From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Modrinth Enhanced Date: Thu, 17 Sep 2026 15:21:24 +0200 Subject: [PATCH] Sign in to custom servers in the browser Sending a password to the auth server leaves no room for two-factor authentication, and players who signed up with another service have no password at all. Yggdrasil Connect is the answer LittleSkin and Blessing Skin with Janus give: OAuth's device flow on the server's own page. A server that offers it, per the `feature.openid_configuration_url` in its metadata, gets "Sign in in the browser" above the password fields. The page opens in the player's browser with the code filled in, the launcher asks the server as often as it allows whether the player is done, and the account is added with the player picked on that page. Its access token is renewed with the refresh token when it runs out. Using it takes a client id: the one the server shares, or one this launcher has registered with that server. LittleSkin shares none, and no app is registered there yet, so the table of them is empty and such a server keeps the password form alone. A Connect account is a row in `minecraft_users` like the others, its session in the refresh token column as JSON behind a marker. --- .../src/components/ui/AuthlibAccountModal.vue | 179 +++++++- apps/app-frontend/src/helpers/auth.js | 23 +- apps/app/build.rs | 2 + apps/app/src/api/auth.rs | 49 +++ packages/app-lib/src/api/minecraft_auth.rs | 47 +- packages/app-lib/src/state/minecraft_auth.rs | 402 +++++++++++++++++- packages/app-lib/src/util/authlib_injector.rs | 94 ++++ 7 files changed, 782 insertions(+), 14 deletions(-) diff --git a/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue b/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue index 4aab3f9..b67b2c7 100644 --- a/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue +++ b/apps/app-frontend/src/components/ui/AuthlibAccountModal.vue @@ -1,5 +1,11 @@