From 9c87e603a9396348b51565b32414ba3de1425e5d Mon Sep 17 00:00:00 2001 From: Felitendo Date: Thu, 17 Sep 2026 16:14:11 +0200 Subject: [PATCH] feat: sign in to custom servers in the browser --- README.md | 9 +- ...-in-to-custom-servers-in-the-browser.patch | 1069 +++++++++++++++++ scripts/check.sh | 2 + 3 files changed, 1079 insertions(+), 1 deletion(-) create mode 100644 patches/0022-Sign-in-to-custom-servers-in-the-browser.patch diff --git a/README.md b/README.md index 5f0621c..71ab169 100644 --- a/README.md +++ b/README.md @@ -34,6 +34,7 @@ works. | `0019-Add-accounts-from-other-...` | Sign in to Drasl, Blessing Skin and other account servers, as with Ely.by. | | `0020-Keep-the-settings-tabs-clear-of-...` | The settings tab list scrolls instead of running over the app version on Linux. | | `0021-Show-and-change-skins-of-custom-...` | A custom server account's skin is shown and changed on the skin page, and its head in the account list. | +| `0022-Sign-in-to-custom-servers-in-...` | Servers with Yggdrasil Connect, such as LittleSkin, sign in on their own page, with two-factor authentication. | ### Offline accounts @@ -86,7 +87,13 @@ header. The dialog then shows the server's name and a link to sign up there. An players asks which one to play as. On Drasl, a player who signed up through another service uses the Minecraft token from their -account page as the password; the dialog says so. +account page as the password; the dialog says so. Servers with +[Yggdrasil Connect](https://github.com/yushijinhun/authlib-injector/issues/268), such as LittleSkin or +Blessing Skin with Janus, also offer "Sign in in the browser": the server's own page opens with the +code filled in, two-factor authentication included, and the launcher picks the account up once it is +done. That takes a client id, which the server either shares or has registered for this launcher; +the registered ones are listed in `CONNECT_CLIENT_IDS` in +`0022-Sign-in-to-custom-servers-in-the-browser.patch`, and there are none yet. The account list shows which server an account is on, with the head of the skin worn there. The skin page shows that skin, and picking or adding one uploads it to the server through diff --git a/patches/0022-Sign-in-to-custom-servers-in-the-browser.patch b/patches/0022-Sign-in-to-custom-servers-in-the-browser.patch new file mode 100644 index 0000000..727ea32 --- /dev/null +++ b/patches/0022-Sign-in-to-custom-servers-in-the-browser.patch @@ -0,0 +1,1069 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Modrinth Enhanced +Date: Thu, 17 Sep 2026 15:21:24 +0200 +Subject: [PATCH] Sign in to custom servers in the browser + +Sending a password to the auth server leaves no room for two-factor +authentication, and players who signed up with another service have no +password at all. Yggdrasil Connect is the answer LittleSkin and Blessing +Skin with Janus give: OAuth's device flow on the server's own page. + +A server that offers it, per the `feature.openid_configuration_url` in +its metadata, gets "Sign in in the browser" above the password fields. +The page opens in the player's browser with the code filled in, the +launcher asks the server as often as it allows whether the player is +done, and the account is added with the player picked on that page. Its +access token is renewed with the refresh token when it runs out. + +Using it takes a client id: the one the server shares, or one this +launcher has registered with that server. LittleSkin shares none, and +no app is registered there yet, so the table of them is empty and such +a server keeps the password form alone. + +A Connect account is a row in `minecraft_users` like the others, its +session in the refresh token column as JSON behind a marker. +--- + .../src/components/ui/AuthlibAccountModal.vue | 179 +++++++- + apps/app-frontend/src/helpers/auth.js | 23 +- + apps/app/build.rs | 2 + + apps/app/src/api/auth.rs | 49 +++ + packages/app-lib/src/api/minecraft_auth.rs | 47 +- + packages/app-lib/src/state/minecraft_auth.rs | 402 +++++++++++++++++- + packages/app-lib/src/util/authlib_injector.rs | 94 ++++ + 7 files changed, 782 insertions(+), 14 deletions(-) + +diff --git a/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue b/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue +index 4aab3f9..b67b2c7 100644 +--- a/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue ++++ b/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue +@@ -1,5 +1,11 @@ +