Compare commits

...
2 Commits
Author SHA1 Message Date
dmg ebc7c7df17 feat(dashboard): refine activity telemetry and maps
CI / validate (push) Successful in 5m24s
Release / release (push) Successful in 11m6s
2026-08-01 20:28:32 -04:00
dmg 9116107917 feat(dashboard): map latest user locations
CI / validate (push) Successful in 5m20s
Release / release (push) Successful in 10m40s
2026-08-01 19:41:03 -04:00
34 changed files with 1044 additions and 66 deletions
+4 -2
View File
@@ -7,9 +7,11 @@ The `design/` directory is the OKF v0.1 product record for this repository. Use
Before changing behavior: Before changing behavior:
1. Read `design/index.md` and every story related to the requested behavior. 1. Read `design/index.md` and every story related to the requested behavior.
2. Update an existing story or create a new `design/us-NNN-short-name.md` story before implementation. 2. Draft updates to an existing story or create a new `design/us-NNN-short-name.md` story before implementation.
3. Define observable acceptance criteria using user or operator language. 3. Define observable acceptance criteria using user or operator language.
4. Set story status to `proposed` or `in-progress` while the work is incomplete. 4. Present the relevant new or updated stories and acceptance criteria to the user for review, and wait for explicit confirmation before changing implementation code.
5. Incorporate requested story changes before proceeding.
6. Set story status to `proposed` or `in-progress` while the work is incomplete.
While implementing: While implementing:
+1 -1
View File
@@ -76,7 +76,7 @@ The token is displayed once and stored only as a SHA-256 hash.
- PostgreSQL and Drizzle ORM - PostgreSQL and Drizzle ORM
- Keycloak OIDC for admin access with the `minecraft-account-manager-admin` role - Keycloak OIDC for admin access with the `minecraft-account-manager-admin` role
- Admin user search, account management, event exploration, operational metrics, and automatic Discord nickname synchronization - Admin user search, account management, event exploration, DAU and confirmed-connection metrics, toggleable Natural Earth/OpenStreetMap user-location views, and automatic Discord nickname synchronization
- Exclusive group admission: unassigned users fall back to protected `everyone`, and only the effective group's access setting applies - Exclusive group admission: unassigned users fall back to protected `everyone`, and only the effective group's access setting applies
- Deployment-managed Discord guild ID and invite URL - Deployment-managed Discord guild ID and invite URL
- discord.js bot with `/register` and `/account` - discord.js bot with `/register` and `/account`
+1 -1
View File
@@ -4,7 +4,7 @@ const contentSecurityPolicy = [
"default-src 'self'", "default-src 'self'",
`script-src 'self' 'unsafe-inline'${process.env.NODE_ENV === "development" ? " 'unsafe-eval'" : ""}`, `script-src 'self' 'unsafe-inline'${process.env.NODE_ENV === "development" ? " 'unsafe-eval'" : ""}`,
"style-src 'self' 'unsafe-inline'", "style-src 'self' 'unsafe-inline'",
"img-src 'self' data:", "img-src 'self' data: https://tile.openstreetmap.org",
"font-src 'self'", "font-src 'self'",
"connect-src 'self'", "connect-src 'self'",
"object-src 'none'", "object-src 'none'",
+8 -1
View File
@@ -17,17 +17,24 @@
"@minecraft-account-manager/logging": "*", "@minecraft-account-manager/logging": "*",
"@minecraft-account-manager/minecraft": "*", "@minecraft-account-manager/minecraft": "*",
"@minecraft-account-manager/network": "*", "@minecraft-account-manager/network": "*",
"d3-geo": "^3.1.1",
"drizzle-orm": "^0.45.1", "drizzle-orm": "^0.45.1",
"leaflet": "^1.9.4",
"next": "^16.2.1", "next": "^16.2.1",
"next-auth": "^4.24.13", "next-auth": "^4.24.13",
"react": "^19.2.3", "react": "^19.2.3",
"react-dom": "^19.2.3" "react-dom": "^19.2.3",
"topojson-client": "^3.1.0",
"world-atlas": "^2.0.2"
}, },
"devDependencies": { "devDependencies": {
"@tailwindcss/postcss": "^4.2.1", "@tailwindcss/postcss": "^4.2.1",
"@types/d3-geo": "^3.1.1",
"@types/leaflet": "^1.9.22",
"@types/node": "^25.0.3", "@types/node": "^25.0.3",
"@types/react": "^19.2.14", "@types/react": "^19.2.14",
"@types/react-dom": "^19.2.3", "@types/react-dom": "^19.2.3",
"@types/topojson-client": "^3.1.5",
"eslint": "^9.39.4", "eslint": "^9.39.4",
"eslint-config-next": "^16.2.1", "eslint-config-next": "^16.2.1",
"tailwindcss": "^4.2.1", "tailwindcss": "^4.2.1",
+102 -34
View File
@@ -1,8 +1,11 @@
import { events, ipObservations, minecraftAccounts, users } from "@minecraft-account-manager/database"; import { events, ipIntelligence, ipObservations, minecraftAccounts, users } from "@minecraft-account-manager/database";
import { and, count, countDistinct, desc, eq, gte, inArray, isNotNull, sql } from "drizzle-orm"; import { formatManagedDiscordNickname } from "@minecraft-account-manager/minecraft";
import { and, count, countDistinct, desc, eq, gte, inArray, isNotNull, isNull, sql } from "drizzle-orm";
import Link from "next/link"; import Link from "next/link";
import { UserWorldMap, type UserMapLocation } from "@/components/user-world-map";
import { db } from "@/lib/database"; import { db } from "@/lib/database";
import { fillDailySeries, type DailyCount } from "@/lib/admin-metrics"; import { fillDailySeries, mergeRiskActivity, type DailyCount } from "@/lib/admin-metrics";
import { parseUserLocation } from "@/lib/user-location-map";
export const dynamic = "force-dynamic"; export const dynamic = "force-dynamic";
@@ -13,28 +16,56 @@ export default async function AdminDashboardPage() {
fourteenDaysAgo.setUTCHours(0, 0, 0, 0); fourteenDaysAgo.setUTCHours(0, 0, 0, 0);
const oneDayAgo = new Date(now.getTime() - 24 * 60 * 60 * 1_000); const oneDayAgo = new Date(now.getTime() - 24 * 60 * 60 * 1_000);
const [registrationRows, [totals], [monthlyActive], riskyActivity, [recentDenials]] = await Promise.all([ const [dailyActiveRows, [totals], [monthlyActive], [monthlyAccounts], locationRows, riskyLatestRows, riskySummaryRows, [recentDenials]] = await Promise.all([
db db
.select({ .select({
