About this project
Ling Yggdrasil is a Yggdrasil external authentication system built for Minecraft, fully compatible with the authlib framework, providing account registration, login, character management, and skin/cape hosting capabilities. It includes a built-in web installation wizard, an anime-style admin console, and a multi-layered security system, allowing you to set up a secure and visually appealing external login service within minutes.
## Quick Start
Environment requirements: Java 25 (recommended; theoretically supports Java 21+), with at least 512 MB of available memory recommended.
Three-step startup:
1. Verify the Java version
2. Download LingYggdrasil-2.2.7.jar and place it in a dedicated empty directory
3. Start it (this directory will become the data directory)
On first startup, the installation wizard will automatically launch (at `http://<server-address>:35598`). Follow the prompts to complete the admin account, database, and email configuration. After installation, the program will simultaneously provide three services:
| Port | Purpose | Access Scope |
|------|------|----------|
| 35565 | User-facing (registration, login, dashboard, skins, friends, etc.) | Public |
| 35577 | Yggdrasil API (for Minecraft launchers) | Public |
| 35599 | Admin console | Should remain private |
| 35598 | Installation wizard | Only open during initial setup |
## Features
### Out-of-the-Box
- Web installation wizard: Automatically guides setup of admin account, database, and email service on first launch
- Multi-database support: SQLite, MySQL, PostgreSQL
- Single JAR deployment: Packaged as a single executable JAR
### Plugin System
- External plugin loading: Automatically scans the `plugins/` directory and loads plugin JARs at startup
- `plugin.yml` description: Paper-style, declaring name, version, author, dependencies, icon, and permission nodes
- Backend plugin management: Supports manual start/stop
- Plugin submenus: Plugins can register to at most one backend submenu
- Dynamic permission nodes: Built-in and plugin nodes are dynamically registered from their sources
- Plugin development API: Build produces `LingYggdrasil-plugin-api-2.2.7.jar`
### Security System
- Argon2 password encryption: 6 adjustable strength levels
- Email verification: Supports domain whitelist/blacklist control
- Same-IP registration limit: Prevents mass registration
- Name blacklist: Supports wildcards
- Independent session system: User, admin, and API use isolated session cookies
- Root integrity protection: Validates the `root_info` table
- Login and operation rate limiting: Frequency limits on critical operations
### User-Facing
- Character management: Create multiple game characters, each with an independent Yggdrasil Token and UUID
- Skins & capes: Upload and manage personal skins and capes, with alias naming and public/private control
- Texture library: Public texture plaza, sorted by popularity, with infinite scroll lazy loading
- Likes & favorites: Like textures to boost popularity
- Shared textures: Two sections for friend-shared and my-favorites
- Friend system: Friend code addition, friend detail cards, block management, checkbox-based texture sharing
- 3D skin preview: Integrated skinview3d, supports 360° rotation preview
- Security settings: Self-service password, email, and nickname changes; view and regenerate tokens
- Operation logs: View, download, and clear your own operation logs
- Themes and languages: Light/dark theme toggle, 10 languages persisted per account
### Admin Console
- Dashboard overview: Core data like user count, character count, skin/cape count, with drag-and-drop component sorting
- User management: View, search, create, edit, and ban users
- Character management: Global CRUD, supporting name changes, ownership transfer, and form switching
- Skin & cape management: Global texture resource management, configure upload size, quantity, storage path, and rate limits
- Security settings: 6-level encryption strength visual cards
- System management: Grouped configuration for site info, feature toggles, domains, announcements, filing, operation logs, etc.
- Permission groups: Admin and user permission groups for fine-grained menu visibility and feature availability control
- World tree settings: Protocol configuration for signature algorithms, token validity, rate limits, UUID versions, etc.
### Yggdrasil Protocol
- Full protocol implementation: Compatible with mainstream Minecraft launchers' Yggdrasil authentication
- Three signature modes: Ed448 (modern), RSA-SHA512, RSA-SHA1 (compatible)
- Token system: Each character automatically generates a 64-bit high-strength token
- Texture hosting: Publicly exposes `/textures/{type}/{hash}` endpoints
- Session management: Complete login, logout, and session validation flow
- Convenience query extensions: Provides extended endpoints for name-based and batch queries
### Internationalization
Built-in Simplified Chinese, Traditional Chinese, Chinese (Huaxia), English, Russian, German, French, Italian, Japanese, and Korean, totaling 10 languages. Language packs are JSON format, supporting external overrides and deep merging.
## Client Integration
Using launchers like HMCL that support custom Yggdrasil as an example:
1. In the launcher's "Account" or "Login Method" settings, select "Custom Yggdrasil / External Login"
2. Fill in the authentication server address with the API root (e.g., `https://example.com`, or `http://<IP>:35577` for direct connection)
3. Enter the character name as the username and the character's Yggdrasil Token as the password
## Tech Stack
| Component | Technology |
|------|------|
| Language | Java 25 |
| Web framework | Javalin |
| Database connection | HikariCP connection pool |
| Database | SQLite / MySQL / PostgreSQL |
| Cryptography | Bouncy Castle (Argon2, Ed448, RSA) |
| Email | Eclipse Angus Mail |
| Logging | Logback + SLF4J |
| Serialization | Jackson |
| Build tool | Maven |
## License
This project is licensed under the GNU Affero General Public License v3.0.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.