fix(api): relay Mojang logins when no auth source is configured

felis api wired the hasJoined multiplexer only when felis.toml had at
least one [[auth_source]]. With none, the source list stayed nil and
every hasJoined answer was a 204. That was harmless while nothing
pointed at the route, but the installer now starts Velocity with
-Dmojang.sessionserver aimed at felis-api unconditionally, and the
generated felis.toml tells the operator to delete the LittleSkin block
for a Mojang-only server. Doing exactly that turned every login away,
premium accounts included, and felis-api logged nothing about it.

Always build the list through authSourcesFromConfig, which prepends
Mojang in code, so an empty config is a Mojang-only relay. felis nano
already behaves this way with the same file.

The new test pins authSourcesFromConfig itself: Mojang first, the only
Identity source, and still present when nothing is configured. Marking
a configured source Identity makes it fail. The call site in cmdAPI is
now a single unconditional assignment and has no unit test of its own.
This commit is contained in:
flyemoji committed 2026-09-22 12:46:00 +09:00
1 parent 800a9042a1
commit 8fe255e38f
3 files changed
+50 -12

No files matched your search

+3 -3
View File
@@ -139,9 +139,9 @@ type API struct {
// AuthSources is the Felis-nano multi-source hasJoined multiplexer's upstream
// Yggdrasil list, in priority order (config order; the Mojang Identity source
// first for 正版优先). Nil — the default — makes the session verifier reject every
// login (204), so the endpoint ships inert until cmd/felis wires configured
// sources. Consumed by handleHasJoined (handlers_hasjoined.go).
// first for 正版优先). Nil makes the session verifier reject every login (204);
// cmd/felis always wires at least the Mojang source through authSourcesFromConfig.
// Consumed by handleHasJoined (handlers_hasjoined.go).
AuthSources []AuthSource
// Now is the clock, injectable for tests. Defaults to time.Now.