From 154002edf3958dd110513c4d9d5d16f4a1b4fd8f Mon Sep 17 00:00:00 2001 From: Minseong Choi Date: Sun, 5 Jul 2026 04:05:45 +0900 Subject: [PATCH] docs(auth): cite MultiLogin reference for UUID-keyed reclaim split MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Anchor the username-collision reclaim's UUID-keyed, proxy-detected design to the multi-Yggdrasil reference: CaaMoe/MultiLogin v6 binds identity as serviceId+online-UUID via "identity cards" that decouple the in-game name from online identity — keyed by UUID, never by name. Note that §B3's Mojang-priority reclaim goes beyond the common "protect the first-bound name" behavior by evicting a squatter once the genuine Mojang owner appears and stashing the squatter's data for the code-only inherit path. --- internal/api/handlers_player_reclaim.go | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/internal/api/handlers_player_reclaim.go b/internal/api/handlers_player_reclaim.go index 99bd3e9..29216db 100644 --- a/internal/api/handlers_player_reclaim.go +++ b/internal/api/handlers_player_reclaim.go @@ -26,6 +26,12 @@ import ( // row cannot express) and are not represented here. The block is keyed by UUID, // never by the contested name, so the genuine Mojang player — same username, // different UUID — is never caught. +// +// This UUID-keyed, proxy-detected split matches the real multi-Yggdrasil reference +// (CaaMoe/MultiLogin binds identity in the plugin as serviceId+online-UUID, keyed by +// UUID, never by name). §B3's Mojang-priority reclaim goes beyond the common "protect +// the first-bound name" behavior: it evicts a squatter once the genuine Mojang owner +// appears and stashes the squatter's data for the code-only inherit path above. const ( // reclaimHoldTTL is the 30-day window a reclaimed account's data is stashed for