
AuthSecured
Password authentication for Paper, Purpur and Fabric Minecraft servers
Оцените первым
155
1
Список изменений
AuthSecured 1.2.2 Security Update
Security fixes
- A private AUTHSECURED_IP_SECRET is now required. Servers without it keep authentication blocked until it is configured.
- Unknown player IP addresses no longer share one rate-limit identity or create IP-bound reconnect sessions.
- Malformed Argon2id hashes cannot request excessive memory or work factors.
- SQLite foreign keys now enforce session deletion when an account is removed.
- Optional Redis fallback is visible in /authadmin doctor. Set redis.required: true to stop authentication when shared Redis is unavailable.
- Discord alerts accept official HTTPS webhook endpoints only.
Reliability and maintenance
- Expired sessions and old audit entries are cleaned periodically outside the server thread.
- Configure logging.audit.retention-days and logging.audit.cleanup-interval-seconds in config.yml.
- SQLite now records its schema version and safely upgrades existing databases.
- Internal errors produce useful, privacy-safe diagnostics.
Packaging
- Updated dependencies after a vulnerability scan.
- Reduced shaded JAR size and isolated bundled JSON libraries.
- Paper and Fabric remain separate downloads; each Fabric file targets one exact Minecraft version.
Performance
- High-frequency events (movement, interactions, commands) now use cached configuration values, significantly reducing string parsing and lookup overhead.
Bug Fixes & Stability
- Intercepted password-bearing commands are now executed directly to prevent double-logging and reliably bypass other command-logging plugins.
- Added graceful degradation if the sensitive command log filter fails to install: the server securely blocks new logins and kicks players instead of erroring on startup.
- Asynchronous player kicks and messages are now properly scheduled to run on the main server thread.
Compatibility & Quality of Life
- Upgraded internal player messaging and kicks to use the modern Adventure Component API for broader Paper compatibility.
- Added explicit folia-supported: false to plugin.yml.
- Added a security reminder for administrators to clear their chat history (F3 + D) after generating a temporary password via /authadmin resetpassword.
Файлы
authsecured-paper-1.2.2.jar(18.47 MiB)
ОсновнойМетаданные
Канал релиза
Release
Номер версии
1.2.2
Загрузчики
PaperPurpur
Версии игры
1.21–26.2
Загрузок
2
Дата публикации
16.09.2026
