AuthCore Changelog
All notable changes to AuthCore, from the first alpha to the current release.
[1.0.0] - 2026-08-15
Build, mixin & proxy-gate hardening (2026-09-06, latest)
Build-time remap errors fixed - all 4 Cannot remap warnings gone
startSleepinglobby restriction: theEither-returning overload never existed on any supported version; unified to the void overload that exists everywhere.- Elytra block:
startFallFlyingwas removed from the mappings long ago (the injection silently never ran); it now injectsupdateFallFlying, the per-tick glide driver, which also extends the elytra + jump lobby restrictions to the 1.16-1.18 range. - Mount block:
startRiding(Entity,Z)was replaced by a 3-arg overload in 1.21.9; the mixin now injects the 1-arg final entrypoint plus the era-specific force overload, so mount blocking actually runs on 1.19-1.21 instead of silently no-oping. - Deop tracking: the
GameProfile->NameAndIdAPI swap happened in 1.21.9, not 26.x; the stonecutter cut point was corrected and the handler uses@Coerceso the same jar never references the 1.21.9-onlyNameAndIdtype.
Runtime mixin crashes fixed (host matrix back to green)
ServerPlayNetworkHandlerMixinlegacy handlers andPlayerListOpMixinusedObjecthandler parameters, which Mixin rejects at runtime (InvalidInjectionException) - the 1.16-1.18 fabric legs and all 26.x legs failed as a result. Handlers now declare the exact packet types.
Startup banner fixed on log4j-era loaders
- On runtimes without slf4j (1.16-1.18 Fabric/Forge) the entire banner printed literal
{}placeholders instead of values. The fallback console logger now substitutes slf4j-style placeholders, so version, Minecraft version, database type and every security flag display correctly.
Proxy-gate bypass & spoofing hardening
- Velocity/BungeeCord proxy gate: a gate error previously failed OPEN (unauthenticated
players allowed through even with
block-unauthenticated=true); it now fails CLOSED by default - deny unless the operator explicitly setsfail-closed=false. - Interop messages (
AUTH_CHANGED) are no longer accepted from player connections - only backend-server senders are trusted, and messages are consumed so they can never be forwarded to clients.
CI: rolling latest-build release & test suite growth
- Every
mainpush that passes build + host tests republishes thelatestGitHub release: same-version uploads REPLACE the jars and regenerate the changelog notes; the stablev*tag release remains the "Latest" release. - Test suite grown to 180+ checks (spoof guard, trusted proxies + CIDR, proxy config strictness, interop parsing, session cache); the Docker harness now verifies server-mode auto-detection and banner data correctness on every leg.
Detection hardening & bypass resistance (2026-09-05)
Full details in changelogs/changelog.md:
7-layer defense-in-depth stack (companion attestation, packet-sequence validation,
behavioral profiling, look-pattern analysis, login-timing distribution, concurrent-farm
fingerprinting), plus the strict trusted-proxies forwarding model and fail-closed proxy
auth defaults.
Hybrid mode, per-account login style & release hardening
Anti-float platform - mid-air logouts can never kick players in the limbo
- A player who logs out mid-air (or underwater) used to be kicked by vanilla's
"Flying is not enabled" floating check while standing in the limbo. AuthCore now
places an invisible BARRIER platform under the limbo player (
lobby.anti-float-platform, on by default); diving players are stood on a platform at the water/lava surface instead of being left submerged. The original block is restored shortly after the authentication flow completes (lobby.anti-float-platform-delay-ms, default 10 seconds) - never overwriting a block another player placed in the meantime. - Crash recovery for the limbo (already present, verified): the pre-limbo snapshot (exact position + dimension, inventory, effects, game mode, health/food/xp) is persisted at lock time; if the server (or the player's session) crashes mid-limbo, the snapshot is restored on the next join BEFORE the fresh lock, so after login the player always returns to the exact spot they were at their last disconnect - regardless of the admin-configured limbo location.
- Movement lock hardened: with movement disabled, the per-tick limbo re-assert now snaps the player back at a 0.25-block drift (was 1.0) - on runtimes without the movement-cancel mixin (Fabric/Forge 1.16-1.21 without a mixin refmap) this is the only server-side lock, and it now holds the player essentially in place. Known limitation: on those runtimes the client can briefly ghost-walk up to the snap interval; the restriction is fully packet-level on NeoForge and every 26.x jar.
Server mode is always taken from server.properties - the config override is gone
- The
session.server-modesetting is removed entirely: the mod always reads the realonline-modefrom the running Minecraft server (MinecraftServer#usesAuthentication). Premium auto-login works the same on online AND offline-mode servers (on offline servers AuthCore re-runs the vanilla encryption handshake and verifies with the server's own Mojang session service - no external API calls; failures fall back to offline register/login, players are never blocked or kicked). - Online-mode servers get a startup warning to keep
enable-secure-profile=falseinserver.properties, so clients without a secure chat profile (cracked/modded players) can still join and chat.
