0.1.2-beta changes nothing the server relies on, so 0.1.1-beta clients
still connect, with a notice to update.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
- Every method except auth_challenge/auth_verify now requires a verified
session (auth::require) and answers "Not authenticated" otherwise.
Before, an unauthenticated connection could send emote_event
notifications to any connected player and probe who is online with
get_player.
- Rate-limit per connection the methods that fan out to other players:
emote (burst 5, +1/s) and send_player (burst 10, +1/s).
- Cap emote/send_player targets at 256 and de-duplicate them.
- Default SUPPORTED_VERSIONS to 0.1.1-beta.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Replace `auth` (which received the player's Minecraft access token) with
the vanilla online-mode flow, so the token never reaches this server:
- auth_challenge: validate the username and return a random one-time
server id
- the client calls Mojang's session `join` with its token and that id
- auth_verify: confirm the join with Mojang's `hasJoined` and log the
player in
Add GET /versions returning {"supported": [...], "deprecated": [...]}
from the SUPPORTED_VERSIONS / DEPRECATED_VERSIONS env vars (defaults:
0.1.0-beta3 supported), exposed in compose.yaml.
Refs saturnclientmc/saturnclient#7
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Picks up the fix that releases session handlers on close, so closed
connections no longer leak their Session and handler state.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
- Serve the session WebSocket on `/` through axum
(`Session::from_axum`) with a 1 MiB message limit
- Add `/health` (checks the database) and a `server healthcheck`
subcommand used by the Dockerfile HEALTHCHECK
- Shut down on SIGTERM/Ctrl+C so container stops are immediate
- Move per-connection handler registration into `register_handlers`
Co-Authored-By: Claude Opus 5.5 <[email protected]>
- Read bind address and database URL from BIND_ADDR / DATABASE_URL
(defaults unchanged for local cargo run)
- Rename DockerFile to Dockerfile and rewrite it: current Rust for
edition 2024, BuildKit cache mounts, non-root user, DB on /data
- Add compose.yaml publishing ${HOST_PORT:-8080} with a persistent
data volume, and a .dockerignore
Co-Authored-By: Claude Opus 5.5 <[email protected]>