day: sql<string>`to_char(date_trunc('day', ${users.createdAt} at time zone 'UTC'), 'YYYY-MM-DD')`, day: sql<string>`to_char(date_trunc('day', ${ipObservations.observedAt} at time zone 'UTC'), 'YYYY-MM-DD')`,
count: count(), count: countDistinct(ipObservations.userId),
}) })
.from(users) .from(ipObservations)
.where(gte(users.createdAt, fourteenDaysAgo)) .where(and(gte(ipObservations.observedAt, fourteenDaysAgo), isNotNull(ipObservations.userId)))
.groupBy(sql`date_trunc('day', ${users.createdAt} at time zone 'UTC')`) .groupBy(sql`date_trunc('day', ${ipObservations.observedAt} at time zone 'UTC')`)
.orderBy(sql`date_trunc('day', ${users.createdAt} at time zone 'UTC')`), .orderBy(sql`date_trunc('day', ${ipObservations.observedAt} at time zone 'UTC')`),
db.select({ users: count(users.id) }).from(users), db.select({ users: count(users.id) }).from(users),
db.select({ db.select({
users: countDistinct(ipObservations.userId), users: countDistinct(ipObservations.userId),
accounts: countDistinct(ipObservations.minecraftAccountId),
}).from(ipObservations).where(and( }).from(ipObservations).where(and(
gte(ipObservations.observedAt, thirtyDaysAgo), gte(ipObservations.observedAt, thirtyDaysAgo),
isNotNull(ipObservations.userId), isNotNull(ipObservations.userId),
)), )),
db.select({ accounts: countDistinct(events.subject) }).from(events).where(and(
eq(events.type, "games.minecraft.account-manager.game.player.connected"),
gte(events.time, thirtyDaysAgo),
)),
db db
.select({ .selectDistinctOn([ipObservations.userId], {
id: ipObservations.id, userId: ipObservations.userId,
name: users.firstName,
discordUsername: users.discordUsername,
primaryUsername: minecraftAccounts.username,
classification: ipObservations.classification, classification: ipObservations.classification,
source: ipObservations.source,
observedAt: ipObservations.observedAt,
intelligence: ipIntelligence.rawResponse,
})
.from(ipObservations)
.innerJoin(users, eq(users.id, ipObservations.userId))
.innerJoin(ipIntelligence, eq(ipIntelligence.ipAddress, ipObservations.ipAddress))
.leftJoin(minecraftAccounts, and(
eq(minecraftAccounts.userId, users.id),
eq(minecraftAccounts.isPrimary, true),
isNull(minecraftAccounts.deletedAt),
))
.where(and(
isNotNull(ipObservations.userId),
sql`case when jsonb_typeof(${ipIntelligence.rawResponse}->'location'->'latitude') = 'number' then (${ipIntelligence.rawResponse}->'location'->>'latitude')::double precision between -90 and 90 else false end`,
sql`case when jsonb_typeof(${ipIntelligence.rawResponse}->'location'->'longitude') = 'number' then (${ipIntelligence.rawResponse}->'location'->>'longitude')::double precision between -180 and 180 else false end`,
))
.orderBy(ipObservations.userId, desc(ipObservations.observedAt), desc(ipObservations.id)),
db
.selectDistinctOn([ipObservations.userId], {
id: ipObservations.id,
classification: ipIntelligence.classification,
observedAt: ipObservations.observedAt, observedAt: ipObservations.observedAt,
source: ipObservations.source, source: ipObservations.source,
userId: users.id, userId: users.id,
@@ -43,17 +74,53 @@ export default async function AdminDashboardPage() {
accountUsername: minecraftAccounts.username, accountUsername: minecraftAccounts.username,
}) })
.from(ipObservations) .from(ipObservations)
.leftJoin(users, eq(users.id, ipObservations.userId)) .innerJoin(users, eq(users.id, ipObservations.userId))
.leftJoin(minecraftAccounts, eq(minecraftAccounts.id, ipObservations.minecraftAccountId)) .leftJoin(minecraftAccounts, eq(minecraftAccounts.id, ipObservations.minecraftAccountId))
.where(inArray(ipObservations.classification, ["vpn", "proxy", "tor"])) .innerJoin(ipIntelligence, eq(ipIntelligence.ipAddress, ipObservations.ipAddress))
.orderBy(desc(ipObservations.observedAt)) .where(and(
.limit(10), isNotNull(ipObservations.userId),
gte(ipObservations.observedAt, thirtyDaysAgo),
inArray(ipIntelligence.classification, ["vpn", "proxy", "tor"]),
))
.orderBy(ipObservations.userId, desc(ipObservations.observedAt), desc(ipObservations.id)),
db
.select({
userId: ipObservations.userId,
count: count(),
classifications: sql<string[]>`array_agg(distinct ${ipIntelligence.classification}::text order by ${ipIntelligence.classification}::text)`,
sources: sql<string[]>`array_agg(distinct ${ipObservations.source}::text order by ${ipObservations.source}::text)`,
})
.from(ipObservations)
.innerJoin(ipIntelligence, eq(ipIntelligence.ipAddress, ipObservations.ipAddress))
.where(and(
isNotNull(ipObservations.userId),
gte(ipObservations.observedAt, thirtyDaysAgo),
inArray(ipIntelligence.classification, ["vpn", "proxy", "tor"]),
))
.groupBy(ipObservations.userId),
db.select({ count: count() }).from(events).where(and( db.select({ count: count() }).from(events).where(and(
eq(events.type, "games.minecraft.account-manager.game.login.denied"), eq(events.type, "games.minecraft.account-manager.game.login.denied"),
gte(events.time, oneDayAgo), gte(events.time, oneDayAgo),
)), )),
]); ]);
const registrations = fillDailySeries(registrationRows as DailyCount[], now, 14); const dailyActive = fillDailySeries(dailyActiveRows as DailyCount[], now, 14);
const riskyActivity = mergeRiskActivity(riskyLatestRows, riskySummaryRows).slice(0, 10);
const locations = locationRows.flatMap((row): UserMapLocation[] => {
const parsed = parseUserLocation(row.intelligence);
if (!parsed || !row.userId) return [];
return [{
userId: row.userId,
name: row.name ?? row.discordUsername,
discordUsername: row.discordUsername,
nickname: formatManagedDiscordNickname(row.name ?? row.discordUsername, row.primaryUsername ?? null),
latitude: parsed.latitude,
longitude: parsed.longitude,
location: parsed.label,
classification: row.classification,
source: row.source,
observedAt: row.observedAt,
}];
});
return ( return (
<main className="mx-auto max-w-6xl px-6 py-14"> <main className="mx-auto max-w-6xl px-6 py-14">
@@ -63,18 +130,20 @@ export default async function AdminDashboardPage() {
