Skip to content

Security: iwosw/server-login

SECURITY.md

Security Policy

Server Login handles local account credentials and network-facing authentication state. Please report suspected vulnerabilities privately and avoid publishing exploit details before a fix is available.

Supported versions

Security fixes are provided for the latest release in the 1.0.x line. Older builds may be asked to upgrade before a report is investigated.

Reporting a vulnerability

Open a private report through GitHub Security Advisories.

Include:

  • the Server Login, Minecraft, and Forge versions;
  • the relevant proxy and forwarding configuration;
  • clear reproduction steps;
  • the expected and observed security boundary;
  • a minimal proof of concept, if one is safe to share privately.

Do not include real player passwords or an unredacted users.json database. Use test accounts and remove public IP addresses, access tokens, and unrelated personal data from logs.

You should receive an initial response within seven days. Please allow time to investigate, prepare a fix, and coordinate disclosure before discussing the issue publicly.

Scope reminder

Server Login authenticates local identities on an offline-mode Minecraft server. It does not provide transport encryption, Mojang account verification, firewalling, anti-DDoS protection, or secure proxy configuration.

There aren't any published security advisories