Skip to content

PaperProxy 1.2.2

Latest

Choose a tag to compare

@OPaperStream OPaperStream released this 09 Oct 04:19

Security and robustness release. Fixes the issues from the review in #1. Thanks to @NeonNoxus for the detailed report. Updating is recommended.

Updates

  • The version inside a downloaded jar must match the release tag and be newer than the running version, so an old signed jar cannot be installed under a newer tag
  • A second release key is trusted in advance, so the signing key can be rotated without breaking updates (see SECURITY.md)
  • Updates are written atomically, limited to 64 MiB, picked by their exact file name and only from GitHub links
  • The launcher installs a waiting update on start. This also makes auto-updates work on Windows from this version on
  • Leftover temp files and old core jars are removed, library checksums are cached, downloads are retried
  • Failed update checks are reported after three attempts instead of silently

Bot protection

  • The server list ping cache is bounded and expires, IPv6 addresses are grouped by /64
  • Known players are bound to their network before login and to their UUID after it, so a known name alone no longer gets past attack mode
  • known-players.txt is written atomically

Network sync

  • Messages between proxies are signed with the new sync.secret and checked for age and replays. Set the same long random secret on every proxy; without it a warning is logged
  • Redis replies are size limited, TLS (redis-ssl) and ACL users (redis-username) are supported
  • Passwords and the Discord webhook can come from the environment (${env:NAME}) or a file (file:path)

Other

  • Control characters can no longer reach the PaperGuard host field
  • Bans with a known UUID only match that UUID, not a later owner of the name
  • Discord messages come from messages.yml and can be translated
  • The exact Velocity base commit is recorded in the jar

Download

paperproxy-1.2.2-RELEASE.jar (small, libraries are downloaded and checked on first start) or -full.jar. Always the newest: https://github.com/OPaperStream/PaperProxy/releases/latest/download/paperproxy.jar

API: net.paperstream:paperproxy-api:1.2.2-RELEASE

Questions and problems: https://dc.gg/paperstream

PaperProxy is not affiliated with PaperMC.