<p className="mt-5 max-w-2xl text-sm leading-6 text-muted">Live, server-rendered registration, activity, and network-risk signals from the account registry.</p> <p className="mt-5 max-w-2xl text-sm leading-6 text-muted">Live, server-rendered registration, activity, and network-risk signals from the account registry.</p>
</header> </header>
<section aria-label="Key metrics" className="mt-8 grid gap-4 sm:grid-cols-2 lg:grid-cols-4"> <UserWorldMap locations={locations} unavailableCount={Math.max(0, (totals?.users ?? 0) - locations.length)} />
<section aria-label="Key metrics" className="mt-10 grid gap-4 sm:grid-cols-2 lg:grid-cols-4">
<Metric label="Registered users" value={totals?.users ?? 0} detail="All time" /> <Metric label="Registered users" value={totals?.users ?? 0} detail="All time" />
<Metric label="Monthly active users" value={monthlyActive?.users ?? 0} detail="Distinct users · 30 days" /> <Metric label="Monthly active users" value={monthlyActive?.users ?? 0} detail="Distinct users · 30 days" />
<Metric label="Active Minecraft accounts" value={monthlyActive?.accounts ?? 0} detail="Distinct accounts · 30 days" /> <Metric label="Active Minecraft accounts" value={monthlyAccounts?.accounts ?? 0} detail="Confirmed connections · 30 days" />
<Metric label="Login denials" value={recentDenials?.count ?? 0} detail="Past 24 hours" accent /> <Metric label="Login denials" value={recentDenials?.count ?? 0} detail="Past 24 hours" accent />
</section> </section>
<div className="mt-10 grid gap-8 lg:grid-cols-[1.3fr_0.7fr]"> <div className="mt-10 grid gap-8 lg:grid-cols-[1.3fr_0.7fr]">
<RegistrationChart data={registrations} /> <DailyActiveChart data={dailyActive} />
<section className="border border-line bg-panel p-6 shadow-[6px_6px_0_var(--color-shadow)]"> <section className="border border-line bg-panel p-6 shadow-[6px_6px_0_var(--color-shadow)]">
<div className="flex items-start justify-between gap-4"> <div className="flex items-start justify-between gap-4">
<div><p className="font-mono text-[9px] font-bold uppercase tracking-widest text-muted">Network review</p><h2 className="mt-2 font-display text-2xl font-black uppercase">Recent VPN activity</h2></div> <div><p className="font-mono text-[9px] font-bold uppercase tracking-widest text-muted">Network review</p><h2 className="mt-2 font-display text-2xl font-black uppercase">Recent risky network activity</h2><p className="mt-2 text-xs text-muted">Collapsed per user across VPN, proxy, and Tor observations from the past 30 days.</p></div>
<Link className="font-mono text-[9px] font-bold uppercase underline underline-offset-4" href="/admin/events?category=security">All security events</Link> <Link className="font-mono text-[9px] font-bold uppercase underline underline-offset-4" href="/admin/events?category=security">All security events</Link>
</div> </div>
<div className="mt-5 divide-y divide-line"> <div className="mt-5 divide-y divide-line">
@@ -83,9 +152,9 @@ export default async function AdminDashboardPage() {
<div className="flex items-start justify-between gap-3"> <div className="flex items-start justify-between gap-3">
<div> <div>
{activity.userId ? <Link className="font-mono text-xs font-bold underline decoration-line underline-offset-4" href={`/admin/users/${activity.userId}`}>{activity.firstName ?? activity.discordUsername ?? "Unknown user"}</Link> : <span className="font-mono text-xs font-bold">Unknown user</span>} {activity.userId ? <Link className="font-mono text-xs font-bold underline decoration-line underline-offset-4" href={`/admin/users/${activity.userId}`}>{activity.firstName ?? activity.discordUsername ?? "Unknown user"}</Link> : <span className="font-mono text-xs font-bold">Unknown user</span>}
<p className="mt-1 text-xs text-muted">{activity.accountUsername ?? "No Minecraft account"} · {activity.source}</p> <p className="mt-1 text-xs text-muted">{activity.accountUsername ?? "No Minecraft account"} · {activity.sources.join(" + ")} · {activity.count} {activity.count === 1 ? "observation" : "observations"}</p>
</div> </div>
<span className="bg-accent px-2 py-1 font-mono text-[9px] font-bold uppercase text-canvas">{activity.classification}</span> <span className="bg-accent px-2 py-1 font-mono text-[9px] font-bold uppercase text-canvas">{activity.classifications.join(" + ")}</span>
</div> </div>
<time className="mt-2 block font-mono text-[9px] text-muted" dateTime={activity.observedAt.toISOString()}>{activity.observedAt.toISOString()}</time> <time className="mt-2 block font-mono text-[9px] text-muted" dateTime={activity.observedAt.toISOString()}>{activity.observedAt.toISOString()}</time>
</article> </article>
@@ -108,7 +177,7 @@ function Metric({ label, value, detail, accent = false }: { label: string; value
); );
} }
function RegistrationChart({ data }: { data: DailyCount[] }) { function DailyActiveChart({ data }: { data: DailyCount[] }) {
const width = 720; const width = 720;
const height = 260; const height = 260;
const padding = 32; const padding = 32;
@@ -121,22 +190,21 @@ function RegistrationChart({ data }: { data: DailyCount[] }) {
return ( return (
<section className="border border-line bg-panel p-6 shadow-[6px_6px_0_var(--color-shadow)]"> <section className="border border-line bg-panel p-6 shadow-[6px_6px_0_var(--color-shadow)]">
<p className="font-mono text-[9px] font-bold uppercase tracking-widest text-muted">Growth signal</p> <p className="font-mono text-[9px] font-bold uppercase tracking-widest text-muted">Activity signal</p>
<h2 className="mt-2 font-display text-2xl font-black uppercase">New users by day</h2> <h2 className="mt-2 font-display text-2xl font-black uppercase">Daily active users</h2>
<svg aria-labelledby="registration-chart-title registration-chart-description" className="mt-6 h-auto w-full" role="img" viewBox={`0 0 ${width} ${height}`}> <svg aria-labelledby="daily-active-chart-title daily-active-chart-description" className="mt-6 h-auto w-full" role="img" viewBox={`0 0 ${width} ${height}`}>
<title id="registration-chart-title">New user registrations over the last 14 days</title> <title id="daily-active-chart-title">Daily active users over the last 14 days</title>
