
Wawel Auth
Authentication mod for Minecraft 1.7.10.
- Загрузки
- 362
- Подписчики
- 3
- Обновлён
- 12 августа 2026 г.
- Лицензия
- LGPL-3.0-only
Опубликован 4 мая 2026 г.
Wawel Auth

Authentication mod for Minecraft 1.7.10.
Server: Allow players from Microsoft, Ely.by, LittleSkin, and more, including the option to host your own integrated auth server.
Client: Login into and manage accounts for various auth providers and servers. Also includes cosmetic features like modern skin support, or 3D skin layers.
This mod also adds some other features, like an admin web panel, and animated capes (only for Wawel Auth accounts). For a complete list of features, and usage instructions, consult the wiki.
Wawel Auth can be installed on the server, client, or both, but the last combination is recommended for an optimal experience. By default, the client saves configuration to a shared folder, no need to login again to all your accounts when switching Minecraft instances. This can be disabled.

Dependencies
- UniMixins

- FentLib

- ModularUI2
(Client only)
[!NOTE] The regular and Maven
devjars bundlesqlite-jdbcandorg.bouncycastleso they work in offline and downstream development environments. Lightweightslimandslim-devjars using embedded DepLoader are also provided.
[!NOTE]
wawelauth-curseforgereleases do not have the ability to import launcher sessions.
Building
./gradlew build
Credits
- Skin layer implementation inspired by the last MIT commit of 3D Skin Layers Mod
- Catalogue-Vintage for folder icon and system-open inspiration
- GT:NH buildscript
- Background image
License
LGPLv3
Buy me some creatine
- ko-fi.com
- Monero:
893tQ56jWt7czBsqAGPq8J5BDnYVCg2tvKpvwTcMY1LS79iDabopdxoUzNLEZtRTH4ewAcKLJ4DM4V41fvrJGHgeKArxwmJ

Ченджлог
1.0.5Релиз1.7.10 · 12 августа 2026 г.
- Added configurable vanilla-style panorama shading to the account manager
- CurseForge builds omit automatic account migration
- Added Android compatibility for SQLite storage and clear handling of unsupported skin/cape file selection
1.0.4Релиз1.7.10 · 14 июля 2026 г.
- Removed ability to configure Implementation Name
- Route all profile texture lookups through WawelAuth
- Moved LOTR map player face patch to FentLib
- Moved Better Questing skin patch to FentLib
- Provider-aware ban/pardon commands
- Provider-aware ServerUtilities player command targets
- Centralized provider-aware command name resolution
- Provider-aware ServerUtilities team player persistence
- UUID-backed ServerUtilities team GUI player actions
- Provider-aware Better Questing party skin sync, invites, commands
- Provider-aware ServerUtilities tab player head skin lookup
- Offloaded HTTP route handlers from Netty event loops to a bounded worker pool. Limits DOS attacks, hammering expensive routes no longer impacts the game.
- Fixed in-game account manager keybind not being registered on the correct bus. Fixed in-game manager npe. Fixed in-game drag and drop not re-opening the manager screen.
- Avoid HTTP self-calls for local auth and avatars
- Other session tokens get invalidated on local account password change
- Admin panel settings saves no longer leak runtime state (auto-added skin domain, fallback server list with discovered keys) into server.json
- Run dummy PBKDF2 for non-existent users to prevent username brute-forcing
- Prompt server admin via fml confirm/cancel for cert regeneration if publicBaseUrl changes
- Launcher session import prompt
- All local auth providers can be toggled on and off in the main manager
- Ingame manager shows local auth (if advertised by current server) as first entry
- Added button next to select account entries to jump to corresponding provider in the manager
- Added client-side authlib-injector compat: skins load properly, and account import works (as long as the provider exists)
- Moved
config/wawelauth.cfgtoconfig/wawelauth/wawelauth.cfg. Migration is automatic - Fixed left leg/arm texture face swap on 64x64 skins
- Sodium-GUIfied interface + many ergdeonomic upgrades
- Moved editable built-in provider JSON definitions to the shared client config by default
1.0.3Релиз1.7.10 · 6 июня 2026 г.
- Fixed escape key not working in some mui2 guis
1.0.2Релиз1.7.10 · 31 мая 2026 г.
- Fixed @Redirect mixin clash with TabFaces
- Added
nodepjars to each release. They do not bundle sqlite or Bouncy Castle, and require FalsePatternLib to download them
1.0.1Релиз1.7.10 · 25 мая 2026 г.
- Hardened fallback texture proxy redirects so they can't reach localhost or private network targets
- Fixed trusted nginx client IP handling for join/hasJoined without trusting spoofed forwarded headers from public clients
- Added app-level rate limiting for admin login and Yggdrasil auth endpoints
- Removed admin session cookie auth and tightened HTTPS detection behind local proxies
- Bounded public fallback profile and texture proxy caches so high-cardinality requests can't grow memory forever
- Hardened animated GIF cape validation without breaking optimized GIF subframes
- Added same-port HTTPS for admin login when you do not have a separate reverse proxy port
- Exposed same-port HTTPS settings in the admin panel with bounded TLS handshake timeout
- Hardened texture resolving and caching to avoid stale skin/cape state and race-condition bugs
- Reused FentLib's shared player face renderer for client account heads
- Replaced automatic orphaned local provider cleanup with an opt-in prompt on server delete to avoid wiping providers shared across Minecraft instances
- Improved local Wawel Auth credential detection and added configurable credential hiding for unsupported providers
- Improved the public site and admin panel
- Added 67minecraft publishing and filled in Modrinth/CurseForge metadata
- Moved server.dat backups to config/wawelauth/backups
- Force player skull rendering to go through Wawel Auth instead of Et Futurum, when installed
1.0.0Релиз1.7.10 · 4 мая 2026 г.
Initial Release.
Комментарии
Загружаем…






