The claims plugin uses usernames to determine who should or should not be allowed to interact with a protected planet. Since these are not unique, a malicious user can easily log in using a different user's name (or change their name on-the-fly) and gain full access to protected planets.
The claims plugin uses usernames to determine who should or should not be allowed to interact with a protected planet. Since these are not unique, a malicious user can easily log in using a different user's name (or change their name on-the-fly) and gain full access to protected planets.