<desc id="registration-chart-description">Daily registrations range from zero to {maximum}. A text summary follows the chart.</desc> <desc id="daily-active-chart-description">Distinct daily users range from zero to {maximum}. Date-labelled values follow the chart.</desc>
<line stroke="var(--line)" strokeWidth="1" x1={padding} x2={width - padding} y1={height - padding} y2={height - padding} /> <line stroke="var(--line)" strokeWidth="1" x1={padding} x2={width - padding} y1={height - padding} y2={height - padding} />
<polyline fill="none" points={points} stroke="var(--accent)" strokeLinecap="square" strokeLinejoin="miter" strokeWidth="4" /> <polyline fill="none" points={points} stroke="var(--accent)" strokeLinecap="square" strokeLinejoin="miter" strokeWidth="4" />
{data.map((entry, index) => { {data.map((entry, index) => {
const [x, y] = points.split(" ")[index]!.split(","); const [x, y] = points.split(" ")[index]!.split(",");
return <circle cx={x} cy={y} fill="var(--panel)" key={entry.day} r="5" stroke="var(--ink)" strokeWidth="3"><title>{entry.day}: {entry.count} new users</title></circle>; return <circle cx={x} cy={y} fill="var(--panel)" key={entry.day} r="5" stroke="var(--ink)" strokeWidth="3"><title>{entry.day}: {entry.count} active users</title></circle>;
})} })}
</svg> </svg>
<dl className="mt-4 grid grid-cols-7 gap-2 border-t border-line pt-4 text-center"> <dl className="mt-4 grid grid-cols-7 gap-2 border-t border-line pt-4 text-center sm:grid-cols-[repeat(14,minmax(0,1fr))]">
{data.map((entry) => <div key={entry.day}><dt className="sr-only">{entry.day}</dt><dd className="font-mono text-xs font-bold">{entry.count}</dd></div>)} {data.map((entry) => <div key={entry.day}><dt className="font-mono text-[8px] text-muted"><time dateTime={entry.day}>{entry.day.slice(5)}</time></dt><dd className="mt-1 font-mono text-xs font-bold">{entry.count}</dd></div>)}
</dl> </dl>
<div aria-hidden="true" className="mt-2 flex justify-between font-mono text-[9px] text-muted"><span>{data[0]?.day}</span><span>{data.at(-1)?.day}</span></div>
</section> </section>
); );
} }
@@ -0,0 +1,134 @@
import { hashToken } from "@minecraft-account-manager/auth";
import { beforeEach, describe, expect, it, vi } from "vitest";
const databaseState = vi.hoisted(() => ({
account: { id: "aaaaaaaa-aaaa-4aaa-8aaa-aaaaaaaaaaaa", userId: "bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb" } as { id: string; userId: string } | null,
inserts: [] as Record<string, unknown>[],
credentialHash: "" as string | null,
replay: false,
}));
vi.mock("@/lib/database", () => ({
db: {
select: () => ({
from: () => ({
where: () => ({
limit: async () => databaseState.credentialHash ? [{ secretHash: databaseState.credentialHash }] : [],
}),
}),
}),
transaction: async (callback: (tx: unknown) => Promise<unknown>) => callback({
delete: () => ({ where: async () => undefined }),
insert: () => ({
values: async (value: Record<string, unknown>) => {
if (databaseState.replay && "requestId" in value) {
throw { code: "23505", constraint_name: "plugin_requests_pkey" };
}
databaseState.inserts.push(value);
},
}),
select: () => ({
from: () => ({
where: () => ({
limit: async () => databaseState.account ? [databaseState.account] : [],
}),
}),
}),
}),
},
}));
import { GET, POST } from "./route";
function validRequest(overrides: Record<string, unknown> = {}) {
return new Request("http://localhost/api/velocity/connection", {
method: "POST",
headers: { authorization: "Bearer valid-token", "content-type": "application/json" },
body: JSON.stringify({
requestId: "8dd9dbdc-020a-4077-983c-77747522de8f",
serverId: "velocity-main",
minecraftUuid: "069a79f444e94726a5befca90e38aaf5",
username: "Notch",
occurredAt: new Date().toISOString(),
...overrides,
}),
});
}
describe("Velocity connection reporting endpoint", () => {
beforeEach(() => {
databaseState.account = { id: "aaaaaaaa-aaaa-4aaa-8aaa-aaaaaaaaaaaa", userId: "bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb" };
databaseState.inserts = [];
databaseState.credentialHash = hashToken("valid-token");
databaseState.replay = false;
});
it("rejects methods other than POST with Problem Details", async () => {
const response = GET(new Request("http://localhost/api/velocity/connection"));
expect(response.status).toBe(405);
expect(response.headers.get("content-type")).toContain("application/problem+json");
expect(response.headers.get("allow")).toBe("POST");
});
it("requires a server credential", async () => {
const response = await POST(new Request("http://localhost/api/velocity/connection", {
method: "POST",
headers: { "content-type": "application/json" },
body: "{}",
}));
expect(response.status).toBe(401);
});
it("validates the report before database access", async () => {
const response = await POST(new Request("http://localhost/api/velocity/connection", {
method: "POST",
headers: { authorization: "Bearer test", "content-type": "application/json" },
body: JSON.stringify({ username: "bad name" }),
}));
expect(response.status).toBe(400);
await expect(response.json()).resolves.toMatchObject({ type: "urn:error:invalid-velocity-connection-request", status: 400 });
});
it("rejects invalid or revoked server credentials", async () => {
databaseState.credentialHash = null;
const response = await POST(validRequest());
expect(response.status).toBe(401);
expect(databaseState.inserts).toHaveLength(0);
});
it("rejects stale reports before recording them", async () => {
const response = await POST(validRequest({ occurredAt: "2026-01-01T00:00:00.000Z" }));
expect(response.status).toBe(401);
expect(databaseState.inserts).toHaveLength(0);
});
it("authenticates and atomically records a confirmed account connection", async () => {
const response = await POST(validRequest());
expect(response.status).toBe(204);
expect(databaseState.inserts).toEqual(expect.arrayContaining([
expect.objectContaining({ requestId: "8dd9dbdc-020a-4077-983c-77747522de8f", serverId: "velocity-main" }),
expect.objectContaining({
type: "games.minecraft.account-manager.game.player.connected",
subject: "minecraft-account/aaaaaaaa-aaaa-4aaa-8aaa-aaaaaaaaaaaa",
