Skip to content

feat(sessions): add per-player session disable permission - #3150

Open
strobil wants to merge 2 commits into
AuthMe:masterfrom
Vanilla-Game:feat/session-excluded-players
Open

strobil wants to merge 2 commits into
AuthMe:masterfrom
Vanilla-Game:feat/session-excluded-players

Conversation

@strobil

@strobil strobil commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Sessions are restored by name and IP only. Players sharing an IP (for example, in one household or behind NAT) can reconnect under each other's names while a session is valid, without a password or TOTP code. This is a real case on our server; disabling sessions globally is the only current workaround.

This adds authme.session.disable (default: false). Grant it to an affected player's account through the permission system. AuthMe revokes any existing session on the next join, requires normal authentication, and does not grant a new session after login. The pre-join dialog check also considers the permission; the actual join checks it again before restoring a session.

Players listed in settings.sessions.excludedPlayers are never granted
a session and never get one restored, so they always have to
authenticate even if their IP hasn't changed. This prevents a player
from entering another player's account when both share the same IP.
@krusic22

Copy link
Copy Markdown
Member

Why not make it a permission node, like allowmultipleaccounts for example?

@strobil

strobil commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

I feel like it’s useless. You could just make a permission that I can give to someone who wants it, though idk if it’s even needed. If something happens, just use /2fa.

/2fa doesn’t protect against this case. AuthMe checks the TOTP code during a regular login, but a valid session is restored automatically, without asking for either the password or the TOTP code. This is a real issue on our server: we have players who share an IP, and one can reconnect under the other’s name while that account’s session is still valid. A permission node could work instead of a config list, as long as it prevents both granting and restoring sessions for that player.

@strobil strobil changed the title feat(sessions): add per-player session exclusion list feat(sessions): add per-player session disable permission Sep 23, 2026
@strobil

strobil commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

Thanks for the suggestion. I replaced excludedPlayers with the authme.session.disable permission in af59e3e. Players with this permission must log in every time, even from the same IP. AuthMe discards any saved session when they join and does not create a new one after they log in.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants