Authenticate through Mojang's session server; add version manifest

Replace `auth` (which received the player's Minecraft access token) with
the vanilla online-mode flow, so the token never reaches this server:

- auth_challenge: validate the username and return a random one-time
  server id
- the client calls Mojang's session `join` with its token and that id
- auth_verify: confirm the join with Mojang's `hasJoined` and log the
  player in

Add GET /versions returning {"supported": [...], "deprecated": [...]}
from the SUPPORTED_VERSIONS / DEPRECATED_VERSIONS env vars (defaults:
0.1.0-beta3 supported), exposed in compose.yaml.

Refs saturnclientmc/saturnclient#7

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-09-25 15:22:18 +02:00
co-authored by claude
parent 222567b735
commit c9abf5df77
6 changed files with 150 additions and 33 deletions
+4
View File
@@ -6,6 +6,10 @@ services:
# Coolify's proxy; set the domain in Coolify as https://<domain>:8080.
ports:
- "${HOST_PORT:-8080}:8080"
environment:
# Comma-separated client versions served at GET /versions.
SUPPORTED_VERSIONS: ${SUPPORTED_VERSIONS:-0.1.0-beta3}
DEPRECATED_VERSIONS: ${DEPRECATED_VERSIONS:-}
volumes:
- server-data:/data