actorUserId: "bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb",
}),
]));
});
it("rejects replayed request IDs", async () => {
databaseState.replay = true;
const response = await POST(validRequest());
expect(response.status).toBe(409);
await expect(response.json()).resolves.toMatchObject({
type: "urn:error:replayed-velocity-connection-request",
status: 409,
});
});
it("does not record an event for an unknown account", async () => {
databaseState.account = null;
const response = await POST(validRequest());
expect(response.status).toBe(404);
expect(databaseState.inserts).toHaveLength(1);
});
});
@@ -0,0 +1,142 @@
import { randomUUID } from "node:crypto";
import { isRequestTimestampFresh, verifyHashedToken } from "@minecraft-account-manager/auth";
import { problemDetails, velocityConnectionRequestSchema } from "@minecraft-account-manager/contracts";
import { events, minecraftAccounts, pluginCredentials, pluginRequests } from "@minecraft-account-manager/database";
import { and, eq, isNull, lt } from "drizzle-orm";
import { NextResponse } from "next/server";
import { db } from "@/lib/database";
import { isUniqueConstraintViolation } from "@/lib/database-errors";
import { logger } from "@/lib/logger";
import { problemInstance, problemResponse } from "@/lib/problem-response";
const MAX_CLOCK_SKEW_MS = 45_000;
function methodNotAllowed(request: Request) {
const response = problemResponse(problemDetails(
"urn:error:method-not-allowed",
"Method not allowed",
405,
"This endpoint only accepts POST requests.",
problemInstance(request),
));
response.headers.set("allow", "POST");
return response;
}
export const GET = methodNotAllowed;
export const PUT = methodNotAllowed;
export const PATCH = methodNotAllowed;
export const DELETE = methodNotAllowed;
export async function POST(request: Request) {
const instance = problemInstance(request);
const authorization = request.headers.get("authorization") ?? "";
const token = authorization.startsWith("Bearer ") ? authorization.slice(7).trim() : "";
if (!token) return problemResponse(problemDetails(
"urn:error:unauthorized",
"Unauthorized",
401,
"A valid Velocity server credential is required.",
instance,
));
const mediaType = request.headers.get("content-type")?.split(";", 1)[0]?.trim().toLowerCase();
if (mediaType !== "application/json") return problemResponse(problemDetails(
"urn:error:unsupported-media-type",
"Unsupported media type",
415,
"Velocity connection reports must use application/json.",
instance,
));
const parsed = velocityConnectionRequestSchema.safeParse(await request.json().catch(() => null));
if (!parsed.success) return problemResponse(problemDetails(
"urn:error:invalid-velocity-connection-request",
"Invalid Velocity connection report",
400,
"The request body does not match the required Velocity connection contract.",
instance,
{ issues: parsed.error.issues.map((issue) => ({ path: issue.path.join("."), message: issue.message, code: issue.code })) },
));
const input = parsed.data;
const occurredAt = new Date(input.occurredAt);
if (!isRequestTimestampFresh(occurredAt, new Date(), MAX_CLOCK_SKEW_MS)) return problemResponse(problemDetails(
"urn:error:expired-velocity-connection-request",
"Expired Velocity connection report",
401,
"The request timestamp is outside the allowed clock-skew window.",
instance,
));
const [credential] = await db
.select({ secretHash: pluginCredentials.secretHash })
.from(pluginCredentials)
.where(and(eq(pluginCredentials.serverId, input.serverId), isNull(pluginCredentials.revokedAt)))
.limit(1);
if (!credential || !verifyHashedToken(token, credential.secretHash)) return problemResponse(problemDetails(
"urn:error:unauthorized",
"Unauthorized",
401,
"The Velocity server credential is invalid or revoked.",
instance,
));
try {
const recorded = await db.transaction(async (tx) => {
await tx.delete(pluginRequests).where(lt(pluginRequests.expiresAt, new Date()));
await tx.insert(pluginRequests).values({
requestId: input.requestId,
serverId: input.serverId,
receivedAt: new Date(),
expiresAt: new Date(Date.now() + 5 * 60_000),
});
const [account] = await tx
.select({ id: minecraftAccounts.id, userId: minecraftAccounts.userId })
.from(minecraftAccounts)
.where(and(eq(minecraftAccounts.minecraftUuid, input.minecraftUuid), isNull(minecraftAccounts.deletedAt)))
.limit(1);
if (!account) return false;
await tx.insert(events).values({
id: randomUUID(),
source: `/velocity/${input.serverId}`,
type: "games.minecraft.account-manager.game.player.connected",
subject: `minecraft-account/${account.id}`,
time: occurredAt,
actorUserId: account.userId,
correlationId: input.requestId,
data: {
username: input.username,
minecraftUuid: input.minecraftUuid,
serverId: input.serverId,
},
});
return true;
});
if (!recorded) return problemResponse(problemDetails(
"urn:error:unknown-minecraft-account",
"Unknown Minecraft account",
404,
"The connected Minecraft account is no longer registered.",
instance,
));
return new NextResponse(null, { status: 204 });
} catch (error) {
if (isUniqueConstraintViolation(error, "plugin_requests_pkey")) return problemResponse(problemDetails(
"urn:error:replayed-velocity-connection-request",
"Velocity request replayed",
409,
"This Velocity request ID has already been processed.",
instance,
));
logger.error({ err: error, event: "velocity.connection_report_failed" }, "Failed to record a confirmed Velocity connection");
return problemResponse(problemDetails(
"urn:error:service-unavailable",
"Service unavailable",
503,
"The connection report could not be recorded.",
instance,
));
}
}
+16
View File
@@ -1,3 +1,4 @@
@import "leaflet/dist/leaflet.css";
@import "tailwindcss"; @import "tailwindcss";
@theme inline { @theme inline {
@@ -58,6 +59,21 @@ body {
transform: translateY(0); transform: translateY(0);
} }
svg a:hover .map-marker,
svg a:focus .map-marker {
stroke: var(--ink);
stroke-width: 6px;
}
.map-marker-tooltip {
opacity: 0;
}
.map-marker-link:hover .map-marker-tooltip,
.map-marker-link:focus .map-marker-tooltip {
opacity: 1;
}
::selection { ::selection {
background: var(--accent); background: var(--accent);
color: var(--panel); color: var(--panel);
