Unverified Commit 154002ed authored by Minseong Choi's avatar Minseong Choi 💬
Browse files

docs(auth): cite MultiLogin reference for UUID-keyed reclaim split

Anchor the username-collision reclaim's UUID-keyed, proxy-detected design to
the multi-Yggdrasil reference: CaaMoe/MultiLogin v6 binds identity as
serviceId+online-UUID via "identity cards" that decouple the in-game name from
online identity — keyed by UUID, never by name. Note that §B3's Mojang-priority
reclaim goes beyond the common "protect the first-bound name" behavior by
evicting a squatter once the genuine Mojang owner appears and stashing the
squatter's data for the code-only inherit path.
parent ec468bae
Loading
Loading
Loading
Loading
+6 −0
Changes for internal/api/handlers_player_reclaim.go: 6 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -26,6 +26,12 @@ import (
// row cannot express) and are not represented here. The block is keyed by UUID,
// never by the contested name, so the genuine Mojang player — same username,
// different UUID — is never caught.
//
// This UUID-keyed, proxy-detected split matches the real multi-Yggdrasil reference
// (CaaMoe/MultiLogin binds identity in the plugin as serviceId+online-UUID, keyed by
// UUID, never by name). §B3's Mojang-priority reclaim goes beyond the common "protect
// the first-bound name" behavior: it evicts a squatter once the genuine Mojang owner
// appears and stashes the squatter's data for the code-only inherit path above.

const (
	// reclaimHoldTTL is the 30-day window a reclaimed account's data is stashed for