Replace `auth` (which received the player's Minecraft access token) with
the vanilla online-mode flow, so the token never reaches this server:
- auth_challenge: validate the username and return a random one-time
server id
- the client calls Mojang's session `join` with its token and that id
- auth_verify: confirm the join with Mojang's `hasJoined` and log the
player in
Add GET /versions returning {"supported": [...], "deprecated": [...]}
from the SUPPORTED_VERSIONS / DEPRECATED_VERSIONS env vars (defaults:
0.1.0-beta3 supported), exposed in compose.yaml.
Refs saturnclientmc/saturnclient#7
Co-Authored-By: Claude Opus 5.5 <[email protected]>
19 lines
578 B
TOML
19 lines
578 B
TOML
[package]
|
|
name = "server"
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
|
|
[dependencies]
|
|
axum = { version = "0.8.9", features = ["ws"] }
|
|
rand = "0.9"
|
|
reqwest = { version = "0.13.2", features = ["json", "query"] }
|
|
serde = { version = "1.0.228", features = ["serde_derive"] }
|
|
serde_json = "1.0.149"
|
|
session-rs = { version = "0.2.1", default-features = false, features = ["axum"] }
|
|
sqlx = { version = "0.8.6", features = [
|
|
"sqlite",
|
|
"runtime-tokio-native-tls",
|
|
"macros",
|
|
] }
|
|
tokio = { version = "1.49.0", features = ["macros", "rt-multi-thread", "net", "signal", "sync", "time"] }
|