The old Windows64 port had no real player identity — it used hardcoded
fake XUIDs, so anyone could impersonate anyone. This replaces that with
proper auth supporting Mojang, Ely.by, and offline accounts.
MCAuth library (new, MCAuth/):
Mojang auth via MSA device code flow (XBL, SISU, MC services),
Ely.by via Yggdrasil with 2FA, offline UUID generation matching
Java Edition (MD5 v3 from "OfflinePlayer:<name>"). Multi-account
manager with background token refresh, per-slot sessions, and
on-disk token persistence. Server-side session verification via
Mojang/Ely.by hasJoined API. Skin fetching and PNG validation
from texture servers.
Network protocol (version bumped to 80):
Three new packets (AuthScheme, AuthResponse, AuthResult) implement
a server-driven auth handshake before login completes. Player
identity migrated from 64-bit XUID to 128-bit GameUUID backed by
two uint64 fields (hi/lo). readPlayerUID/writePlayerUID now
serialize 16 bytes on the wire. Old and new clients cannot connect
to each other — version mismatch is rejected at PreLogin.
Save migration:
Map data mappings auto-migrate from old format: the old 64-bit
XUID is placed in hi, lo is set to 0 as a sentinel. On first
access by the real player, the sentinel entry is upgraded in-place
to the full 128-bit UUID. Format detection is by file size (2080,
2112, or 4160 bytes). Player .dat filenames inside saveData.ms
change from decimal XUID to dashed UUID — old saves need manual
entry renaming in the archive.
UI:
NativeUIRenderer: immediate-mode drawing system (quads, text,
9-slice panels, scrollbars, focus lists) for rendering auth
screens without Flash/Scaleform. UIScene_MSAuth handles device
code display, Ely.by credential input with 2FA, per-account
skin head preview, and multi-account add/remove/switch.
Server:
online-mode and auth-provider (mojang/elyby) in server.properties.
Whitelist and ban checks validate against the server-verified UUID.
Incompatible auth scheme logs which provider the server expects
vs what the client is using.
Also fixes a pre-existing exploit where any client could send a
DebugOptionsPacket to grant themselves CraftAnything and other debug
privileges on any server — now requires OP status server-side.
* Move to cmake
* Move sources to source_groups and ditch more old VS files
* Add BuildVer.h generation
* Break out cmake source lists to platforms
* Don't copy swf files
* Revert audio changes from merge
* Add platform defines
* Match MSBuild flags
* Move BuildVer.h to common include and fix rebuild issue
* Seperate projects properly
* Exclude more files and make sure GameHDD exists
* Missing line
* Remove remaining VS project files
* Update readme and actions
* Use incremental LTCG
* Update workflows
* Update build workflows and output folder
* Disable vcpkg checks
* Force MSVC
* Use precompiled headers
* Only use PCH for cpp
* Exclude compat_shims from PCH
* Handle per-platform source includes
* Copy only current platform media
* Define Iggy libs per platform
* Fix EnsureGameHDD check
* Only set WIN32_EXECUTABLE on Windows
* Correct Iggy libs path
* Remove include of terrain_MipmapLevel
* Correct path to xsb/xwb
* Implement copilot suggestions
* Add clang flags (untested)
* Fix robocopy error checking
* Update documentation
* Drop CMakePresets.json version as we dont use v6 features
* Always cleanup artifacts in nightly even if some builds fail
* Re-work compiler target options
* Move newer iggy dll into redist and cleanup
* Fix typos
* Remove 'Source Files' from all source groups
* Remove old ps1 build scripts