Skip to content

fix(auth): reject premium login when stored Mojang UUID differs - #61

Open
Pawelusze wants to merge 1 commit into
Navio1430:mainfrom
Pawelusze:fix/premium-username-uuid-mismatch
Open

Pawelusze wants to merge 1 commit into
Navio1430:mainfrom
Pawelusze:fix/premium-username-uuid-mismatch

Conversation

@Pawelusze

Copy link
Copy Markdown

Problem

On login of an existing premium user, NavAuth matches the account by username only. In UsernameResolutionService the branch for an existing premium user (existingUserIgnoreCase != null && isPremium) never compares the stored mojangUuid with the Mojang verified UUID. After a username is released and reclaimed by a different premium account (Mojang frees a released name after about 37 days), the new owner logs into the previous user's stored account: same UUID, no password, and any permissions bound to that UUID (for example operator).

Fix

In that branch, when the name is premium and the stored mojangUuid differs from the Mojang verified profile UUID, deny the login with a dedicated reason and message instead of returning success.

Verified

Reproduced end to end on Velocity plus Paper. Before the fix, a premium account with a different Mojang UUID received the stored victim UUID with no password and could run operator commands. After the fix the same login is rejected at PreLogin and never reaches the backend. The UUID mismatch state was seeded directly in the database, since the name release itself is Mojang policy and not part of the plugin.

An existing premium user was matched by username only. After a username was released and reclaimed by another premium account, the new owner logged into the previous user's identity and inherited its permissions. Compare the stored mojangUuid with the Mojang-verified profile and deny the login on mismatch.
@Navio1430 Navio1430 added the bug Something isn't working label Sep 15, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants