
AethelGuard
Aethelguard is a secure and highly configurable authentication plugin for Paper servers, featuring captcha, 2FA, account recovery, VPN/proxy checks, adaptive security, clean console logs, and multi-language support.
Список изменений
🛡️ Aethelguard v0.3-sentinel
🧠 Adaptive Security + Recovery Update
Hello everyone! Aethelguard’s biggest update so far is here.
v0.3-sentinel transforms the auth system from a simple login/register structure into a much stronger security package with captcha, 2FA, recovery, adaptive security, VPN checks, and an advanced config system. ✨
🚀 Highlights
🧠 Adaptive Security
Aethelguard can now evaluate player login risk more intelligently.
- ✅ Captcha bypass support for trusted IPs
- 🚨 Extra captcha for suspicious IPs
- 📌 Manual suspicious IP list
- 🧪 Different captcha type selection for suspicious players
- 🧭 Risk detection when too many accounts are created from the same IP
- ❌ Risk evaluation based on failed password attempts
🕵️ VPN / Proxy Detection
VPN/proxy checking has been added with this release.
- 🌐 IPWHOIS support
- 🌐 IPAPI support
- 🧠 VPN, proxy, Tor, and hosting/datacenter signals
- ⏱️ Timeout setting
- 🗃️ Cache system
- 🛟
fail-openoption for API failures - 🏠 Toggle for local/private IP checks
Suspicious connections can be verified more carefully with extra captcha instead of going through the normal auth flow. 🛡️
🧯 Account Recovery
Players can now recover their accounts more safely.
- 🧠 Security question system
- 🧾 One-time backup code system
- 🔁 Recovery method selection
- 🔐
/recover question <answer> <newPassword> - 🔐
/recover code <backupCode> <newPassword> - ⚙️ Separate enable/disable options for security questions and backup codes
Security questions are loaded from separate language files:
- 🇹🇷
security_questions_tr.yml - 🇬🇧
security_questions_en.yml
📱 2FA / Authenticator
TOTP-based 2FA has been added.
- 📱 Compatible with Google Authenticator
- 🔐 Compatible with Microsoft Authenticator
- 🟣 Compatible with Authy
- 🧩 Compatible with other TOTP-supported apps
- ⚡ Players with 2FA enabled can go directly to
/2fa <code>after captcha
Commands:
/2fa setup
/2fa confirm <code>
/2fa disable <code>
/2fa <code>
🧪 Captcha System
Captcha verification has been added before login/register.
Supported captcha types:
- 🗺️
MAP - 🔤
TEXT - 🔢
NUMERIC - 🔡
ALPHANUMERIC - ➕
MATH
New captcha features:
- ⏱️ Captcha cooldown
- 🎯 Captcha attempt system
- 👢 Kick option after maximum captcha attempts
- 🧠 Captcha attempts are separate from login/register password attempts
- 🗺️ Map captcha item is removed from the player after authentication
- 🔊 Captcha success sound can be configured
🔑 Advanced Password Policy
Password security is now much more flexible and manageable.
Configurable options:
- 🔢 Minimum password length
- 🔢 Maximum password length
- 🔤 Required letter
- 🔢 Required number
- 🚫 Block username usage inside passwords
- 🇹🇷 Enable/disable Turkish characters
- ✒️ Enable/disable punctuation marks
- 😀 Enable/disable emojis, special fonts, and symbols outside the normal alphabet
- 🧹 Blocked word list
These rules apply to the following flows:
/register/changepassword/recover/aethelguard changepassword
⏳ Security Cooldowns
Cooldowns have been added for sensitive account security commands.
Configurable by default:
- 🔐 Password change
- 📱 2FA setup
- 📵 2FA disable
- 🧠 Security question change
- 🧾 Backup code generation
- 🔁 Recovery method change
- 🧯 Password reset with recover
Admins can also add their own commands to a custom cooldown list. ⚙️
🎒 Inventory Protection During Auth
Player items can now be hidden while they are on the captcha/login/register/2FA screen.
- 🎒 Hide inventory
- 🛡️ Hide armor
- 🧤 Hide offhand item
- ✅ Safely restore after authentication
- 🗺️ Prevent captcha map items from permanently mixing into the real inventory
📊 Bossbar and Prompt System
A bossbar is shown depending on the player’s authentication stage.
- 🧪 Captcha stage
- 🔐 Login stage
- 📝 Register stage
- 📱 2FA stage
Prompt repeats can now be configured separately:
- Captcha prompt repeat
- Login prompt repeat
- Register prompt repeat
- 2FA prompt repeat
Each one has its own interval setting. ⏱️
🧩 Config Sync System
The config system has been greatly improved.
Aethelguard now checks the config file on startup and reload:
- 🧩 Adds missing keys
- 📝 Adds new settings with comments
- 📌 Does not place new settings at the bottom of the file
- 🗂️ Places settings in the correct category
- 🔵 Sends an info log to console when the config is reorganized
- 🧼 Cleans up the old
local-loggingsection - 🛡️ Preserves existing admin values
🌍 Language and Console Improvements
The message system has been made more organized.
- 🇹🇷
messages_tr.yml - 🇬🇧
messages_en.yml - 🌐 Custom
messages_<code>.ymlsupport - 🧠 Separate language files for security questions
- 🖥️
enfor console - 🖥️
tr nativefor console - 🖥️
tr asciifor console
For panels that do not support Turkish characters properly, console-text-mode: ascii can be used. ✨
🧼 Log Cleanup
The vanilla log cleanup system has been preserved and improved.
Filtered logs can include:
joined the gameleft the gamelogged in with entity idlost connectionUUID of playerissued server command
Aethelguard now logs its own important auth events in a cleaner way. 🔎
🛠️ Added Commands
New player commands:
/securityquestion setup
/securityquestion answer <answer>
/securityquestion status
/backupcodes generate
/recoverymethod question
/recoverymethod backup-code
/recover question <answer> <newPassword>
/recover code <backupCode> <newPassword>
New/improved admin commands:
/aethelguard sessions
/aethelguard session <player>
/aethelguard clearsession <player>
/aethelguard clearsessions
/aethelguard unlogin <player>
🔄 What Changed From 0.2-sentinel to 0.3-sentinel?
0.2-sentinel was built around a clean login/register flow and cleaner console logs.
0.3-sentinel makes the auth system smarter, safer, and easier to manage.
In short:
- 🧪 No captcha before → Captcha system added
- 📱 No 2FA before → Authenticator support added
- 🧯 No recovery before → Security question + backup code recovery added
- 🕵️ No VPN checks before → VPN/proxy detection added
- 🧠 No adaptive security before → Risk-based captcha behavior added
- 🔑 Basic password checks before → Advanced password policy added
- ⏳ Limited cooldown system before → Sensitive security cooldowns added
- 🧩 Config system improved → Commented, ordered, auto-sync config system added
- 🖥️ Turkish console mode improved →
native/asciiseparation strengthened - 📚 README and documentation rewritten from scratch
📦 File
Recommended jar for this release:
aethelguard-0.3-sentinel.jar
⚠️ Notes
- Due to a temporary Minecraft-side shutdown issue, this version has passed compile/build checks, but final in-game testing is still recommended.
- Old config files are automatically migrated to the new structure, but backing up before updating is still a good idea.
- It is recommended to restart the server after changing critical settings such as database, captcha, 2FA, and recovery.
💬 Thanks
Thank you to everyone following, testing, and suggesting ideas for Aethelguard.
This release is a major step where Aethelguard starts moving beyond a “basic auth plugin” and toward a real security system. 🛡️✨
