docs(auth): cite MultiLogin reference for UUID-keyed reclaim split

Anchor the username-collision reclaim's UUID-keyed, proxy-detected design to
the multi-Yggdrasil reference: CaaMoe/MultiLogin v6 binds identity as
serviceId+online-UUID via "identity cards" that decouple the in-game name from
online identity — keyed by UUID, never by name. Note that §B3's Mojang-priority
reclaim goes beyond the common "protect the first-bound name" behavior by
evicting a squatter once the genuine Mojang owner appears and stashing the
squatter's data for the code-only inherit path.
This commit is contained in:
flyemoji committed 2026-07-05 04:05:56 +09:00
1 parent ec468baef9
commit 154002edf3
1 file changed
+6
+6
View File
@@ -26,6 +26,12 @@ import (
// row cannot express) and are not represented here. The block is keyed by UUID,
// never by the contested name, so the genuine Mojang player — same username,
// different UUID — is never caught.
//
// This UUID-keyed, proxy-detected split matches the real multi-Yggdrasil reference
// (CaaMoe/MultiLogin binds identity in the plugin as serviceId+online-UUID, keyed by
// UUID, never by name). §B3's Mojang-priority reclaim goes beyond the common "protect
// the first-bound name" behavior: it evicts a squatter once the genuine Mojang owner
// appears and stashes the squatter's data for the code-only inherit path above.
const (
// reclaimHoldTTL is the 30-day window a reclaimed account's data is stashed for