
PureAuth
PureAuth is a bulletproof login system that secures servers using BCrypt encryption and intelligent IP sessions. The plugin offers modern MiniMessage gradients and professional administrative tools.
Оцените первым
562
5
Список изменений
PureAuth 6.1.0 - Secure PIN Login
PureAuth 6.1.0 adds a complete and configurable GUI-based PIN authentication system while preserving password, 2FA, recovery and existing PureAuth security behavior.
PIN authentication
- Added
/setpinfor authenticated players. - PINs are entered using an interactive GUI with player heads representing digits
0-9. - A new PIN must be entered twice before it is saved.
- The default PIN length is 6 digits and can be configured from 1 to 9 digits.
- PINs are stored only as BCrypt hashes.
- PIN length is stored per account so future configuration changes do not lock existing users out.
- Accounts with a PIN automatically receive the login GUI when joining.
/loginis blocked for PIN accounts.- Sessions and Premium Auto-Login cannot bypass PIN verification.
- Invalid PIN attempts use the existing attempt, kick, account-lock and Discord notification systems.
2FA and recovery
- PIN verification happens before 2FA when both methods are enabled.
- 2FA backup-code recovery remains available at the correct login stage.
- Account recovery can remove a forgotten PIN and restore password authentication.
- Recovery password changes and PIN removal are saved atomically.
PIN management
/changepassopens the PIN change GUI for PIN accounts.- Changing a PIN requires the current PIN and two matching entries of the new PIN.
/rempindisables PIN authentication and restores password login./rempinremains available when the PIN feature is globally disabled.
Login GUI security
- Closing the PIN GUI stops authentication.
- Configurable title, subtitle and chat instructions explain that the player must reconnect.
- Recovery instructions are displayed when recovery is enabled and configured for the account.
- Unnecessary commands, chat, movement, interaction and inventory actions stay blocked before authentication.
Administration
Added:
/pureauth setpin <player> <pin>/pureauth changepin <player> <pin>/pureauth rempin <player>/paalias for/pureauthpureauth.admin.pinpermission
Administrative PIN commands validate input, handle missing accounts and invalid states, redact plaintext PINs from logs and safely refresh online authentication state.
Configuration
Server owners can configure the feature toggle, PIN length, GUI title, materials, digit head textures, item names, lore, status indicators, controls, sounds and all Polish/English notifications.
Database and fixes
- Added automatic migration for
pin_enabled,pin_hashandpin_length. - Added null, missing-record and unavailable-database handling.
- Fixed PIN cache lifecycle and
/changepassmode selection. - Fixed GUI indicator overlap and centered the number pad.
- Improved shutdown ordering for async tasks and the database pool.
- Fixed account registration so a failed database insert cannot log the player in.
Compatibility
Available on Wiki.
Файлы
pureauth-velocity-6.1.0-R.jar(18.03 MiB)
ОсновнойМетаданные
Канал релиза
Release
Номер версии
6.1.0
Загрузчики
Velocity
Версии игры
26.2
Загрузок
5
Дата публикации
23.08.2026