@@ -0,0 +1,82 @@
"use client";
import type { ReactNode } from "react";
import { useEffect, useRef, useState } from "react";
import type { UserMapLocation } from "./user-world-map";
export function MapViewToggle({ locations, children }: { locations: UserMapLocation[]; children: ReactNode }) {
const [view, setView] = useState<"overview" | "interactive">("overview");
return (
<div className="mt-6">
<div aria-label="Map view" className="flex flex-wrap gap-2" role="group">
<button aria-controls="map-overview-panel" aria-pressed={view === "overview"} className={`border px-4 py-2 font-mono text-[10px] font-bold uppercase ${view === "overview" ? "border-ink bg-ink text-canvas" : "border-line"}`} id="map-overview-tab" onClick={() => setView("overview")} type="button">World overview</button>
<button aria-controls="map-interactive-panel" aria-pressed={view === "interactive"} className={`border px-4 py-2 font-mono text-[10px] font-bold uppercase ${view === "interactive" ? "border-ink bg-ink text-canvas" : "border-line"}`} id="map-interactive-tab" onClick={() => setView("interactive")} type="button">Interactive OpenStreetMap</button>
</div>
<p className="mt-2 max-w-2xl text-[10px] leading-4 text-muted">Selecting the interactive view requests map tiles from OpenStreetMap, which receives your IP address, the portal origin, and the geographic area being viewed.</p>
<div aria-labelledby="map-overview-tab" hidden={view !== "overview"} id="map-overview-panel" role="region">{children}</div>
<div aria-labelledby="map-interactive-tab" hidden={view !== "interactive"} id="map-interactive-panel" role="region">
{view === "interactive" && <InteractiveMap locations={locations} />}
</div>
</div>
);
}
function InteractiveMap({ locations }: { locations: UserMapLocation[] }) {
const container = useRef<HTMLDivElement>(null);
useEffect(() => {
if (!container.current) return;
let cancelled = false;
let cleanup = () => {};
void import("leaflet").then((leaflet) => {
if (cancelled || !container.current) return;
const map = leaflet.map(container.current, { minZoom: 1, worldCopyJump: true }).setView([20, 0], 2);
leaflet.tileLayer("https://tile.openstreetmap.org/{z}/{x}/{y}.png", {
attribution: '&copy; <a href="https://www.openstreetmap.org/copyright">OpenStreetMap contributors</a>',
maxZoom: 19,
referrerPolicy: "strict-origin-when-cross-origin",
}).addTo(map);
const bounds: [number, number][] = [];
for (const user of locations) {
const marker = leaflet.circleMarker([user.latitude, user.longitude], {
radius: 8,
color: "#eee8d8",
weight: 3,
fillColor: "#a32f1b",
fillOpacity: 1,
}).addTo(map);
const tooltip = document.createElement("span");
tooltip.textContent = `${user.nickname} · ${user.location}`;
marker.bindTooltip(tooltip, { direction: "top" });
const userPath = `/admin/users/${user.userId}`;
marker.on("click", () => window.location.assign(userPath));
const element = marker.getElement();
element?.setAttribute("aria-label", `${user.nickname}, ${user.location}`);
element?.setAttribute("role", "link");
element?.setAttribute("tabindex", "0");
element?.addEventListener("focus", () => marker.openTooltip());
element?.addEventListener("blur", () => marker.closeTooltip());
element?.addEventListener("keydown", (event) => {
const keyboardEvent = event as KeyboardEvent;
if (keyboardEvent.key === "Enter" || keyboardEvent.key === " ") {
keyboardEvent.preventDefault();
window.location.assign(userPath);
}
});
bounds.push([user.latitude, user.longitude]);
}
if (bounds.length) map.fitBounds(bounds, { padding: [40, 40], maxZoom: 6 });
cleanup = () => map.remove();
});
return () => {
cancelled = true;
cleanup();
};
}, [locations]);
return <div aria-label="Interactive map of latest approximate user locations" className="mt-3 h-[32rem] max-h-[70vh] min-h-80 border border-line" ref={container} role="region" />;
}
@@ -0,0 +1,47 @@
import { renderToStaticMarkup } from "react-dom/server";
import { describe, expect, it } from "vitest";
import { UserWorldMap } from "./user-world-map";
describe("UserWorldMap", () => {
it("renders an accessible linked marker, text fallback, and open-data attribution", () => {
const markup = renderToStaticMarkup(<UserWorldMap locations={[{
userId: "11111111-1111-4111-8111-111111111111",
name: "Dani",
discordUsername: "dani",
nickname: "Dani (Steve)",
latitude: 37.4056,
longitude: -122.0775,
location: "Mountain View, California, US",
classification: "clear",
source: "game",
observedAt: new Date("2026-08-01T12:00:00Z"),
}]} unavailableCount={2} />);
expect(markup).toContain('role="group"');
expect(markup).toContain('class="map-marker-target"');
expect(markup).toContain("Latest approximate location for registered users");
expect(markup).toContain('href="/admin/users/11111111-1111-4111-8111-111111111111"');
expect(markup).toContain("Dani (Steve)");
expect(markup).toContain("Mountain View, California, US");
expect(markup).toContain("World overview");
expect(markup).toContain("Interactive OpenStreetMap");
expect(markup).toContain("OpenStreetMap, which receives your IP address");
expect(markup).toContain("map-marker-tooltip");
expect(markup).toContain('id="map-overview-panel"');
expect(markup).not.toContain("tile.openstreetmap.org");
expect(markup).toContain("Natural Earth, public domain");
expect(markup).toContain("2 without coordinates");
const countryPaths = [...markup.matchAll(/<path d="([^"]+)"/g)].map((match) => match[1] ?? "");
expect(countryPaths.length).toBeGreaterThan(100);
for (const path of countryPaths) {
const subpaths = path.split("M").slice(1);
for (const subpath of subpaths) {
const xCoordinates = [...subpath.matchAll(/(?:^|L)(-?\d+(?:\.\d+)?),/g)].map((match) => Number(match[1]));
for (let index = 1; index < xCoordinates.length; index += 1) {
expect(Math.abs(xCoordinates[index]! - xCoordinates[index - 1]!)).toBeLessThan(500);
}
}
}
});
});
@@ -0,0 +1,95 @@
import type { FeatureCollection } from "geojson";
import type { GeometryCollection, Topology } from "topojson-specification";
import { geoEquirectangular, geoPath } from "d3-geo";
import { feature } from "topojson-client";
