Repository navigation
Security and robustness release. Fixes the issues from the review in #1. Thanks to @NeonNoxus for the detailed report. Updating is recommended.
Updates
- The version inside a downloaded jar must match the release tag and be newer than the running version, so an old signed jar cannot be installed under a newer tag
- A second release key is trusted in advance, so the signing key can be rotated without breaking updates (see
SECURITY.md) - Updates are written atomically, limited to 64 MiB, picked by their exact file name and only from GitHub links
- The launcher installs a waiting update on start. This also makes auto-updates work on Windows from this version on
- Leftover temp files and old core jars are removed, library checksums are cached, downloads are retried
- Failed update checks are reported after three attempts instead of silently
Bot protection
- The server list ping cache is bounded and expires, IPv6 addresses are grouped by /64
- Known players are bound to their network before login and to their UUID after it, so a known name alone no longer gets past attack mode
known-players.txtis written atomically
Network sync
- Messages between proxies are signed with the new
sync.secretand checked for age and replays. Set the same long random secret on every proxy; without it a warning is logged - Redis replies are size limited, TLS (
redis-ssl) and ACL users (redis-username) are supported - Passwords and the Discord webhook can come from the environment (
${env:NAME}) or a file (file:path)
Other
- Control characters can no longer reach the PaperGuard host field
- Bans with a known UUID only match that UUID, not a later owner of the name
- Discord messages come from
messages.ymland can be translated - The exact Velocity base commit is recorded in the jar
Download
paperproxy-1.2.2-RELEASE.jar (small, libraries are downloaded and checked on first start) or -full.jar. Always the newest: https://github.com/OPaperStream/PaperProxy/releases/latest/download/paperproxy.jar
API: net.paperstream:paperproxy-api:1.2.2-RELEASE
Questions and problems: https://dc.gg/paperstream
PaperProxy is not affiliated with PaperMC.