Skip to content

Releases: OPaperStream/PaperProxy

PaperProxy 1.2.2

Choose a tag to compare

@OPaperStream OPaperStream released this 09 Oct 04:19

Security and robustness release. Fixes the issues from the review in #1. Thanks to @NeonNoxus for the detailed report. Updating is recommended.

Updates

  • The version inside a downloaded jar must match the release tag and be newer than the running version, so an old signed jar cannot be installed under a newer tag
  • A second release key is trusted in advance, so the signing key can be rotated without breaking updates (see SECURITY.md)
  • Updates are written atomically, limited to 64 MiB, picked by their exact file name and only from GitHub links
  • The launcher installs a waiting update on start. This also makes auto-updates work on Windows from this version on
  • Leftover temp files and old core jars are removed, library checksums are cached, downloads are retried
  • Failed update checks are reported after three attempts instead of silently

Bot protection

  • The server list ping cache is bounded and expires, IPv6 addresses are grouped by /64
  • Known players are bound to their network before login and to their UUID after it, so a known name alone no longer gets past attack mode
  • known-players.txt is written atomically

Network sync

  • Messages between proxies are signed with the new sync.secret and checked for age and replays. Set the same long random secret on every proxy; without it a warning is logged
  • Redis replies are size limited, TLS (redis-ssl) and ACL users (redis-username) are supported
  • Passwords and the Discord webhook can come from the environment (${env:NAME}) or a file (file:path)

Other

  • Control characters can no longer reach the PaperGuard host field
  • Bans with a known UUID only match that UUID, not a later owner of the name
  • Discord messages come from messages.yml and can be translated
  • The exact Velocity base commit is recorded in the jar

Download

paperproxy-1.2.2-RELEASE.jar (small, libraries are downloaded and checked on first start) or -full.jar. Always the newest: https://github.com/OPaperStream/PaperProxy/releases/latest/download/paperproxy.jar

API: net.paperstream:paperproxy-api:1.2.2-RELEASE

Questions and problems: https://dc.gg/paperstream

PaperProxy is not affiliated with PaperMC.

PaperProxy 1.2.1

Choose a tag to compare

@OPaperStream OPaperStream released this 08 Oct 13:37

The first release of PaperProxy. After the alpha and beta phase, 1.2.1 is the first version marked as a release. It includes everything from 1.2.0-BETA plus fixes for bugs that PaperProxy inherited from Velocity.

Fixed bugs from Velocity

Fixes from pull requests that are still open at Velocity, most of them approved by Velocity reviewers:

  • Fallback servers were skipped when the first server accepted the connection and then stalled (#1821)
  • Client settings (language, skin parts) got lost during a server switch (#1891)
  • Fallback after a reload when servers were removed from the try list (#1883)
  • Tab list with several entries added or removed at once (#1872)
  • Chat messages could arrive in the wrong order (#1782)
  • Endpoints were logged twice when opening and closing (#1777)
  • Short query packets caused errors (#1857)
  • Wrong login status when the backend disconnects (#1864)
  • Forge detection with legacy and BungeeGuard forwarding (#1785)
  • The read timeout is 25 seconds now, so the proxy notices a stalled player before the client times out by itself; unchanged configs are migrated (#1820, issue #1819)
  • prevent-client-proxy-connections refused every player from a LAN, VPN or cluster network; private addresses are no longer sent to Mojang (issue #1414)

Thanks to the authors of these pull requests.

Tested

  • A real 26.1.2 client stayed on the Code of Conduct screen for over five minutes without being kicked (issue #1731 at Velocity) and joined normally afterwards.
  • Join, chat, parties, limbo and a restart of all backends with bots, permissions with LuckPerms-Bungee, ViaVersion.

Download

paperproxy-1.2.1-RELEASE.jar (small, libraries are downloaded and checked on first start) or -full.jar. Always the newest: https://github.com/OPaperStream/PaperProxy/releases/latest/download/paperproxy.jar

API: net.paperstream:paperproxy-api:1.2.1-RELEASE, see the wiki.

Questions and problems: https://dc.gg/paperstream

PaperProxy is not affiliated with PaperMC.

PaperProxy 1.2.0-BETA

Choose a tag to compare

@OPaperStream OPaperStream released this 06 Oct 04:44

The beta phase starts. PaperProxy 1.2.0-BETA was tested on a test network with a real Minecraft client, which found two bugs that were already in earlier versions. Please update.

Fixed

  • Permissions from BungeeCord permission plugins now apply to proxy commands. With only LuckPerms-Bungee installed, commands like /send, /glist or /pp servers were never allowed, even with *. Velocity's permission checks now ask BungeeCord permission plugins too.
  • Update notices never reached alpha users. The default update channel release hid every alpha and beta release. updates.channel is now auto and follows the version you run; the old release setting also follows it on alpha and beta builds.
  • /pp via, /pp restart and /pp paperguard without arguments show their usage instead of a raw error.

New

  • Update notifier: a banner in the console, an in-game notice with buttons to download, read the changelog or install, and how many versions behind you are. /pp update now downloads and verifies the update for the next restart.
  • Party API: PaperProxy.get().getParties() and PartyJoinEvent, PartyLeaveEvent, PartyFollowEvent (cancellable, for example during a minigame round).
  • The API is on Maven: net.paperstream:paperproxy-api:1.2.0-BETA, setup in the README and the wiki.
  • Wiki on GitHub and Codeberg.
  • Release keys can be rotated safely, see SECURITY.md.
  • Async plugin tasks get up to 10 seconds to finish when the proxy stops.