import countriesTopologyJson from "world-atlas/countries-110m.json";
import Link from "next/link";
import { MapViewToggle } from "./map-view-toggle";
const WIDTH = 1_000;
const HEIGHT = 500;
const topology = countriesTopologyJson as unknown as Topology<{ countries: GeometryCollection }>;
const countries = feature(topology, topology.objects.countries) as FeatureCollection;
const projection = geoEquirectangular().fitExtent([[1, 1], [WIDTH - 1, HEIGHT - 1]], { type: "Sphere" });
const countryPath = geoPath(projection);
export interface UserMapLocation {
userId: string;
name: string;
discordUsername: string;
nickname: string;
latitude: number;
longitude: number;
location: string;
classification: string;
source: string;
observedAt: Date;
}
export function UserWorldMap({ locations, unavailableCount }: { locations: UserMapLocation[]; unavailableCount: number }) {
return (
<section className="mt-8 border border-line bg-panel p-5 shadow-[8px_8px_0_var(--color-shadow)] sm:p-7">
<div className="flex flex-col gap-4 sm:flex-row sm:items-end sm:justify-between">
<div>
<p className="font-mono text-[9px] font-bold uppercase tracking-widest text-muted">Latest known location</p>
<h2 className="mt-2 font-display text-3xl font-black uppercase">Community world</h2>
</div>
<p className="max-w-sm text-xs leading-5 text-muted">{locations.length} mapped · {unavailableCount} without coordinates. Locations are approximate IP intelligence, not precise device positions.</p>
</div>
<MapViewToggle locations={locations}>
<div className="mt-3 overflow-hidden border border-line bg-[#b9d4d1]">
<svg aria-labelledby="user-world-map-title user-world-map-description" className="h-auto w-full" role="group" viewBox={`0 0 ${WIDTH} ${HEIGHT}`}>
<title id="user-world-map-title">Latest approximate location for registered users</title>
<desc id="user-world-map-description">An open-data world map with one linked marker for every user whose latest geolocated observation has valid coordinates. A complete text list follows.</desc>
<rect fill="#b9d4d1" height={HEIGHT} width={WIDTH} />
<g aria-hidden="true" fill="var(--canvas)" stroke="var(--line)" strokeWidth="0.7">
{countries.features.map((country, index) => {
const path = countryPath(country);
return path ? <path d={path} key={country.id ?? index} /> : null;
})}
</g>
<g>
{locations.map((user) => {
const projected = projection([user.longitude, user.latitude]);
if (!projected) return null;
const x = Math.min(WIDTH - 14, Math.max(14, projected[0]));
const y = Math.min(HEIGHT - 14, Math.max(14, projected[1]));
const tooltipWidth = Math.min(260, Math.max(110, user.nickname.length * 8 + 24));
const tooltipX = Math.min(WIDTH - tooltipWidth - 4, Math.max(4, x - tooltipWidth / 2));
const tooltipY = y > 46 ? y - 38 : y + 18;
return (
<a aria-label={`${user.nickname}, ${user.location}, last seen ${user.observedAt.toISOString()}`} className="map-marker-link" href={`/admin/users/${user.userId}`} key={user.userId}>
<circle className="map-marker-target" cx={x} cy={y} fill="none" pointerEvents="stroke" r="7" stroke="transparent" strokeWidth="24" vectorEffect="non-scaling-stroke">
<title>{user.nickname} · {user.location} · {user.classification}</title>
</circle>
<circle className="map-marker" cx={x} cy={y} fill="var(--accent)" pointerEvents="none" r="7" stroke="var(--panel)" strokeWidth="3" />
<g aria-hidden="true" className="map-marker-tooltip" pointerEvents="none">
<rect fill="var(--ink)" height="28" rx="2" width={tooltipWidth} x={tooltipX} y={tooltipY} />
<text dominantBaseline="middle" fill="var(--panel)" fontFamily="var(--font-mono)" fontSize="12" textAnchor="middle" x={tooltipX + tooltipWidth / 2} y={tooltipY + 14}>{user.nickname}</text>
</g>
</a>
);
})}
</g>
</svg>
</div>
</MapViewToggle>
<p className="mt-2 text-right font-mono text-[9px] text-muted">Map boundaries: Natural Earth, public domain</p>
<details className="mt-5 border-t border-line pt-4">
<summary className="w-fit cursor-pointer font-mono text-[10px] font-bold uppercase underline underline-offset-4">View accessible location list</summary>
<div className="mt-4 overflow-x-auto">
<table className="w-full min-w-[680px] border-collapse text-left text-xs">
<caption className="sr-only">Latest approximate registered-user locations</caption>
<thead className="border-b border-line font-mono text-[9px] uppercase tracking-wider text-muted"><tr><th className="py-3 pr-4" scope="col">User</th><th className="p-3" scope="col">Location</th><th className="p-3" scope="col">Network</th><th className="p-3" scope="col">Source</th><th className="py-3 pl-4" scope="col">Last observed</th></tr></thead>
<tbody className="divide-y divide-line">
{locations.map((user) => <tr key={user.userId}><th className="py-3 pr-4 text-left" scope="row"><Link className="font-mono font-bold underline underline-offset-4" href={`/admin/users/${user.userId}`}>{user.nickname}</Link><span className="mt-1 block font-mono text-[9px] font-normal text-muted">@{user.discordUsername}</span></th><td className="p-3">{user.location}</td><td className="p-3 font-mono uppercase">{user.classification}</td><td className="p-3">{user.source}</td><td className="py-3 pl-4 font-mono text-[9px]"><time dateTime={user.observedAt.toISOString()}>{user.observedAt.toISOString()}</time></td></tr>)}
{!locations.length && <tr><td className="py-6 text-muted" colSpan={5}>No user observations currently include valid coordinates.</td></tr>}
</tbody>
</table>
</div>
</details>
</section>
);
}
+17 -1
View File
@@ -1,5 +1,5 @@
import { describe, expect, it } from "vitest"; import { describe, expect, it } from "vitest";
import { fillDailySeries } from "./admin-metrics"; import { fillDailySeries, mergeRiskActivity } from "./admin-metrics";
describe("admin dashboard metrics", () => { describe("admin dashboard metrics", () => {
it("fills missing UTC registration days with zero", () => { it("fills missing UTC registration days with zero", () => {
@@ -13,4 +13,20 @@ describe("admin dashboard metrics", () => {
{ day: "2026-08-01", count: 1 }, { day: "2026-08-01", count: 1 },
]); ]);
}); });
