Conversation
Players listed in settings.sessions.excludedPlayers are never granted a session and never get one restored, so they always have to authenticate even if their IP hasn't changed. This prevents a player from entering another player's account when both share the same IP.
|
Why not make it a permission node, like |
|
|
Thanks for the suggestion. I replaced |
Sessions are restored by name and IP only. Players sharing an IP (for example, in one household or behind NAT) can reconnect under each other's names while a session is valid, without a password or TOTP code. This is a real case on our server; disabling sessions globally is the only current workaround.
This adds
authme.session.disable(default:false). Grant it to an affected player's account through the permission system. AuthMe revokes any existing session on the next join, requires normal authentication, and does not grant a new session after login. The pre-join dialog check also considers the permission; the actual join checks it again before restoring a session.