Hybrid servers: offline-mode players can join BOTH server modes
- New
allow-offline-playersconfig (session.authentication, defaulttrue): with it on, offline (cracked) players can join and register/login on online-mode servers too - the login mixin intercepts offline-UUID clients on online-mode servers and runs them through vanilla's own offline accept flow (no Mojang session check, offline UUID kept; online-mode players still use their real UUID and the normal session verification). Fail-safe: on versions where the offline accept flow cannot be driven, vanilla's normal rejection takes over - nobody is stranded. - With
allow-offline-players = falsethe server is online-mode-only everywhere: offline players are kicked with a clear message on arrival (join gate, before session resume / register / login), and on online-mode servers they are disconnected at login.
Premium auto-login respects its config on BOTH modes; auto-login players keep a null password
- The
premium-auto-loginconfig (on by default) is now honored regardless of the server's mode. Auto-login players are NEVER given an auto-generated password - their stored password stays null (the oldpremium-auto-registerrandom-password path is removed). - If auto-login is turned off (or a player switches to password login), verified online-mode
players are treated like any standard account: because their password is null they are
asked to
/registeron their next re-auth. Their online-mode status is preserved, so auto-login simply resumes when the config (or their mode choice) is switched back.
Per-account login style: players and admins can switch online/offline mode
- New player command
/account set-mode online|offline(permissionauthcore.user.setmode, level 0): switches the player's own account between automatic login and password login. - Switching to password login is smart about passwords: a player who ALREADY has a stored
password keeps it and simply logs in with it (
/login); only auto-login accounts with a null password are asked to/registera new one. The active session is destroyed either way so the change takes effect on the next join. /authcore set-mode offline <player>no longer takes a password argument and follows the same rule (existing password kept / register when null). Both admin mode commands destroy the session too.- A player's own mode choice is honored on join: accounts explicitly set to password login are never auto-logged-in, even on an online-mode server where the session was verified.
Terminology: "premium"/"cracked" replaced project-wide
- Non-user-facing text (console logs, debug output, admin commands, web panel labels, code
comments, docs) now uses online-mode players and offline-mode players instead of
"premium players" and "cracked players". Internal identifiers and the
premium-auto-loginconfig key stay unchanged for API/config compatibility. - Player-facing messages stay human: auto-login greets with "Welcome to the Server!", mode switches talk about "automatic login" / "password login" - no technical jargon anywhere in chat, titles or kick screens.
Limbo guard debug output
- The per-join limbo guard report is now debug-level and formatted like the startup banner:
one aligned row per guard (movement / chat / commands / block-break / block-use / item-use
/ item-drop / attacks, each
allowedorLOCKED) plus a live lobby-usage line ("35% used (7/20)", "unlimited" when no cap).
Scale, race-condition safety & docs
- Performance/scalability pass documented for 500k+ registered accounts and thousands of
concurrent players: O(1) user lookups on every hot path, lazy DB loading, bounded
self-cleaning caches, no resource spikes under join/login bursts (per-user throttles,
rate limits, fixed-size daemon IO pool), race-condition-free concurrency (canonical
single-
User-per-account cache,synchronizedDB access,volatileshared state, deduped join/leave hooks, atomic counters). - Docs re-skin: the hosted docs now use a black + red fortress-cyber theme with an enhanced sidebar table of contents (topic count, in-TOC scroll progress, back-to-top, glowing active states) and a wider, spread-out content layout; README and every docs page updated for the current behavior.
Limbo, performance & configuration overhaul
Limbo quality pass (no more screen vibration, no bypasses)
- Anti-vibration movement correction: the client was snapped back on EVERY violating
movement packet (up to 40 position packets/s → rubber-banding). Corrections are now
distance- and throttle-based:
lobby.movement-correction-radius(default 1.5 blocks) andlobby.movement-correction-interval-ms(default 600ms), the classic AuthMe feel (ghost-walk a little, one clean snap). Movement packets are still cancelled on every packet, so the server entity never leaves the anchor (no bypass). - Vehicle-movement bypass closed:
handleMoveVehiclewas uncovered: lobby players on boats/minecarts (or spoofing the packet) could move freely. Now cancelled + anchored like player movement. - Inventory lock without touching chat: the inventory is fully inert in the limbo
(every slot click blocked and force-closed on interaction, including shift-clicks and
armor equipping), while the chat input is NEVER interrupted, so
/registerand/loginalways work. A periodic force-close packet was tried and removed again: the client closes ANY screen (including chat) on a container-close packet, and there is no server-side signal for "inventory open"; click-based blocking is the only safe approach. - Attack-callback fix (the "can't hit mobs" bug): the fabric
AttackEntityCallbacklistener was registered under the wrong method name (attackinstead ofinteract), so the reflective proxy returned null for every attack and the fabric event cancelled ALL attacks for everyone, in and out of the lobby. One-line fix. - Server-side auth menu removed (chest menu + book input +
/menucommand): auth is purely chat-driven with clickable buttons; the menu system, its mixins and its command are deleted entirely. - Context-aware chat buttons: the login/register buttons build the EXACT command shape the player needs (password confirmation, 2FA code, captcha code) and show it in the action bar; no confusion about which auth factors apply.
