Home›Java›Mods›EmpireAuth
EmpireAuth


[​IMG] [​IMG] [​IMG] [​IMG]

[​IMG] [​IMG] [​IMG]

[​IMG] [​IMG] [​IMG]

​

EmpireAuth

A registration and login system for a network running in offline mode. One jar holds both halves: drop it into the proxy and into every backend server.

How the two halves talk

The proxy owns the accounts and the database. The backend servers only need to know whether a player is allowed to act yet, and they learn that over a plugin messaging channel.

That channel is the part most login plugins get wrong. A Bukkit server hands a plugin any payload a client sends on a registered channel, so if the message is not authenticated, a modified client can send the plugin's own "authentication succeeded" message and unlock its own account. In EmpireAuth every message carries an HMAC-SHA256 signature over a shared secret, a timestamp and a nonce. A forged, stale or replayed message is dropped. Neither half starts until security.shared-secret is set on both sides, so there is no insecure default to forget about.

Passwords

PBKDF2-HMAC-SHA512, 210000 rounds by default and never fewer than 100000. Comparison is constant time. Raising the round count later re-hashes each password by itself the next time its owner logs in.

Length limits, a character class policy and a blacklist of common passwords are all configurable.

Brute force protection

An account locks after a configurable number of failed attempts A separate rate limit per IP address, so one address cannot work through a list of names * An optional login timeout that disconnects a player who never authenticates

Restrictions before login

Configurable per item: blindness, slowness, a freeze on the joining block, no building, no interaction, no inventory, no damage in either direction, and no chat. The default when a message cannot be read is always the restricted state, never the free one.

Commands

On the proxy: /login, /register, /logout, /resetpassword, plus the administrative /empireauth subcommands. Which commands an unauthenticated player may still run is a configuration list, matched exactly rather than by prefix.

On the backend: /authstatus shows how many players on that server are currently restricted.

Install both halves or neither

The backend component restricts every player until the proxy tells it otherwise, and it does not exempt operators. On a server with no proxy in front of it, nobody can chat or run a command, /login included, because /login lives on the proxy. That is the safe direction to fail in, but it means the backend jar alone is not useful. Without a shared secret it refuses to activate at all and logs why.

Storage

SQLite by default, MySQL through a configuration change. Connections are pooled with HikariCP.

Before you install

Generate a secret and put the same value in the proxy and every backend configuration:

Code (Text):

head -c 32 /dev/urandom | base64
 

Commands

Plugin details

Read from the plugin's own plugin.yml.

Quick facts

Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.

EmpireAuth is a free Minecraft Java mod. Compatible with Minecraft 1.21, 26.1, 26.2, 26.3. Downloaded 4 times (via Spigot). Download it and open it directly in the game.

Explore more