Login+
作者:rebot | 分类:模组
Minecraft 版本: 1.8 1.8.1 1.8.2 1.8.3 1.8.4 1.8.5 1.8.6 1.8.7 1.8.8 1.8.9 1.9 1.9.1 1.9.2 1.9.3 1.9.4 1.10 1.10.1 1.10.2 1.11 1.11.1 1.11.2 1.12 1.12.1 1.12.2 1.13 1.13.1 1.13.2 1.14 1.14.1 1.14.2 1.14.3 1.14.4 1.15 1.15.1 1.15.2 1.16 1.16.1 1.16.2 1.16.3 1.16.4 1.16.5 1.17 1.17.1 1.18 1.18.1 1.18.2 1.19 1.19.1 1.19.2 1.19.3 1.19.4 1.20 1.20.1 1.20.2 1.20.3 1.20.4 1.20.5 1.20.6 1.21 1.21.1 1.21.2 1.21.3 1.21.4 1.21.5 1.21.6 1.21.7 1.21.8 1.21.9 1.21.10 1.21.11 26.1 26.1.1 26.1.2 26.2
平台: bukkit paper purpur spigot
标签: game-mechanics management utility
? Login+
Register once, stay protected forever. Login+ is a modern authentication plugin for offline-mode servers — passwords, sessions, free 2FA and full account protection in one jar for Spigot/Paper 1.8.8 → 1.21+.
Written in Kotlin, runs fully server side, so every client and every client version is supported. No mods, no datapacks, no paid services — drop the jar in, restart, done.
?️ Your players' passwords are protected with Argon2id — winner of the Password Hashing Competition and OWASP's #1 recommendation. Its memory-hard design makes large-scale GPU brute-force attacks impractical. Passwords are never stored as readable text — not even the server owner can recover them.
✨ Features
- ? Argon2id password hashing — the strongest password protection available today, with OWASP-baseline defaults you can raise in the config
- ⏱️ Sessions — reconnect within 15 minutes (configurable) from the same IP and skip the login. Survives server restarts
- ? Free 2FA — three flavours:
- Google Authenticator (TOTP) — works 100% offline, the QR code is rendered on an in-game map item for easy scanning
- Discord — your own bot DMs the login code
- Telegram — your own bot sends the login code
- ? Security alerts — players with Discord/Telegram linked get warned about new-IP logins, brute-force attempts and password changes — even while offline
- ? Console password shield —
/loginand/registerare intercepted so passwords never appear in the console or log files - ? Full freeze before login — no moving, chatting, commands, damage, inventory or item pickup; optional blindness and spawn teleport that hides base coordinates from stream snipers
- ? Anti-bot & brute-force protection — per-player attempt limits, per-IP lockouts, join-flood lockdown, username regex filter, per-IP account limits
- ? Anti-impersonation — kicks
NoTcHif the account was registered asNotch, blocks duplicate names, optional UUID checks - ? Premium mode —
/premiumlets verified Mojang accounts skip the password (only when the connection can actually be verified — Login+ never pretends) - ? E-mail recovery — forgot the password? A one-time code is mailed via your own SMTP mailbox. 2FA still applies after recovery
- ? Country filter — whitelist or blacklist joins by country
- ? Proxy ready — works behind Velocity, BungeeCord and Waterfall; with shared MySQL, sessions carry across backend servers (no re-login when switching). Login+ checks your forwarding setup on startup and prints hints
- ? Sound feedback — level-up chime on success, buzzer on wrong password (cross-version safe)
- ?️ SQLite out of the box, MySQL for networks — with automatic scheduled backups
- ? Fully translatable — clean English and Russian message files included
⚙️ Commands & Permissions
| Command | Permission | Short Description |
|---|---|---|
/register <pass> <pass> |
loginplus.player.register |
Create an account |
/login <pass> (alias /l) |
loginplus.player.login |
Log in |
/logout |
loginplus.player.logout |
Log out and lock the account |
/changepassword <old> <new> |
loginplus.player.changepassword |
Change password |
/unregister <pass> |
loginplus.player.unregister |
Delete own account |
/2fa setup <totp\|discord\|telegram> |
loginplus.player.2fa |
Enable two-factor auth |
/2fa <code> |
loginplus.player.2fa |
Enter the code during login |
/email set <address> |
loginplus.player.email |
Bind a recovery e-mail |
/email recovery |
loginplus.player.email |
Recover a forgotten password |
/premium / /freemium |
loginplus.player.premium |
Toggle Mojang auto-login |
/loginplus <reload\|forcelogin\|unregister\|info> |
loginplus.admin |
Admin commands |
All player permissions default to true; admin commands default to OP.
? Quick Start
- Drop the jar into
/pluginsand restart the server. - Players run
/register <password> <password>, then/login <password>next time. - (Optional) Enable free 2FA, e-mail recovery and more in
config.yml— every option is documented right in the file.
Setting up the 2FA bots (both 100% free)
- Telegram: message @BotFather →
/newbot→ copy the token intoconfig.yml. Players run/2fa setup telegram. - Discord: discord.com/developers/applications → New Application → Bot → copy the token into
config.yml. Players run/2fa setup discord <their user ID>. - Google Authenticator: nothing to set up — players just run
/2fa setup totpand scan the QR map. Works offline.
? Running behind Velocity / BungeeCord / Waterfall
Login+ runs on your backend (Spigot/Paper) servers and fully supports proxy networks:
- Enable IP forwarding on both sides (proxy and backend).
- For multi-server networks set
storage.type: MYSQLand point every backend at the same database — players switching servers stay logged in seamlessly. - Firewall the backend ports so players can only connect through the proxy.
Login+ verifies the forwarding configuration on startup and prints console hints if something looks wrong.
? Some Advice
- Login+ is built for offline-mode servers — for example, the backend servers behind a Velocity, BungeeCord or Waterfall proxy, where Minecraft's own account verification is turned off and a login plugin is what keeps every account secure. Pure online-mode (premium) servers are already verified by Mojang, so they don't need a login plugin.
- Avoid
/reload; restart the server instead. - Honest security note:
/premiumonly activates when Mojang really verified the connection (online-mode server or online-mode proxy with modern forwarding). On a plain offline-mode server there is nothing to verify, so it politely refuses instead of pretending to be secure.
请登录后举报
暂无评论,抢个沙发吧~