- Styling: clickable chat buttons are now underlined; the action bar gets the same drop-shadow as titles/subtitles.
- Crash-safe limbo verified: the pre-limbo snapshot is saved at lock, restored before the fresh lock on rejoin after a crash, and deleted on clean unlock; the unlock lifts restrictions before any restore step so a failed restore can never keep a player stuck.
Performance pass (constant per-packet cost, bounded memory)
- O(1) user lookups on every hot path: new
User.getUser(UUID)/User.getUser(player). a single map get, no string allocations, no scans, no DB, and all per-packet mixin guards (movement, clicks, chat, ticks, entity events, commands) now use it. - Indexed username lookups: precomputed lowercase names + a
byLowerNameindex makelookUpByUsernamemode O(1) too (previously a full-map scan with per-entrytoLowerCaseallocations). - Throttled cache touches: the last-access map put now happens at most once per minute per user instead of on every packet.
Split configuration (one file per config block)
settings.conf(root: language, debugMode, logging, cache) +lobby.conf+session.conf+password-rules.conf+commands.conf+database.conf+messages-<lang>.conf. Section files override the same block in settings.conf and are written with defaults on first boot; existing single-file configs migrate automatically (legacy sections are stripped from settings.conf on save; every setting has exactly one owner). Redis-distributed config overrides still merge on top.
Hybrid / hub networks
- Session resume no longer requires the same IP when
session.session-from-same-ip-onlyis disabled: on proxy networks the forwarded IP can legitimately differ hub ↔ game, which previously silently dropped sessions on every hub transfer.
Fixed since 1.0.1
ServerEventsFallbackLeaveMixinsilently missing from built jars (stale incremental compile state dropped the new class); rebuilt with--rerun-tasks; all 21 mixins verified present in every jar.- Mixin handler descriptors now match the target methods exactly on 26.x
(
placeNewPlayer3-arg,tickServer(BooleanSupplier)), so the server no longer aborts withInvalidInjectionException.
1.19-1.21 backward compatibility (NeoForge 21.1.x)
- NeoForge 21.1.x boot fixed: the
1.19-1.21NeoForge jar crashed at startup on NeoForge 21.1.x (e.g. 21.1.248, Minecraft 1.21.1) with aNoClassDefFoundErroronnet/minecraft/resources/Identifier- theResourceLocation→Identifierrename happened at 1.21.11, so the build target's class name could not load on older 1.21.x. The font style no longer callsIdentifier.tryParse()directly (it is a deliberate no-op - the font API keeps changing shape every version and the old reflective lookups hung the server thread), andCompat/Lobbyno longer import either class name - the compat layer stays fully reflective. - NeoForge loader minimum corrected:
neoforge.mods.tomlno longer requires[21.11.45,)(the build-target pin, which rejected every NeoForge 21.1.x server). The G2 jar now declares[20.2.59-beta,)(the first NeoForge supporting the group's lowest Minecraft version), matching the Forge/Fabric minimums. - gson no longer bundled in NeoForge jars: the shaded
com.google.gsoninside the jar-in-jar set made the NeoForge module layer ambiguous (com.google.gsonis already provided by the game) and prevented startup. Forge AND NeoForge builds now exclude gson from the shaded configuration; Fabric keeps the shaded copy. 1.21.1added to the host-test matrix: the Docker harness now boots the G2 jars on Minecraft 1.21.1 (with the matching NeoForge 21.1.x / Fabric / Forge loaders) in addition to 1.19.4, 1.20.6 and 1.21.11, so this regression is caught automatically.
Out-of-the-box experience & hardening (2026-08-14)
Server mode is now auto-detected (server-mode = "auto", the new default)
- The real
server.propertiesonline-mode is read from the running server (MinecraftServer#usesAuthentication) - cracked AND premium servers work with zero config changes. Explicitonline/offlinevalues still override, with a one-time mismatch warning. - Previously the default (
"online") kicked online-mode players on offline-mode servers with a bogus "Your Authentication Token is invalid" (premium-UUID mismatch against their offline-mode UUID) and silently auto-registered offline-mode players as premium (no register/login prompt, no limbo). Both are fixed.
Premium auto-login works on offline-mode servers, outage-proof
- Premium status of new accounts is verified asynchronously (IO pool) - the join path makes zero blocking Mojang API calls.
- If the Mojang API is unreachable at join, the player is shown "Checking your premium account..." and the check auto-retries in the background (every 20s, up to 4 min) - auto-register + auto-login resume the moment the API confirms the name.
