Skip to content

v1.7.0

Choose a tag to compare

@github-actions github-actions released this 03 Mar 14:51
· 9 commits to master since this release

简体中文 | English | Official Documentation

Architecture: Modular Refactoring

  • Introduced PluginContext as central service container
  • Split monolithic WebServer (~1800 lines) into 20+ single-responsibility HttpHandler classes under web/handler/
  • Extracted ConfigManager, I18nManager, OpsManager, ResourceManager into core/ package
  • Added ApiRouter for centralized route registration
  • Added VmcCommandExecutor for in-game admin commands (/vmc approve/reject/ban/unban/delete/list/info)
  • Added PlayerLoginListener with plugin-mode whitelist enforcement and status-based kick messages
  • Unified admin handler authentication via AdminAuthUtil

Identifier Migration: UUID -> Username

  • Removed UUID as primary user identifier; username is now the sole key across all layers
  • Updated UserDao, FileUserDao, MysqlUserDao to use username-based lookups
  • Added getUserByEmail, getUserByUsernameExact to UserDao interface
  • Added convenience default methods: banUser, unbanUser, getUsers, getTotalUsers, etc.

Admin Login Refactoring

  • Replaced static admin.password config with player-data-based authentication
  • Admin login now verifies against registered player credentials; only server OPs can access admin panel
  • Login supports both username and email lookup with AuthMe password integration

Security Enhancements

  • Introduced PasswordUtil with SHA-256 + salt hashing (AuthMe-compatible $SHA$ format)
  • Plaintext password fallback now logs a warning to encourage migration
  • Unified admin endpoint authentication through AdminAuthUtil
  • Added query parameter URL decoding to prevent injection via encoded characters
  • Proxy error handling changed from fail-open to fail-close (deny login), fixing security vulnerability

API Endpoint Restructuring

  • RESTful API paths: /api/admin/users, /api/admin/user/approve, /api/admin/user/reject, etc.
  • Questionnaire endpoints moved to /api/questionnaire/config and /api/questionnaire/submit
  • Added /api/admin/sync endpoint for AuthMe data synchronization
  • Added /api/user/status endpoint for user status queries

Frontend Improvements

  • Optimized dialog system: unified all modals to use shared Dialog component
  • Refactored User Management: split user list and pending reviews into separate components
  • Improved accessibility: added aria-labelledby, role="dialog", and focus management
  • Fixed z-index issues: elevated dialog layer to z-60 to prevent overlap
  • Admin login form updated to username + password fields
  • API service updated to match new RESTful endpoint paths

Dependency Updates

  • MySQL driver updated from mysql-connector-java to mysql-connector-j
  • Removed duplicate jakarta.mail-api dependency
  • Maven Shade Plugin updated to 3.5.0

Bug Fixes

  • Fixed AuthMe sync skipping banned users during status upgrade
  • Fixed scoring service unavailability detection in questionnaire results
  • Fixed WebResponseHelper.readJson to handle malformed JSON bodies gracefully