Skip to content

Releases: TuiLaZeroTwo/0glnAuth

0gln Auth v0.1.3

Choose a tag to compare

@TuiLaZeroTwo TuiLaZeroTwo released this 12 Sep 04:29

Premium impersonation fix: premium auto-login and /premium claims now require the client to present the real Mojang UUID at login (JPremium-style handshake detection).

What was broken

Anyone joining with a premium-flagged name was auto-logged-in, and any first-joiner could /premium-claim an unregistered premium name. In offline mode the server never verifies identity with Mojang, so a cracked launcher could use someone else's premium name.

How it works now

Premium launchers send their genuine Mojang UUID in the Login Start packet; cracked launchers send an offline-derived (or absent) UUID. The plugin now:

  • /premium: resolves the Mojang UUID for the name and requires the claimant's presented UUID to match - stock cracked launchers are rejected with a clear message
  • Join with a premium-flagged name: auto-login only on UUID match; a mismatching (cracked) client is told to join with the premium launcher and is frozen until timeout

Limitations

Offline mode never cryptographically authenticates the presented UUID, so a custom-modified client that knows the victim's Mojang UUID could still spoof it. This defeats stock launchers (the practical cracked-server threat); full protection requires online-mode or a proxy like JPremium.

Install

Replace the wasm and restart. Existing premium accounts keep working (their stored premium_id is now also UUID-verified at join). Two new [messages] keys: premium.uuid_mismatch, premium.uuid_wrong.

0gln Auth v0.1.2

Choose a tag to compare

@TuiLaZeroTwo TuiLaZeroTwo released this 12 Sep 03:45

Fixes: Permission already registered error on startup.

What was broken

v0.1.1 failed to load: all seven player commands share one permission node (0gln Auth:player), and the plugin tried to register that node once per command - the second attempt was rejected as a duplicate and aborted initialization.

Fix

Permission nodes are now registered exactly once per unique node; every command still attaches to its node. The plugin initializes cleanly.

Install

Replace the wasm in the server plugins/ directory and restart. No data migration needed.

0gln Auth v0.1.1

Choose a tag to compare

@TuiLaZeroTwo TuiLaZeroTwo released this 12 Sep 03:24

Fixes plugin initialization failure on live servers.

What was broken

v0.1.0 failed to load: Pumpkin rejected the permission nodes (0glnauth.player / 0glnauth.admin) because permissions must be namespaced under the plugin's name.

Fix

Permission nodes are now fully namespaced: 0gln Auth:player and 0gln Auth:admin. The plugin initializes, registers commands and handlers, and passes the permission gate.

Install

Same as v0.1.0: copy zero_gln_auth.wasm into the server plugins/ directory (offline mode required). Existing account stores are unaffected.

If v0.1.0 already wrote a data folder, no cleanup is needed - it failed before creating any store. Full changelog and docs: see README.

0gln Auth v0.1.0

Choose a tag to compare

@TuiLaZeroTwo TuiLaZeroTwo released this 12 Sep 02:53

0gln Auth v0.1.0

Authentication plugin for Pumpkin (Rust Minecraft server), built as a WASM plugin for offline-mode servers. A remake of AuthMe + JPremium logic in Rust.

Features

  • Cracked (offline) players: classic /register + /login password flow (Argon2 hashing, 8-64 chars, password != username), /logout, /changepassword, /unregister
  • Premium (paid) players: claim your name once with /premium - verified live against Mojang session servers, then auto-login on every join
  • Sessions: relog within 120 min from the same IP resumes silently
  • Freeze before login: unauthenticated players cannot move, chat, run non-auth commands, break/place blocks, interact, drop items, or attack
  • Login timeout: unauthenticated players kicked after 120s
  • Rate limiting: 5 wrong passwords from one IP = kick (counter survives reconnect, resets only on success)
  • Single session: a name cannot be online twice - duplicate joins denied at pre-login
  • Config-driven: full config.toml with policy keys AND an editable [messages] section - every player-facing message can be reworded, Bukkit-config style
  • Fail-closed design: corrupt store/config fails the plugin load loudly (never silently wipes accounts); store errors never auto-allow anyone

Install

  1. Server must run offline mode (online_mode=false / authentication disabled)
  2. Download zero_gln_auth.wasm and copy it into the server plugins/ directory
  3. Start the server - config is generated in plugins/data/0gln Auth/
  4. Requires Pumpkin plugin permissions: fs.read.data, fs.write.data, http.outbound (for /premium Mojang checks)

Commands

Command Who Effect
/register everyone create cracked account
/login (+ /l, /log) everyone log in
/premium everyone verify name with Mojang + auto-login forever
/logout, /changepassword, /unregister players account management
/setpremium on/off, /forcelogin ops (level 3+) admin tools

Security notes

  • No join-time auto-resolution: a premium name is only granted through an explicit /premium claim (Mojang-verified) - existing password accounts can never be silently converted
  • Residual risk (documented): the first /premium claim on an unregistered premium name owns it on this server
  • WARNING: if the plugin fails to load, the server runs WITHOUT auth - check /plugins after config changes

Tech

Rust (WASM, wasm32-wasip2), pumpkin-plugin-api 0.1.0-dev+26.2-26.45, Argon2, waki (WASI HTTP), JSON flatfile storage with atomic writes, TOML config.

Built from commit 987a8d7. 26/26 unit tests passing.