- Tri-state premium lookups (
PREMIUM/NOT_PREMIUM/UNAVAILABLE) so a cached null can never be mistaken for a definitive negative; API failures are throttled (30s error cache). - HTTP 204 ("not a premium profile") now counts as a healthy API response - previously every offline-UUID lookup decayed the API-health window and produced bogus "Mojang API is currently unreachable" warnings.
- The premium-name squatting guard only fires when premium auto-login is disabled (it used to kick legitimate online-mode players joining offline servers before auto-login could run).
- Auto-registered online-mode players now see "Registered! Your account has been created!" as clear feedback.
Messages display correctly on every version and loader
- Title packets were broken on 26.x (the compat layer only knew the 1.16-1.21 Yarn class
names) - every title/subtitle message was silently dropped.
Compat.sendTitlenow tries the 26.x Mojang names (ClientboundSetTitleTextPacket/ClientboundSetSubtitleTextPacket/ClientboundSetTitlesAnimationPacket), the older Mojang fade name, Yarn names, then the 1.16 combined API. - Richer multi-channel templates: login, registration, wrong password, not registered, captcha, password change, session resume, premium auto-login and the lobby welcome now use title + subtitle + action bar combinations.
- Title fade timings are floored so a title can never render with 0-tick fades.
Audit fixes (logic, errors and bypasses)
- Chat restriction bypass on 26.x: the chat handler was renamed to
handleChat- the mixin now targets it, so lobby players can no longer chat on 26.x. - Command restriction on Forge/NeoForge: the lobby command whitelist/blacklist only matched
Yarn names (
method_9249); the MojangperformCommand/executetargets are now covered, so it applies on Forge 1.16-1.21 and NeoForge too. - Stale companion-token kick:
verifySessionClaimno longer kicks players who are already authenticated this join (premium auto-login etc.) over a stale/absent companion token. allowMobDamagehonored: mobs can now target lobby players when the config allows it (previously the mixin blocked targeting unconditionally).- Hash-failure free-roam closed: if password hashing fails during register, the player is locked into the lobby instead of being left authenticated-but-unregistered with full access.
- Interop parity:
User.login()/logout()now broadcast the auth state on theauthcore:authchannel - premium auto-login, session resume and deferred verification previously stayed silent to proxies/other mods. - Legacy-hash verification:
Encrypter.verifyfalls back through all supported algorithms instead of throwing password4j parse errors ("Bad salt length" / "Invalid salt version") on migrated/foreign DB rows; argon2 hashing uses an explicit spec-conformant 16-byte salt. - Ghost-detection window no longer goes negative with small config values.
- Chat commands on 1.16-1.18.2: chat commands ride the chat packet there - the chat
restriction now lets "/"-prefixed messages through to the command dispatcher (the lobby
whitelist still blocks non-auth commands), so
/loginand/registerwere unblockable for lobby players on the classic line. - Adventure-mode limbo applied:
lobby.force-adventure-modenow actually switches the player into adventure on lock (the game-mode-change mixin only blocked leaving it). - Mode-switch / proxy safety: online-mode players whose account is keyed by the offline UUID (server switched online-mode, or Velocity forwarding on an offline backend) are no longer kicked with the "Authentication Token is invalid" mismatch - the genuine premium profile is confirmed against the Mojang API and auto-logged-in instead.
- Failed-hash guard: a password hashing failure in
/account set-password, email recovery,/authcore set-password, mode changes or the web panel can no longer silently set the stored password to null and unregister the account. - IP-rules whitelist semantics:
allowrules are no longer silent no-ops - when anyallowrule exists, unmatched IPs are denied (whitelist mode). - Login history parity: every login path (premium auto-login, session resume, deferred
verification, SSO) now records a login-history row, not just
/login. - Returning-premium re-validation: on offline-mode servers the premium claim of returning accounts is re-checked against the Mojang API asynchronously - accounts auto-created as "premium" by earlier builds are downgraded to offline-mode (register/login prompt) while legit premium names keep auto-login (fail-open during API outages, cache-aware tri-state).
- Mojang API removed for premium detection: premium status now comes ONLY from the
server's OWN Mojang session authentication - a login mixin captures the profile that
vanilla's
hasJoinedSerververified (carries Mojang textures properties). All direct Mojang HTTP lookups (name/uuid profile APIs) were removed from the join flow. On offline-mode servers nobody can be premium (the server authenticates no one), so offline players are NEVER auto-registered or auto-logged-in anymore - stale "online-mode" DB flags from earlier builds are detected and downgraded on join (register/login prompt). - Server-side premium verification (offline servers): with premium auto-login enabled the
login mixin now runs the vanilla encryption handshake on offline-mode servers and verifies
the session with the server's own
MinecraftSessionService- genuine online-mode players are auto-logged-in while cracked clients (and any Mojang outage) fall back to the normal offline register/login flow. Fail-safe: handshake failures, API timeouts and clients that never answer (15s watchdog) all continue as offline - nobody is ever kicked or stranded. - Extra limbo restrictions: item usage (
useItem), riding/vehicle entry (startRiding), sleeping in beds, and offhand-item swapping are now blocked in the lobby on EVERY loader; players riding into the lobby are dismounted on lock. New config keyslobby.allow-sleepingandlobby.allow-item-swapping(both default false). - Full-proof post-login restore: the snapshot restore now re-mounts the player's previous vehicle, lands airborne survival players on safe ground (elytra gliding / mid-air), rescues players from suffocation when blocks changed while they were in the lobby, keeps swimmers in the water column, and clears fall damage from the restore itself - flying (creative/ spectator) is restored via the original game mode.
