Add configurable authlib-injector API path and HTTP support for Yggdrasil auth

Re-implements the changes from PR #2890, adapted for the current codebase
which uses System.Text.Json.Nodes and HttpClient instead of the legacy
Json.JSONData and hand-rolled SslStream HTTP client.

Changes:
- Settings.cs: Convert AuthlibServer from struct to class with
  [TomlDoNotInlineObject]; convert Host to a property that parses
  'host:port' syntax; add AuthlibInjectorAPIPath (default '/api/yggdrasil')
  for servers that use a different prefix (e.g. Drasl uses '/authlib-injector');
  add UseHttps (default true) so local/dev auth servers without TLS work.

- ConfigComments.resx: Add descriptive inline comments for the new
  AuthlibServer fields (Host, Port, AuthlibInjectorAPIPath, UseHttps).

- ProtocolHandler.cs: Replace three hardcoded '/api/yggdrasil/...' paths
  with AuthlibInjectorAPIPath-based paths (authenticate, refresh, join).
  Replace hand-rolled TcpClient+SslStream HTTP in DoHTTPSRequest with
  HttpClient+SocketsHttpHandler (ConnectCallback routes through ProxyHandler).
  Add useHttps parameter so HTTP-only auth servers are supported.

- KeyUtils.cs: Add AuthServerSupportsProfileKeys() that fetches the
  authlib-injector metadata endpoint and checks feature.enable_profile_key.
  Update GetNewProfileKeys() to skip key fetch when the auth server does not
  support profile keys; build the cert URL dynamically using AuthlibInjectorAPIPath
  for Yggdrasil; always fetch real certs instead of returning a dummy response.
  Remove MakeDummyResponse() which is no longer needed.

Tested against a local Drasl instance with authlib-injector 1.2.7 on a
1.21.11 Minecraft server — full auth flow (login, profile key fetch, session
join) confirmed working end-to-end.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Anon 2026-03-22 23:43:24 +01:00
parent 72ec3122ae
commit ff9aa62702
4 changed files with 188 additions and 142 deletions

View file

@ -850,7 +850,19 @@ If the connection to the Minecraft game server is blocked by the firewall, set E
<value>Ignore invalid player name</value>
</data>
<data name="Main.General.AuthlibServer" xml:space="preserve">
<value>Yggdrasil authlib server domain name and port.</value>
<value>authlib-injector authentication server to use for Yggdrasil accounts</value>
</data>
<data name="AuthlibServer.Host" xml:space="preserve">
<value>Domain name or IP address</value>
</data>
<data name="AuthlibServer.Port" xml:space="preserve">
<value>Port to connect on</value>
</data>
<data name="AuthlibServer.AuthlibInjectorAPIPath" xml:space="preserve">
<value>Path component of the authlib-injector API location. Refer to the authlib-injector documentation for more info.</value>
</data>
<data name="AuthlibServer.UseHttps" xml:space="preserve">
<value>Set to false if your authlib-injector server uses plain HTTP (e.g. for local testing without TLS).</value>
</data>
<data name="Main.Advanced.enable_sentry" xml:space="preserve">
<value>Set to false to opt-out of Sentry error logging.</value>