Releases: TuiLaZeroTwo/0glnAuth
Release list
0gln Auth v0.1.3
Premium impersonation fix: premium auto-login and /premium claims now require the client to present the real Mojang UUID at login (JPremium-style handshake detection).
What was broken
Anyone joining with a premium-flagged name was auto-logged-in, and any first-joiner could /premium-claim an unregistered premium name. In offline mode the server never verifies identity with Mojang, so a cracked launcher could use someone else's premium name.
How it works now
Premium launchers send their genuine Mojang UUID in the Login Start packet; cracked launchers send an offline-derived (or absent) UUID. The plugin now:
- /premium: resolves the Mojang UUID for the name and requires the claimant's presented UUID to match - stock cracked launchers are rejected with a clear message
- Join with a premium-flagged name: auto-login only on UUID match; a mismatching (cracked) client is told to join with the premium launcher and is frozen until timeout
Limitations
Offline mode never cryptographically authenticates the presented UUID, so a custom-modified client that knows the victim's Mojang UUID could still spoof it. This defeats stock launchers (the practical cracked-server threat); full protection requires online-mode or a proxy like JPremium.
Install
Replace the wasm and restart. Existing premium accounts keep working (their stored premium_id is now also UUID-verified at join). Two new [messages] keys: premium.uuid_mismatch, premium.uuid_wrong.
0gln Auth v0.1.2
Fixes: Permission already registered error on startup.
What was broken
v0.1.1 failed to load: all seven player commands share one permission node (0gln Auth:player), and the plugin tried to register that node once per command - the second attempt was rejected as a duplicate and aborted initialization.
Fix
Permission nodes are now registered exactly once per unique node; every command still attaches to its node. The plugin initializes cleanly.
Install
Replace the wasm in the server plugins/ directory and restart. No data migration needed.
0gln Auth v0.1.1
Fixes plugin initialization failure on live servers.
What was broken
v0.1.0 failed to load: Pumpkin rejected the permission nodes (0glnauth.player / 0glnauth.admin) because permissions must be namespaced under the plugin's name.
Fix
Permission nodes are now fully namespaced: 0gln Auth:player and 0gln Auth:admin. The plugin initializes, registers commands and handlers, and passes the permission gate.
Install
Same as v0.1.0: copy zero_gln_auth.wasm into the server plugins/ directory (offline mode required). Existing account stores are unaffected.
If v0.1.0 already wrote a data folder, no cleanup is needed - it failed before creating any store. Full changelog and docs: see README.
0gln Auth v0.1.0
0gln Auth v0.1.0
Authentication plugin for Pumpkin (Rust Minecraft server), built as a WASM plugin for offline-mode servers. A remake of AuthMe + JPremium logic in Rust.
Features
- Cracked (offline) players: classic /register + /login password flow (Argon2 hashing, 8-64 chars, password != username), /logout, /changepassword, /unregister
- Premium (paid) players: claim your name once with /premium - verified live against Mojang session servers, then auto-login on every join
- Sessions: relog within 120 min from the same IP resumes silently
- Freeze before login: unauthenticated players cannot move, chat, run non-auth commands, break/place blocks, interact, drop items, or attack
- Login timeout: unauthenticated players kicked after 120s
- Rate limiting: 5 wrong passwords from one IP = kick (counter survives reconnect, resets only on success)
- Single session: a name cannot be online twice - duplicate joins denied at pre-login
- Config-driven: full config.toml with policy keys AND an editable [messages] section - every player-facing message can be reworded, Bukkit-config style
- Fail-closed design: corrupt store/config fails the plugin load loudly (never silently wipes accounts); store errors never auto-allow anyone
Install
- Server must run offline mode (online_mode=false / authentication disabled)
- Download zero_gln_auth.wasm and copy it into the server plugins/ directory
- Start the server - config is generated in plugins/data/0gln Auth/
- Requires Pumpkin plugin permissions: fs.read.data, fs.write.data, http.outbound (for /premium Mojang checks)
Commands
| Command | Who | Effect |
|---|---|---|
| /register | everyone | create cracked account |
| /login (+ /l, /log) | everyone | log in |
| /premium | everyone | verify name with Mojang + auto-login forever |
| /logout, /changepassword, /unregister | players | account management |
| /setpremium on/off, /forcelogin | ops (level 3+) | admin tools |
Security notes
- No join-time auto-resolution: a premium name is only granted through an explicit /premium claim (Mojang-verified) - existing password accounts can never be silently converted
- Residual risk (documented): the first /premium claim on an unregistered premium name owns it on this server
- WARNING: if the plugin fails to load, the server runs WITHOUT auth - check /plugins after config changes
Tech
Rust (WASM, wasm32-wasip2), pumpkin-plugin-api 0.1.0-dev+26.2-26.45, Argon2, waki (WASI HTTP), JSON flatfile storage with atomic writes, TOML config.
Built from commit 987a8d7. 26/26 unit tests passing.