- Auto-migration of everything: ConfigMigrator now also refreshes the enriched multi-channel message defaults for configs that still hold the old single-channel values (custom messages are preserved); on first offline-mode detection the database is bulk-migrated once per boot (stale "online-mode" flags cleared); schema and config keys migrate automatically as before.
- Command availability fix: /register, /login and /account were reported as "Unknown
command" on 1.20.5+ (26.x) because the OP-level permission check used APIs that no longer
exist there (PermissionLevel / getPermissions). The check now short-circuits for level 0
(all players) and resolves the new
net.minecraft.server.permissionsAPI on 26.x, the older permission API on 1.20.5-1.21, and the legacy method on 1.16-1.18. - New docs page - Authentication Flows (
docs/1.0.0/flows.html, linked from the nav, README and guide learning path): every flow explained step by step in plain language with the functions involved (join, limbo lockdown, register, login, session resume, logout, premium verification, auto-migration) plus the failure-safety guarantees. - Repository hygiene: removed ~5.5 GB of generated artifacts from the working tree
(host-test work dirs, variant build outputs, rendered site, node_modules) and removed
dead code (unused config keys
allowOnlineNameByOffline/premiumApiStrict, unused message template, unused User suppliers and Snapshot fields). - Security suite now 86 checks (legacy-hash fallback, wrong-algorithm verification,
AuthMe
$SHA$verification, algorithm inference, weak-algorithm detection). - Third-party mod integrations (
in.potenfyr.authcore.integration): optional, reflection-based, best-effort support for DiscordSRV (the linked Discord account is auto-imported on authentication so webhooks/notifications can use it) and InteractiveChat (compatible - AuthCore restrictions are lobby-scoped and never touch other mods). New/authcore compatcommand reports loader, server mode and integration state. - Version-gated config migrations (
ConfigMigrator): runs after config load, applies registered upgrade steps for newer versions, bumpsconfig.versionand persists - the pipeline for future structural config changes (1.0.0 -> 1.0.1 ships with no transforms needed; runtime auto-detection handles the server-mode default change). - Transparent password-hash upgrade: weak (md5 / sha-256 / sha-512) or outdated stored hashes - including AuthMe-style imported ones - are re-hashed with the configured algorithm on the account's next successful login (never blocks the login, flagged in the security log).
- AuthMe import (
/authcore import authme <file>): imports accounts from an AuthMe SQLite database; existing accounts are never overwritten; legacy hash formats are supported ($SHA$, bcrypt, argon2, pbkdf2, scrypt, plain hex digests) and verified/upgraded on login. - Security suite now 82 checks (legacy-hash fallback, wrong-algorithm verification,
AuthMe
$SHA$verification, algorithm inference, weak-algorithm detection).
Universal single-jar architecture (1.16.x - 26.1-26.2) (2026-08-11)
- One source, every Minecraft version - the old per-version source sets are gone; version
variants live under
src/(src/main/java+src/client/java= classic yarn code,src/modern/java= Mojang 26.1-26.2 code) behind thein.potenfyr.authcore.compatreflection layer and version-stable mixin targets. Verified by compiling the identical source against 1.16.5, 1.17.1, 1.18.2, 1.19.4, 1.20.6, 1.21.1 and 1.21.11 (all green), with a per-push CI matrix. - Universal mixins: login hello (reflects over
getProfile()vsname()/profileId(), plus authlib'sgetName()/getId()vs recordname()/id()), handshake proxy forwarding (record accessor vs private field), chat restriction (single mixin coveringonGameMessage/onChatMessage/handleChatMessage). FabricHooksregisters commands (API v1/v2), item-use and damage events reflectively - missing fabric APIs are skipped gracefully.fabric.mod.jsondeclaresminecraft >=1.16.0,java >=16,environment "*"- the same jar runs on servers AND clients, standalone or behind Velocity / BungeeCord.- Version-independent features (commands, config, database, security, web panel, email, Redis) work unchanged on every version.
- Client companion always included: the universal jar bundles the client login-screen companion (auto-login GUI) for 1.20.2+ clients. The companion is fully reflection-guarded, so the jar loads safely on older clients (1.16 - 1.20.1) and simply skips the screen there.
