About this project

Ling Yggdrasil is a Yggdrasil external authentication system built for Minecraft, fully compatible with the authlib framework, providing account registration, login, character management, and skin/cape hosting capabilities. It includes a built-in web installation wizard, an anime-style admin console, and a multi-layered security system, allowing you to set up a secure and visually appealing external login service within minutes. ## Quick Start Environment requirements: Java 25 (recommended; theoretically supports Java 21+), with at least 512 MB of available memory recommended. Three-step startup: 1. Verify the Java version 2. Download LingYggdrasil-2.2.7.jar and place it in a dedicated empty directory 3. Start it (this directory will become the data directory) On first startup, the installation wizard will automatically launch (at `http://<server-address>:35598`). Follow the prompts to complete the admin account, database, and email configuration. After installation, the program will simultaneously provide three services: | Port | Purpose | Access Scope | |------|------|----------| | 35565 | User-facing (registration, login, dashboard, skins, friends, etc.) | Public | | 35577 | Yggdrasil API (for Minecraft launchers) | Public | | 35599 | Admin console | Should remain private | | 35598 | Installation wizard | Only open during initial setup | ## Features ### Out-of-the-Box - Web installation wizard: Automatically guides setup of admin account, database, and email service on first launch - Multi-database support: SQLite, MySQL, PostgreSQL - Single JAR deployment: Packaged as a single executable JAR ### Plugin System - External plugin loading: Automatically scans the `plugins/` directory and loads plugin JARs at startup - `plugin.yml` description: Paper-style, declaring name, version, author, dependencies, icon, and permission nodes - Backend plugin management: Supports manual start/stop - Plugin submenus: Plugins can register to at most one backend submenu - Dynamic permission nodes: Built-in and plugin nodes are dynamically registered from their sources - Plugin development API: Build produces `LingYggdrasil-plugin-api-2.2.7.jar` ### Security System - Argon2 password encryption: 6 adjustable strength levels - Email verification: Supports domain whitelist/blacklist control - Same-IP registration limit: Prevents mass registration - Name blacklist: Supports wildcards - Independent session system: User, admin, and API use isolated session cookies - Root integrity protection: Validates the `root_info` table - Login and operation rate limiting: Frequency limits on critical operations ### User-Facing - Character management: Create multiple game characters, each with an independent Yggdrasil Token and UUID - Skins & capes: Upload and manage personal skins and capes, with alias naming and public/private control - Texture library: Public texture plaza, sorted by popularity, with infinite scroll lazy loading - Likes & favorites: Like textures to boost popularity - Shared textures: Two sections for friend-shared and my-favorites - Friend system: Friend code addition, friend detail cards, block management, checkbox-based texture sharing - 3D skin preview: Integrated skinview3d, supports 360° rotation preview - Security settings: Self-service password, email, and nickname changes; view and regenerate tokens - Operation logs: View, download, and clear your own operation logs - Themes and languages: Light/dark theme toggle, 10 languages persisted per account ### Admin Console - Dashboard overview: Core data like user count, character count, skin/cape count, with drag-and-drop component sorting - User management: View, search, create, edit, and ban users - Character management: Global CRUD, supporting name changes, ownership transfer, and form switching - Skin & cape management: Global texture resource management, configure upload size, quantity, storage path, and rate limits - Security settings: 6-level encryption strength visual cards - System management: Grouped configuration for site info, feature toggles, domains, announcements, filing, operation logs, etc. - Permission groups: Admin and user permission groups for fine-grained menu visibility and feature availability control - World tree settings: Protocol configuration for signature algorithms, token validity, rate limits, UUID versions, etc. ### Yggdrasil Protocol - Full protocol implementation: Compatible with mainstream Minecraft launchers' Yggdrasil authentication - Three signature modes: Ed448 (modern), RSA-SHA512, RSA-SHA1 (compatible) - Token system: Each character automatically generates a 64-bit high-strength token - Texture hosting: Publicly exposes `/textures/{type}/{hash}` endpoints - Session management: Complete login, logout, and session validation flow - Convenience query extensions: Provides extended endpoints for name-based and batch queries ### Internationalization Built-in Simplified Chinese, Traditional Chinese, Chinese (Huaxia), English, Russian, German, French, Italian, Japanese, and Korean, totaling 10 languages. Language packs are JSON format, supporting external overrides and deep merging. ## Client Integration Using launchers like HMCL that support custom Yggdrasil as an example: 1. In the launcher's "Account" or "Login Method" settings, select "Custom Yggdrasil / External Login" 2. Fill in the authentication server address with the API root (e.g., `https://example.com`, or `http://<IP>:35577` for direct connection) 3. Enter the character name as the username and the character's Yggdrasil Token as the password ## Tech Stack | Component | Technology | |------|------| | Language | Java 25 | | Web framework | Javalin | | Database connection | HikariCP connection pool | | Database | SQLite / MySQL / PostgreSQL | | Cryptography | Bouncy Castle (Argon2, Ed448, RSA) | | Email | Eclipse Angus Mail | | Logging | Logback + SLF4J | | Serialization | Jackson | | Build tool | Maven | ## License This project is licensed under the GNU Affero General Public License v3.0.