Questionnaire endpoints moved to
/api/questionnaire/configand/api/questionnaire/submit - Added
/api/admin/syncendpoint for AuthMe data synchronization - Added
/api/user/statusendpoint for user status queries
Frontend Improvements
- Optimized dialog system: unified all modals to use shared
Dialogcomponent - Refactored User Management: split user list and pending reviews into separate components
- Improved accessibility: added
aria-labelledby,role="dialog", and focus management - Fixed z-index issues: elevated dialog layer to z-60 to prevent overlap
- Admin login form updated to username + password fields
- API service updated to match new RESTful endpoint paths
Dependency Updates
- MySQL driver updated from
mysql-connector-javatomysql-connector-j - Removed duplicate
jakarta.mail-apidependency - Maven Shade Plugin updated to 3.5.0
Bug Fixes
- Fixed AuthMe sync skipping banned users during status upgrade
- Fixed scoring service unavailability detection in questionnaire results
- Fixed
WebResponseHelper.readJsonto handle malformed JSON bodies gracefully