- If the client cannot send the auto-login command (e.g. signed-chat restrictions), the player gets an in-chat hint with the exact command to type instead of failing silently.
- Limbo tick re-assert guards: every tick the lobby re-applies the blindness/invisibility effects (lost e.g. by milk) and teleports lobby players back when movement is disabled and they drifted - fallbacks for environments where the version-specific mixins cannot apply.
- Defense in depth:
/loginand/registerre-verify their prerequisites at execution time, not only in the commandrequirespredicate. - Release automation: tag-triggered GitHub workflow (
ci.yml- the ONLY workflow now) builds the universal jar, extracts the changelog section for the tag and drafts a release with the jar attached. - One workflow, honest CI: all previous workflows (build / client-check / lint-test /
gradle-validate / dependency-audit / multi-version-check / release) were merged into a
single
ci.yml. Matrix builds no longer mask failures (gradlewexec-bit bug fixed, yarn versions corrected: 1.19.4+build.2, 1.20.6+build.3, fabric-api 0.46.1+1.17, 0.100.8+1.20.6). - Full proxy-side auth: the proxy plugin (BungeeCord + Velocity) can now disconnect players WITHOUT a valid Redis session (block-unauthenticated=true in config/authcore-proxy.properties) before they reach any backend - zero-dependency RESP Redis client, fail-open on Redis outage, /authcore status command.
- 26.1-26.2 snapshot compile checks: new daily CI job compiles the modern source against the NEWEST 26.1-26.2 release the moment Fabric publishes yarn mappings for it - fails visibly on breakage.
- **Velocity modern forwarding (Fabric server): HMAC-verified velocity:player_info login receiver applies the real UUID/username when velocity-secret is set; legacy/BungeeCord handshake parsing auto-detected (protocol = auto).
- Interop channel authcore:auth + BungeeCord AuthCore subchannel - other mods and proxies can coexist with a DIFFERENT auth mod on the backend; broadcasts on join/login/register/logout/kick/unregister (session.interop).
- Separate database config: optional config/authcore/database.conf (only the database { } block) is merged over settings.conf, so credentials can live outside the main config.
- Config per role: server = settings.conf, client = authcore-client.json, proxy = authcore-proxy.properties, database = database.conf.
- 26.1-26.2 support (real build): Minecraft 26.0+ is unobfuscated (Mojang names at runtime,
intermediary gone), so AuthCore ships a second jar built from the Mojang-mapped
source (
src/modern/java,-Pmodern=true, loom 1.16.x, Java 25, no mappings):authcore-modern-1.0.0.jarfor 26.0+ servers/clients. The classic universal jar covers 1.16.0 - 1.21.11. Both jars carry the client login-screen companion (environment "*"), and the release workflow attaches both. The two name-spaces cannot coexist in one jar - seedocs/26x.mdfor the migration/sync workflow.
Multi-loader & multi-version workspace (Stonecutter / Stonecraft)
- One Mojang-mapped source tree, three range jars per loader: fabric/forge/neoforge for 1.16-1.18, 1.19-1.21 and 26.1-26.2 (7 release jars in total).
- Verified on every range endpoint: 1.16.5, 1.17.1, 1.18.2, 1.19.4, 1.20.6, 1.21.1, 1.21.11, 26.1.2, 26.2, all 22 harness checks PASS on all 7 loader build targets.
Modrinth version range fix
- Uploaded jars no longer claim every Minecraft version. The shipped metadata now declares the
exact supported range per jar, so Modrinth pre-selects precisely the tested versions instead
of the full grid:
- Fabric (
fabric.mod.json):>=1.16 <=1.18.2/>=1.19 <=1.21.11/>=26.1 <=26.2. - Forge / NeoForge (
mods.toml/neoforge.mods.toml):[1.16,1.18.2]/[1.19,1.21.11]/[26.1,26.2](maven syntax).
- Fabric (
- Loader minimums are now the group-aware floors (the first loader version supporting each
group's LOWEST Minecraft version, never the build target - otherwise in-range servers are
rejected): Fabric loader
>=0.14.24(1.19 line) />=0.16.0(26.1 line), FML[41.1.0,)(1.19 line) /[36.1.0,)(1.16 line), NeoForge[20.2.59-beta,)(1.20.2 line) /[26.1.0,)(26.1 line). - Root cause: the range placeholders never reached the built jars -
fabric.mod.jsonshipped"minecraft": "*"(Modrinth reads this as "all versions") andmods.tomlshipped only the single build target. All 7 jars were rebuilt and their metadata verified.
Security & anti-bypass
- ClientGuard: behavioral profiles, 16 detection signals (ghost clients, missing client settings, packet/click/chat/payload floods, tab probing, fake companions, confusable names, concurrent logins), weighted risk score with a decision matrix.
- Companion attestation: challenge-response HMAC, periodic re-challenges, session tokens (rotated on every login, hashed at rest) and token-based session resume.
