Skip to content

0gln Auth v0.1.0

Choose a tag to compare

@TuiLaZeroTwo TuiLaZeroTwo released this 12 Sep 02:53
· 3 commits to main since this release

0gln Auth v0.1.0

Authentication plugin for Pumpkin (Rust Minecraft server), built as a WASM plugin for offline-mode servers. A remake of AuthMe + JPremium logic in Rust.

Features

  • Cracked (offline) players: classic /register + /login password flow (Argon2 hashing, 8-64 chars, password != username), /logout, /changepassword, /unregister
  • Premium (paid) players: claim your name once with /premium - verified live against Mojang session servers, then auto-login on every join
  • Sessions: relog within 120 min from the same IP resumes silently
  • Freeze before login: unauthenticated players cannot move, chat, run non-auth commands, break/place blocks, interact, drop items, or attack
  • Login timeout: unauthenticated players kicked after 120s
  • Rate limiting: 5 wrong passwords from one IP = kick (counter survives reconnect, resets only on success)
  • Single session: a name cannot be online twice - duplicate joins denied at pre-login
  • Config-driven: full config.toml with policy keys AND an editable [messages] section - every player-facing message can be reworded, Bukkit-config style
  • Fail-closed design: corrupt store/config fails the plugin load loudly (never silently wipes accounts); store errors never auto-allow anyone

Install

  1. Server must run offline mode (online_mode=false / authentication disabled)
  2. Download zero_gln_auth.wasm and copy it into the server plugins/ directory
  3. Start the server - config is generated in plugins/data/0gln Auth/
  4. Requires Pumpkin plugin permissions: fs.read.data, fs.write.data, http.outbound (for /premium Mojang checks)

Commands

Command Who Effect
/register everyone create cracked account
/login (+ /l, /log) everyone log in
/premium everyone verify name with Mojang + auto-login forever
/logout, /changepassword, /unregister players account management
/setpremium on/off, /forcelogin ops (level 3+) admin tools

Security notes

  • No join-time auto-resolution: a premium name is only granted through an explicit /premium claim (Mojang-verified) - existing password accounts can never be silently converted
  • Residual risk (documented): the first /premium claim on an unregistered premium name owns it on this server
  • WARNING: if the plugin fails to load, the server runs WITHOUT auth - check /plugins after config changes

Tech

Rust (WASM, wasm32-wasip2), pumpkin-plugin-api 0.1.0-dev+26.2-26.45, Argon2, waki (WASI HTTP), JSON flatfile storage with atomic writes, TOML config.

Built from commit 987a8d7. 26/26 unit tests passing.