mirror of
https://github.com/smartcmd/MinecraftConsoles.git
synced 2026-08-20 09:57:09 +00:00
The old Windows64 port had no real player identity — it used hardcoded fake XUIDs, so anyone could impersonate anyone. This replaces that with proper auth supporting Mojang, Ely.by, and offline accounts. MCAuth library (new, MCAuth/): Mojang auth via MSA device code flow (XBL, SISU, MC services), Ely.by via Yggdrasil with 2FA, offline UUID generation matching Java Edition (MD5 v3 from "OfflinePlayer:<name>"). Multi-account manager with background token refresh, per-slot sessions, and on-disk token persistence. Server-side session verification via Mojang/Ely.by hasJoined API. Skin fetching and PNG validation from texture servers. Network protocol (version bumped to 80): Three new packets (AuthScheme, AuthResponse, AuthResult) implement a server-driven auth handshake before login completes. Player identity migrated from 64-bit XUID to 128-bit GameUUID backed by two uint64 fields (hi/lo). readPlayerUID/writePlayerUID now serialize 16 bytes on the wire. Old and new clients cannot connect to each other — version mismatch is rejected at PreLogin. Save migration: Map data mappings auto-migrate from old format: the old 64-bit XUID is placed in hi, lo is set to 0 as a sentinel. On first access by the real player, the sentinel entry is upgraded in-place to the full 128-bit UUID. Format detection is by file size (2080, 2112, or 4160 bytes). Player .dat filenames inside saveData.ms change from decimal XUID to dashed UUID — old saves need manual entry renaming in the archive. UI: NativeUIRenderer: immediate-mode drawing system (quads, text, 9-slice panels, scrollbars, focus lists) for rendering auth screens without Flash/Scaleform. UIScene_MSAuth handles device code display, Ely.by credential input with 2FA, per-account skin head preview, and multi-account add/remove/switch. Server: online-mode and auth-provider (mojang/elyby) in server.properties. Whitelist and ban checks validate against the server-verified UUID. Incompatible auth scheme logs which provider the server expects vs what the client is using. Also fixes a pre-existing exploit where any client could send a DebugOptionsPacket to grant themselves CraftAnything and other debug privileges on any server — now requires OP status server-side.
59 lines
1.5 KiB
C++
59 lines
1.5 KiB
C++
#pragma once
|
|
#include <cstdint>
|
|
#include <string>
|
|
#include <istream>
|
|
#include <functional>
|
|
|
|
struct GameUUID {
|
|
uint64_t hi = 0;
|
|
uint64_t lo = 0;
|
|
|
|
bool isValid() const { return hi != 0 || lo != 0; }
|
|
|
|
// String conversion
|
|
std::string toDashed() const;
|
|
std::string toUndashed() const;
|
|
std::wstring toWDashed() const;
|
|
static GameUUID fromDashed(const std::string& s);
|
|
static GameUUID fromUndashed(const std::string& s);
|
|
|
|
// Generation
|
|
static GameUUID generateV4();
|
|
static GameUUID generateOffline(const std::string& playerName);
|
|
|
|
// Comparison
|
|
bool operator==(const GameUUID& o) const { return hi == o.hi && lo == o.lo; }
|
|
bool operator!=(const GameUUID& o) const { return !(*this == o); }
|
|
bool operator<(const GameUUID& o) const { return hi < o.hi || (hi == o.hi && lo < o.lo); }
|
|
|
|
// Hash support for unordered containers
|
|
struct Hash {
|
|
size_t operator()(const GameUUID& u) const {
|
|
size_t h = std::hash<uint64_t>{}(u.hi);
|
|
h ^= std::hash<uint64_t>{}(u.lo) + 0x9e3779b9 + (h << 6) + (h >> 2);
|
|
return h;
|
|
}
|
|
};
|
|
};
|
|
|
|
inline const GameUUID INVALID_UUID = {};
|
|
|
|
// Stream extraction for _fromString<PlayerUID> compatibility
|
|
inline std::wistream& operator>>(std::wistream& is, GameUUID& uuid)
|
|
{
|
|
std::wstring ws;
|
|
is >> ws;
|
|
std::string s(ws.begin(), ws.end());
|
|
uuid = GameUUID::fromDashed(s);
|
|
return is;
|
|
}
|
|
|
|
// Specialise std::hash so unordered_map<PlayerUID, ...> works without explicit Hash argument
|
|
namespace std {
|
|
template<> struct hash<GameUUID> {
|
|
size_t operator()(const GameUUID& u) const {
|
|
return GameUUID::Hash{}(u);
|
|
}
|
|
};
|
|
}
|