- MFA / 2FA: TOTP + single-use recovery codes + optional email OTP + MFA step-up for sensitive commands.
- Network SSO: Redis-backed single sign-on across a server network (optional).
- Error codes: console-only AC-... codes at every failure site, decodable by the author; no internals leak to clients.
Security fixes found by the new test suite
- PBKDF2 DoS fixed - password4j's PBKDF2
check()could hang the server thread during login. PBKDF2 is now a self-contained JDKSecretKeyFactoryimplementation ($pbkdf2-sha256$iter$salt$hash, constant-time comparison).
Performance for 100k+ users
- Lazy user loading - users are fetched from the database on demand (join/login/whois) instead of loading the whole table at startup. A 100k-registered server keeps only online + recently-touched users in memory.
- Bounded LRU cache (20k max) with idle eviction; online users are never evicted.
- Admin
listcommands,whois, export and the web panel are now database-backed (bounded, searchable queries) instead of iterating the in-memory map. - Thread-safe canonical cache (a single User instance per account under concurrent access).
Race-condition hardening
AuthCoreServer.config/messages, user session fields,TpsManager.tickCounterand the DB connection are nowvolatile.- All database access is
synchronized(single shared JDBC connection is never used concurrently). - User cache-miss fetches are serialized under a dedicated lock.
New features
- Cross-server security event bus (Redis pub/sub
authcore:events): login, logout, register, brute-force, account-locked and kick events are broadcast network-wide; receivers log, webhook and execute remote kicks. - Discord account linking:
/discord link|unlink, 6-char link codes (webhook + Redis, 10-min TTL), bot completion via the web panellinkaction,discordIdstored per account. - Maintenance mode:
/authcore maintenance on|offblocks all joins with a custom message. - Honeypot: a fake listener port auto-bans every connecting IP (writes
denyrules toip-rules.conf). - Automated backups: scheduled SQLite copies / JSON exports with rotation (
session.backup). - Rotating announcements: list-based, interval-driven (
lobby.announcements). - Password history:
password-rules.history-sizeblocks reuse of recent passwords. - Fast-rejoin alert: bot-pattern detection (alert-only).
- Web panel: read-only token,
/metricsendpoint, DB-backed player list. - Extra webhooks:
security.extra-webhook-urls(Slack/Telegram/custom). /authcore validateconfig dry-run,/authcore resetpwalias.- New config surface for admins:
session.maintenance,session.honeypot,session.backup,session.authentication.auto-luck-perms-group,bind-bedrock-xuid,web-panel.readonly-token,rate-limit.alert-on-fast-rejoin,lobby.announcements,password-rules.history-size,security.extra-webhook-urls- all fully commented insettings.confand documented indocs/CONFIG.mdwith defaults + scenarios.
Quality
test/- standalone test suite (57 checks) covering password hashing round-trips, captcha lifecycle, email recovery, rate limiting, proxy parsing, device fingerprints. Run viatest/run-security-tests.sh.- Access control validation pass: every command re-verified (player vs admin vs console),
/discordguarded in lobby, read-only web token.
Bot / backend separation
- The Discord bot integration is now strictly backend-owned: the bot never touches the
database. Every write is executed by the mod backend through the web panel API; the bot
communicates over Redis (link codes
authcore:discordlink:*, mappingauthcore:discord:*,authcore:eventspub/sub) plus the API. Docs (API.md,WEBPANEL.md) state the rule explicitly.
Tooling
- Host-compat harness: range/loader/version selection, forward-compat scan, live logs, parallel 6, professional HTML dashboard + markdown coverage matrix, 22 checks.
- GitHub Actions: builds all 7 variants, Docker host-tests on every push/schedule, weekly compat scan that auto-releases new validated versions with changelog entries.
Cleanup
- Removed legacy / migration leftovers:
src/common/,src/client/,_migration/,postman/,release.sh,docs/migration.md. - Removed IDE artifacts (
.settings/,bin/,.classpath,.project,.factorypath), staledist/jars and the obsoleteauthcore-26.x-*jars. - Fixed mojibake in the ClientGuard config comment, removed duplicated/corrupt changelog sections, corrected stale wording ("26.0+" → 26.1-26.2, Java 17/21/25, multi-loader tagline).
