5 Commits
Author SHA1 Message Date
selimaj-devandclaude b72279a7fd Support 0.1.3-beta and deprecate 0.1.2-beta by default
Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-28 23:02:35 +02:00
selimaj-devandclaude a5a937694d Support 0.1.2-beta and deprecate 0.1.1-beta by default
0.1.2-beta changes nothing the server relies on, so 0.1.1-beta clients
still connect, with a notice to update.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-27 19:18:55 +02:00
selimaj-devandclaude 56f511d5f6 Require authentication for RPCs and rate-limit fan-out methods
- Every method except auth_challenge/auth_verify now requires a verified
  session (auth::require) and answers "Not authenticated" otherwise.
  Before, an unauthenticated connection could send emote_event
  notifications to any connected player and probe who is online with
  get_player.
- Rate-limit per connection the methods that fan out to other players:
  emote (burst 5, +1/s) and send_player (burst 10, +1/s).
- Cap emote/send_player targets at 256 and de-duplicate them.
- Default SUPPORTED_VERSIONS to 0.1.1-beta.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-25 19:56:44 +02:00
selimaj-devandclaude c9abf5df77 Authenticate through Mojang's session server; add version manifest
Replace `auth` (which received the player's Minecraft access token) with
the vanilla online-mode flow, so the token never reaches this server:

- auth_challenge: validate the username and return a random one-time
  server id
- the client calls Mojang's session `join` with its token and that id
- auth_verify: confirm the join with Mojang's `hasJoined` and log the
  player in

Add GET /versions returning {"supported": [...], "deprecated": [...]}
from the SUPPORTED_VERSIONS / DEPRECATED_VERSIONS env vars (defaults:
0.1.0-beta3 supported), exposed in compose.yaml.

Refs saturnclientmc/saturnclient#7

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-25 15:22:18 +02:00
selimaj-devandclaude 2ea0a1228f Make server deployable with Docker Compose on Coolify
- Read bind address and database URL from BIND_ADDR / DATABASE_URL
  (defaults unchanged for local cargo run)
- Rename DockerFile to Dockerfile and rewrite it: current Rust for
  edition 2024, BuildKit cache mounts, non-root user, DB on /data
- Add compose.yaml publishing ${HOST_PORT:-8080} with a persistent
  data volume, and a .dockerignore

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-25 05:00:32 +02:00