+6
−5
+4
−3
Loading
d417efc8 got this backwards, in both the code comment and the installer summary. It claimed authlib appends /session/minecraft/hasJoined itself, so the property should be given the base URL only. Velocity does not work that way, and a real login says so: pointed at http://127.0.0.1:8081, a Mojang login arrives at nano as GET /?username=FLYEMOJ1&serverId=-23ae0b50... with no path at all. Velocity appends the query string to the property verbatim and issues the request itself; authlib is not in the loop. nano has no route on /, so it answers 404 and Velocity kicks the player with authservers_down. Velocity's own default for the property is the full URL, https://sessionserver.mojang.com/session/minecraft/hasJoined, which is the same thing said another way. With the full endpoint URL the same account logs straight in, so both the nano.go header and summary_nano now print -Dmojang.sessionserver=http://127.0.0.1:8081/session/minecraft/hasJoined and note that the flag belongs between `java` and `-jar`. Verified against Velocity 3.5.1 + Paper 26.2 on the deploy host: a Mojang login reaches the backend with its real Mojang UUID unchanged, and a LittleSkin login under the same username reaches it as UUIDv3(felisAuthNS, "littleskin:"+id) -- two different players on the backend, which is the point.