Single human verification (map captcha & GUI removal, intelligence overhaul) (2026-08-16)
One verification method, scored on EVERY login
- The map captcha and its remnants are gone completely (no map items, no map-data
pipeline, no stale "map" text/config); the server-side screen/GUI code is removed too
(screen mixins, force-close inventory on clicks, the
IN_LOBBY/OUT_OF_LOBBYGUI signals - the client companion still ships its optional screens, the server no longer drives them). - The legacy text captcha (
Security.CaptchaManager), the post-login colored-itemsHumanVerificationand the captcha-farm detection are deleted - ActionCaptcha is now the single human-verification method. - Every login is scored independently - a first login does not make an account trusted,
and an account owner can hand their credentials to a bot, so sessions are never
pre-trusted. Signals: ghost pattern, ClientGuard risk, instant login (within
instant-login-sec), failed attempts before success, missing 2FA on a TOTP account, fresh account age, fast rejoin loops. Trust signals subtract: premium (Mojang-verified), valid companion session token, previously trusted account, already passed the challenge. A player is challenged (sneak / jump / look-up physical task) only when the score reacheslobby.captcha.bot-score-threshold(default 60). All weights are configurable and every decision is traced in debug logs. - No chat spam: the challenge prompt is a single message at start and one on success - no periodic progress spam.
- Fixed the "broken captcha" bug: trusted/TPS-bypass players were blocked at
/loginbecause the pre-auth gate checkedcaptchaVerifiedwhile the lobby skipped issuing the captcha. The pre-auth gate is gone entirely;/loginand/registerno longer take acaptcha-codeargument.
Debug logging everywhere, off by default
debug-modenow defaults to false (it wastrue). Withdebug-mode = trueadmins get a full trace of where and when the mod decides: join classification, lobby lock/unlock, login attempts, every ClientGuard signal (name + weight + description), every AuthIntelligence detection (flood/spray/2FA brute/registration-farm/session-replay/ ATO with counters and windows), the complete human-verification score breakdown, web-panel lockout tracking, webhook delivery and database dialect selection.
Host-test harness rebuilt (correctness + speed + player simulation)
- Verdict gaps closed:
securitySummary,maintenance,portListen,panelBadToken,panelLockoutnow actually fail the run (they rendered FAIL cells while the run said PASS). - The graceful-stop check was accidentally nested inside the honeypot
if- it is now top-level and always runs. - Player-simulation bugs fixed: the global timeout now writes its check file (a crashed/
timed-out sim used to count as a silent green PASS), the entrypoint captures the sim's
real exit code, markers reset per reconnect (the limbo prompt was never re-verified),
the post-login chat check could never detect new violations (stale "before" snapshot),
and a TDZ crash on every sim connect (
endPromisereferencinghandleduring its own construction) is fixed. - JSON escaping on
fail()and the result writer (quotes/backslashes can no longer corruptresult.json); parallel crash-recovery keeps the test identity (the caught exception overwrote$_→ blank FAIL rows). - Speed: JBR image builds run in parallel, shorter fixed sleeps (post-Done 5s→2s, command cadence 3s→2s, sim violation loop 60s→45s, post-login wait 7s→4s), default boot timeout 900s→480s, container log poll 2s→4s. Sim SKIPs (no protocol data for brand-new MC versions) render as n/a instead of FAIL cells, with the reason in the report.
- The player simulation keeps using
minecraft-protocol(the standard packet-event client;protocolobdoes not exist on npm). Verified: 1.18.2 / 1.21.11 / 26.1.2 resolve and connect; 26.2 cleanly SKIPs until protocol data is published.
Docs & setup guide
- New "Feature-by-feature setup" section in the guide: every feature (human verification, MFA, brute force, sessions, ClientGuard, AuthIntelligence, rate limits/IP rules, SSO, web panel + honeypot, premium/proxy, maintenance/shadow-ban/whitelist/announcements, backups/Discord/locales) with what it does, the exact config, and a real-world scenario.
- README gained a "Feature setup at a glance" table; the config reference documents the new captcha scoring settings.
[1.0.0-alpha.5] - 2026-08-08
- Velocity / BungeeCord proxy support (server-side IP forwarding,
session.proxy-support) - Web admin panel (HTTP/HTTPS with auto self-signed cert, token auth)
- Email recovery & alerts (SMTP login alerts,
/account recover) - Client login-screen companion (login GUI before joining)
[1.0.0-alpha.4] - 2026-08-08
- Combat-log punishment, Discord webhooks, security log + rotation, login history,
intelligence (new IP/country), account locking, risk scores, CAPTCHA, recovery codes,
progressive punishment, per-IP rate limits, PostgreSQL, Redis session/ban sync,
AuthCoreApi,/authcore backup|history, 6 new localized messages in 7 languages.
[1.0.0-alpha.3] - 2026-08-08
- Fixed premium (online-mode) detection: Mojang API-outage-safe, no player ever blocked by an API failure; transient failures retry; health-tracked lookups.
[1.0.0-alpha.2] - 2026-08-08
- Per-hash random salts (bcrypt/scrypt/pbkdf2 no longer broken), case-insensitive user lookup,
UUID re-keying, no account enumeration, command
requiresversion fix, console/authcore, MySQL URL fixes, localhost/LAN support, JDK HttpClient, structured startup banner.
[1.0.0-alpha.1] - 2026-01-01
- Initial framework: hybrid auth, limbo (lobby), session management, message system, granular lobby restrictions, 2FA (TOTP), config system (settings.conf + messages.conf).