From b323975ddb590e5c4f5593308eff70eb500f10fb Mon Sep 17 00:00:00 2001 From: Minseong Choi Date: Mon, 13 Jul 2026 11:05:45 +0900 Subject: [PATCH] fix(nano): -Dmojang.sessionserver takes the full hasJoined URL, not the base d417efc got this backwards, in both the code comment and the installer summary. It claimed authlib appends /session/minecraft/hasJoined itself, so the property should be given the base URL only. Velocity does not work that way, and a real login says so: pointed at http://127.0.0.1:8081, a Mojang login arrives at nano as GET /?username=FLYEMOJ1&serverId=-23ae0b50... with no path at all. Velocity appends the query string to the property verbatim and issues the request itself; authlib is not in the loop. nano has no route on /, so it answers 404 and Velocity kicks the player with authservers_down. Velocity's own default for the property is the full URL, https://sessionserver.mojang.com/session/minecraft/hasJoined, which is the same thing said another way. With the full endpoint URL the same account logs straight in, so both the nano.go header and summary_nano now print -Dmojang.sessionserver=http://127.0.0.1:8081/session/minecraft/hasJoined and note that the flag belongs between `java` and `-jar`. Verified against Velocity 3.5.1 + Paper 26.2 on the deploy host: a Mojang login reaches the backend with its real Mojang UUID unchanged, and a LittleSkin login under the same username reaches it as UUIDv3(felisAuthNS, "littleskin:"+id) -- two different players on the backend, which is the point. --- cmd/felis/nano.go | 11 ++++++----- deploy/bootstrap.sh | 7 ++++--- 2 files changed, 10 insertions(+), 8 deletions(-) diff --git a/cmd/felis/nano.go b/cmd/felis/nano.go index 12d818e..c01c3c5 100644 --- a/cmd/felis/nano.go +++ b/cmd/felis/nano.go @@ -5,11 +5,12 @@ package main // full Felis control plane (no k3s, no Postgres, no DB). It reads [[auth_source]] from // felis.toml, leads with Mojang as the code-owned identity anchor (正版优先), and serves the // vanilla sessionserver hasJoined endpoint. Point Velocity at it with -// -Dmojang.sessionserver=http://127.0.0.1:8081 -// — the base URL only: authlib appends /session/minecraft/hasJoined itself. Then it -// verifies logins against Mojang plus every configured third-party source. Serving a -// proxy on another host means binding off-loopback with -listen; see the flag below for -// why that is an explicit opt-in and not the default. +// -Dmojang.sessionserver=http://127.0.0.1:8081/session/minecraft/hasJoined +// — Velocity's property takes the FULL endpoint URL, path included (its default is the +// full https://sessionserver.mojang.com/session/minecraft/hasJoined), and Velocity issues +// that request itself rather than through authlib. Then it verifies logins against Mojang +// plus every configured third-party source. Serving a proxy on another host means binding +// off-loopback with -listen; see the flag below for why that is an explicit opt-in. // // This is the no-database delivery of the identical brain `felis api` mounts through its // route table (internal/api.HasJoinedHandler). `felis setup --nano` / the bootstrap nano diff --git a/deploy/bootstrap.sh b/deploy/bootstrap.sh index 21e13b3..5af6d56 100644 --- a/deploy/bootstrap.sh +++ b/deploy/bootstrap.sh @@ -1247,9 +1247,10 @@ summary_nano() { systemctl --no-pager --full status felis-nano 2>/dev/null | head -n 6 || true echo log "hasJoined endpoint: http://${host}:${port}/session/minecraft/hasJoined" - log "Point Velocity at it — add to the proxy JVM startup flags:" - log " -Dmojang.sessionserver=http://${host}:${port}" - log " (base URL only — authlib appends the path itself)" + log "Point Velocity at it — add to the proxy JVM startup flags (between java and -jar):" + log " -Dmojang.sessionserver=http://${host}:${port}/session/minecraft/hasJoined" + log " (the FULL endpoint URL, path included — Velocity's default for this property is" + log " the full https://sessionserver.mojang.com/session/minecraft/hasJoined)" if nano_listen_is_loopback; then log "Bound to loopback: reachable from Velocity on THIS host, and from nowhere else." log "Proxy on another machine? Re-run with FELIS_NANO_LISTEN=:${port} and"