nickuc / OpeNLogin

A practical, secure and friendly authentication plugin
https://www.spigotmc.org/resources/57272/
MIT License
65 stars 60 forks source link

Major Security risk! #12

Closed K4mey closed 3 years ago

K4mey commented 3 years ago

I have gotten a lot of reports from my players that there is a major security risk with your login plugin.. there are some players that abuse this bug, the thing is that they use someone else's name to join server, even tho they don't know password they still can toggle F3 and see their coordinates, and grief their bases, using other plugin to tp you to spawn every time you login does fix this issue but players have to do /home every time they want to go back to their home, and this is also annoying to new players, that are just exploring terrain and when they re-join server they can't go back to the location they left of.

i have noticed that a lot of other login plugins teleport you to desired spawn location on join, and after you login using /login command, it teleports you back to your previous location, so that's what i recommend to be added.

There is an easy fix if you're a big server and you have bungeecord and hub, but for small servers like mine it is essential that the login plugin has spawn on join feature.

a8underscore commented 3 years ago

tldr: "Can you add a feture that when players join server they get teleported to spawn and then when they login they get teleported back, to prevent cord stealing?"

nickuc commented 3 years ago

Hi!

I will probably implement this feature soon. For now, I recommend using nLogin (https://nickuc.com/repo/find?name=nLogin).

K4mey commented 3 years ago

Is it possible to transfer all registered users over to nLogin so that they don't have to re-register, because someone will abuse and register with someone else's username.

nickuc commented 3 years ago

Yes, it is possible. Perform the command /nlogin converter openlogin