The old Windows64 port had no real player identity — it used hardcoded
fake XUIDs, so anyone could impersonate anyone. This replaces that with
proper auth supporting Mojang, Ely.by, and offline accounts.
MCAuth library (new, MCAuth/):
Mojang auth via MSA device code flow (XBL, SISU, MC services),
Ely.by via Yggdrasil with 2FA, offline UUID generation matching
Java Edition (MD5 v3 from "OfflinePlayer:<name>"). Multi-account
manager with background token refresh, per-slot sessions, and
on-disk token persistence. Server-side session verification via
Mojang/Ely.by hasJoined API. Skin fetching and PNG validation
from texture servers.
Network protocol (version bumped to 80):
Three new packets (AuthScheme, AuthResponse, AuthResult) implement
a server-driven auth handshake before login completes. Player
identity migrated from 64-bit XUID to 128-bit GameUUID backed by
two uint64 fields (hi/lo). readPlayerUID/writePlayerUID now
serialize 16 bytes on the wire. Old and new clients cannot connect
to each other — version mismatch is rejected at PreLogin.
Save migration:
Map data mappings auto-migrate from old format: the old 64-bit
XUID is placed in hi, lo is set to 0 as a sentinel. On first
access by the real player, the sentinel entry is upgraded in-place
to the full 128-bit UUID. Format detection is by file size (2080,
2112, or 4160 bytes). Player .dat filenames inside saveData.ms
change from decimal XUID to dashed UUID — old saves need manual
entry renaming in the archive.
UI:
NativeUIRenderer: immediate-mode drawing system (quads, text,
9-slice panels, scrollbars, focus lists) for rendering auth
screens without Flash/Scaleform. UIScene_MSAuth handles device
code display, Ely.by credential input with 2FA, per-account
skin head preview, and multi-account add/remove/switch.
Server:
online-mode and auth-provider (mojang/elyby) in server.properties.
Whitelist and ban checks validate against the server-verified UUID.
Incompatible auth scheme logs which provider the server expects
vs what the client is using.
Also fixes a pre-existing exploit where any client could send a
DebugOptionsPacket to grant themselves CraftAnything and other debug
privileges on any server — now requires OP status server-side.
* Fixed boats falling and a TP glitch #266
* Replaced every C-style cast with C++ ones
* Replaced every C-style cast with C++ ones
* Fixed boats falling and a TP glitch #266
* Updated NULL to nullptr and fixing some type issues
* Modernized and fixed a few bugs
- Replaced most instances of `NULL` with `nullptr`.
- Replaced most `shared_ptr(new ...)` with `make_shared`.
- Removed the `nullptr` macro as it was interfering with the actual nullptr keyword in some instances.
* Fixing more conflicts
* Replace int loops with size_t and start work on overrides
* Add safety checks and fix a issue with vector going OOR
This code was not tested and breaks in Release builds, reverting to restore
functionality of the nightly. All in-game menus do not work and generating
a world crashes.
This reverts commit a9be52c41a.
* Fixed boats falling and a TP glitch #266
* Replaced every C-style cast with C++ ones
* Replaced every C-style cast with C++ ones
* Fixed boats falling and a TP glitch #266
* Updated NULL to nullptr and fixing some type issues
* Modernized and fixed a few bugs
- Replaced most instances of `NULL` with `nullptr`.
- Replaced most `shared_ptr(new ...)` with `make_shared`.
- Removed the `nullptr` macro as it was interfering with the actual nullptr keyword in some instances.
* Fixing more conflicts
* Replace int loops with size_t and start work on overrides
* Multiplayer 8 to max byte increase.
Made-with: Cursor
* Server chunk optimizations for large player counts, server full notification fix, added to server.properties.