Loading
Sign in before continuing.
fix(nano): stop trusting an expired free name while mojang is failing
When the premium-name lookup failed, isPremiumName fell back to any cached answer, however old. An expired "free" is exactly the answer that may have stopped being true: someone can buy the name after it was last seen free. For as long as api.mojang.com kept failing (429, 5xx, a timeout), a third-party player holding that name kept it on every reconnect, and the Velocity registry, keyed on the name, turned its new owner away as already connected. A hostile source could drive the host into Mojang's rate limit on purpose to hold names that way. A failed lookup now always counts as taken, so the player is renamed with the source's prefix. An expired "taken" already gave that answer, so only the stale "free" case changes. The cost is cosmetic: during an outage an ordinary third-party player may get a prefix they do not need, and their data follows the UUID, not the name. A new test gives the cache a free entry past its TTL and has Mojang answer 429. It fails on the old fallback. The two comments that described the fallback now describe the fail-closed rule.