The hasJoined contract listed only 200 and 204 and named authlib as the caller. The handler now answers four more ways, and a proxy operator reading the contract could not tell a refused login from a down source. - 204 also covers a missing or oversized parameter (no source is asked), a third-party name that is not a legal Minecraft username, and an identity id that does not parse. - 400 for a request that declares a body. There is no response body, and the connection is closed. - 500 when the bar-list lookup fails, with the usual error body. - 503 when no source validated and at least one failed, since that source's player may be the one logging in. The three query parameters now carry the 64-byte cap. The profile name says a third-party player holding a registered Mojang name gets it back prefixed and cut to 16 characters. The description names Velocity, drops the "thin login hook" that does not exist, and says that a non-200, non-204 answer makes Velocity report the auth servers as down.
172 KiB
172 KiB