Re-implements the changes from PR #2890, adapted for the current codebase
which uses System.Text.Json.Nodes and HttpClient instead of the legacy
Json.JSONData and hand-rolled SslStream HTTP client.
Changes:
- Settings.cs: Convert AuthlibServer from struct to class with
[TomlDoNotInlineObject]; convert Host to a property that parses
'host:port' syntax; add AuthlibInjectorAPIPath (default '/api/yggdrasil')
for servers that use a different prefix (e.g. Drasl uses '/authlib-injector');
add UseHttps (default true) so local/dev auth servers without TLS work.
- ConfigComments.resx: Add descriptive inline comments for the new
AuthlibServer fields (Host, Port, AuthlibInjectorAPIPath, UseHttps).
- ProtocolHandler.cs: Replace three hardcoded '/api/yggdrasil/...' paths
with AuthlibInjectorAPIPath-based paths (authenticate, refresh, join).
Replace hand-rolled TcpClient+SslStream HTTP in DoHTTPSRequest with
HttpClient+SocketsHttpHandler (ConnectCallback routes through ProxyHandler).
Add useHttps parameter so HTTP-only auth servers are supported.
- KeyUtils.cs: Add AuthServerSupportsProfileKeys() that fetches the
authlib-injector metadata endpoint and checks feature.enable_profile_key.
Update GetNewProfileKeys() to skip key fetch when the auth server does not
support profile keys; build the cert URL dynamically using AuthlibInjectorAPIPath
for Yggdrasil; always fetch real certs instead of returning a dummy response.
Remove MakeDummyResponse() which is no longer needed.
Tested against a local Drasl instance with authlib-injector 1.2.7 on a
1.21.11 Minecraft server — full auth flow (login, profile key fetch, session
join) confirmed working end-to-end.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Rewrite Json.cs to use System.Text.Json.Nodes (JsonNode, JsonObject, JsonArray)
- Add JsonNodeExtensions.GetStringValue() for backward-compatible string access
- Update all 14 consumer files to use the new JsonNode API
- Remove ~300 lines of hand-rolled JSON parsing code from 2013
- Replace KeyUtils.EscapeString with delegation to Json.EscapeString
Co-authored-by: milutinke <441903+milutinke@users.noreply.github.com>
Agent-Logs-Url: https://github.com/milutinke/Minecraft-Console-Client/sessions/afcd1b7b-ea23-4a0d-bb46-a90b623406fc
When try to send message in yggdrasil-auth server with `enforce-secure-profile=true`
and `online-mode=true` enabled, will fail with message in red:
Chat disabled due to missing profile public key. Please try reconnecting.
So yggdrasil-auth-client also has to encrypt chat messages like Microsoft-auth-client
to send out messages.