Tested with a real client

Limbo (players stay connected while all servers restart and are sent back automatically), returning to a server after its restart, /hub with server groups, permissions through LuckPerms-Bungee, ViaVersion with a 26.1.2 client on 1.21.4 backends.

Download

paperproxy-1.2.0-BETA.jar (small, libraries are downloaded and checked on first start) or -full.jar. Always the newest: https://github.com/OPaperStream/PaperProxy/releases/latest/download/paperproxy.jar

Please report problems on GitHub, Codeberg or Discord: https://dc.gg/paperstream

PaperProxy is not affiliated with PaperMC.

PaperProxy 1.1.0-ALPHA

Choose a tag to compare

@OPaperStream OPaperStream released this 05 Oct 21:34

PaperProxy 1.1.0-ALPHA is the biggest update so far. Most of it is things you would otherwise install plugins or extra servers for. Everything is in paperproxy.toml, most features are on by default and can be switched off.

New

  • Limbo: when a server restarts or crashes and no other server can take its players, they stay connected and are sent back as soon as it is online again. Real kicks (bans, AFK) are passed on as before.
  • Server groups: lobby = ["lobby-1", "lobby-2"] sends players to the emptiest member and skips full or offline ones.
  • Queues for full or offline servers, with position in the action bar and priority permissions.
  • /hub and /lobby for a server or group of your choice.
  • Parties: /party and /pc, members follow their leader from server to server.
  • Bans, mutes and kicks for the whole network (punish.enabled, off by default because backends have commands with the same names).
  • Network sync over Redis for several proxies: network wide player count, /find and /alert across proxies, /pp network, no double logins.
  • Planned restarts: /pp restart <seconds> [reason] or daily times, with countdown and titles.
  • Restart without kicks: shutdown.transfer-to hands players to another proxy (1.20.5+ clients).
  • Discord webhook for servers going down, bot attacks, maintenance, updates, restarts and bans.
  • Bot protection: attack mode on connection floods, new players must ping the server list first, accounts per IP limit, blocked name patterns.
  • Prometheus metrics with a ready Grafana dashboard (docs/grafana).
  • Update folder: drop new jars into plugins/update, they replace the old version on the next start.
  • Hidden commands: keep commands out of tab completion.
  • Query passthrough: server queries show the map, version and plugins of a backend.
  • /send for groups and /send server <from> <to>.

BungeeCord plugins

  • unsafe().sendPacket works now: scoreboard and tab plugins that send packets are supported (clients up to 1.21.7).
  • LuckPerms-Bungee no longer fails on getDisabledCommands.
  • The scheduler uses normal threads, plugins with blocking database calls (SQLite) no longer stall the proxy.

Fixes

  • Group members keep the order from the config.

Download

paperproxy-1.1.0-ALPHA.jar is the small jar (libraries are downloaded and checked on first start), -full.jar contains everything. paperproxy.jar is the same as the small jar and always available at
https://github.com/OPaperStream/PaperProxy/releases/latest/download/paperproxy.jar

This is an alpha. Please report problems on GitHub or Discord: https://dc.gg/paperstream

PaperProxy is not affiliated with PaperMC.

PaperProxy 1.0.1-ALPHA

Pre-release

Choose a tag to compare

@OPaperStream OPaperStream released this 03 Oct 16:28

Second alpha of PaperProxy. Not affiliated with PaperMC.

Changes

  • The backend plugin is now PaperGuard with its own repository: https://github.com/OPaperStream/PaperGuard. Replace PaperProxy-Bridge with PaperGuard, your settings are taken over automatically. The proxy warns on servers that still run the old bridge.
  • PaperGuard test vectors are now checked in the proxy build, so proxy and plugin always sign the same way.
  • bStats: client versions count every join since the last report, not only the players online at that moment.
  • New default MOTD "A PaperProxy Server" for new installations.
  • Pterodactyl egg in pterodactyl/.

Files

  • paperproxy-1.0.1-ALPHA.jar: small jar (about 2 MB), downloads its libraries on first start and checks every file
  • paperproxy-1.0.1-ALPHA-full.jar: everything inside, for servers without internet on start
  • .sha512 and .sig: used by the auto-updater

Requires Java 25.

PaperProxy 1.0.0-ALPHA

Pre-release

Choose a tag to compare

@OPaperStream OPaperStream released this 03 Oct 13:58

First public test build. Not for production yet.

NOT AN OFFICIAL PAPER PROJECT. PaperProxy is not affiliated with or endorsed by PaperMC.

Requires Java 25.

Files

  • paperproxy-1.0.0-ALPHA.jar: the proxy (java -jar paperproxy-1.0.0-ALPHA.jar)
  • PaperProxy-Bridge-1.0.0-ALPHA.jar: backend plugin for PaperGuard (Paper 1.12.2+, Folia)
  • .sha512 / .sig: checksum and signature used by the auto-updater

Highlights

  • Velocity and BungeeCord plugins on one proxy
  • Forwarding per server, PaperGuard (signed, replay-proof forwarding)
  • messages.yml, motd.yml
  • Plugin reload/load/unload, event watchdog
  • ViaVersion installer and version rules per server
  • Health checks, maintenance mode, ping cache, /alert /find /ip
  • Update notifications and optional verified auto-updater
  • API (PaperProxy.get())

Known limitations

  • PaperProxy-Bridge does not support plain Spigot or versions below 1.12.2 yet
  • BungeeCord plugins that use BungeeCord internals (raw packets, Netty) do not work

Feedback: https://dc.gg/paperstream