it("merges complete per-user VPN summaries with each user's latest observation", () => {
const latest = [
{ userId: "user-2", classification: "tor", observedAt: new Date("2026-08-01T11:00:00Z") },
{ userId: "user-1", classification: "proxy", observedAt: new Date("2026-08-01T12:00:00Z") },
];
const summaries = [
{ userId: "user-1", count: 2000, classifications: ["proxy", "vpn"], sources: ["game", "web"] },
{ userId: "user-2", count: 1, classifications: ["tor"], sources: ["web"] },
];
expect(mergeRiskActivity(latest, summaries)).toEqual([
expect.objectContaining({ userId: "user-1", count: 2000, classification: "proxy", classifications: ["proxy", "vpn"], sources: ["game", "web"] }),
expect.objectContaining({ userId: "user-2", count: 1, classification: "tor" }),
]);
});
}); });
+13
View File
@@ -3,6 +3,19 @@ export interface DailyCount {
count: number; count: number;
} }
export function mergeRiskActivity<
T extends { userId: string; observedAt: Date },
S extends { userId: string | null },
>(latestRows: T[], summaryRows: S[]) {
const summaries = new Map(summaryRows.flatMap((summary) => summary.userId ? [[summary.userId, summary] as const] : []));
return latestRows
.flatMap((activity) => {
const summary = summaries.get(activity.userId);
return summary ? [{ ...activity, ...summary }] : [];
})
.sort((left, right) => right.observedAt.getTime() - left.observedAt.getTime());
}
export function fillDailySeries(rows: DailyCount[], end: Date, days: number) { export function fillDailySeries(rows: DailyCount[], end: Date, days: number) {
const counts = new Map(rows.map((row) => [row.day, Number(row.count)])); const counts = new Map(rows.map((row) => [row.day, Number(row.count)]));
const endDay = new Date(Date.UTC(end.getUTCFullYear(), end.getUTCMonth(), end.getUTCDate())); const endDay = new Date(Date.UTC(end.getUTCFullYear(), end.getUTCMonth(), end.getUTCDate()));
+1
View File
@@ -10,6 +10,7 @@ describe("event filters", () => {
it("classifies events into operator-friendly views", () => { it("classifies events into operator-friendly views", () => {
expect(eventCategory("games.minecraft.account-manager.group.deleted")).toBe("groups"); expect(eventCategory("games.minecraft.account-manager.group.deleted")).toBe("groups");
expect(eventCategory("games.minecraft.account-manager.game.login.denied")).toBe("admission"); expect(eventCategory("games.minecraft.account-manager.game.login.denied")).toBe("admission");
expect(eventCategory("games.minecraft.account-manager.game.player.connected")).toBe("admission");
expect(eventCategory("games.minecraft.account-manager.network.vpn-blocked")).toBe("security"); expect(eventCategory("games.minecraft.account-manager.network.vpn-blocked")).toBe("security");
expect(eventCategory("games.minecraft.account-manager.auth.magic-link.consumed")).toBe("security"); expect(eventCategory("games.minecraft.account-manager.auth.magic-link.consumed")).toBe("security");
expect(eventCategory("games.minecraft.account-manager.discord.nickname.updated")).toBe("identity"); expect(eventCategory("games.minecraft.account-manager.discord.nickname.updated")).toBe("identity");
+1 -1
View File
@@ -4,7 +4,7 @@ export type EventCategory = (typeof eventCategoryValues)[number];
export function eventCategory(type: string): Exclude<EventCategory, "all"> { export function eventCategory(type: string): Exclude<EventCategory, "all"> {
if (type.includes(".group.")) return "groups"; if (type.includes(".group.")) return "groups";
if (type.includes(".network.") || type.includes(".auth.") || type.includes("authentication") || type.includes("replay")) return "security"; if (type.includes(".network.") || type.includes(".auth.") || type.includes("authentication") || type.includes("replay")) return "security";
if (type.includes(".game.login.")) return "admission"; if (type.includes(".game.")) return "admission";
if (type.includes(".discord.") || type.includes(".user.") || type.includes("minecraft-account")) return "identity"; if (type.includes(".discord.") || type.includes(".user.") || type.includes("minecraft-account")) return "identity";
return "operations"; return "operations";
} }
@@ -0,0 +1,31 @@
import { describe, expect, it } from "vitest";
import { parseUserLocation, projectWorldPoint } from "./user-location-map";
describe("user location map", () => {
it("extracts a valid approximate location from cached IP intelligence", () => {
expect(parseUserLocation({
classification: "clear",
location: {
city: "Mountain View",
region: "California",
countryCode: "US",
latitude: 37.4056,
longitude: -122.0775,
},
})).toEqual({
latitude: 37.4056,
longitude: -122.0775,
label: "Mountain View, California, US",
});
});
it("rejects missing and out-of-range coordinates", () => {
expect(parseUserLocation({ location: { latitude: 91, longitude: 0 } })).toBeNull();
expect(parseUserLocation({ location: { city: "Unknown" } })).toBeNull();
});
it("projects longitude and latitude into an equirectangular SVG", () => {
expect(projectWorldPoint(0, 0, 800, 400)).toEqual({ x: 400, y: 200 });
expect(projectWorldPoint(90, 180, 800, 400)).toEqual({ x: 800, y: 0 });
});
});
+41
View File
@@ -0,0 +1,41 @@
type UnknownMap = Record<string, unknown>;
function objectValue(value: unknown): UnknownMap | null {
return value && typeof value === "object" && !Array.isArray(value)
? value as UnknownMap
: null;
}
function coordinate(value: unknown) {
if (typeof value === "number" && Number.isFinite(value)) return value;
if (typeof value === "string" && value.trim() && Number.isFinite(Number(value))) return Number(value);
return null;
}
export interface ParsedUserLocation {
latitude: number;
longitude: number;
label: string;
}
export function parseUserLocation(value: unknown): ParsedUserLocation | null {
const intelligence = objectValue(value);
const location = objectValue(intelligence?.location);
if (!location) return null;
const latitude = coordinate(location.latitude);
const longitude = coordinate(location.longitude);
if (latitude === null || longitude === null || latitude < -90 || latitude > 90 || longitude < -180 || longitude > 180) {
return null;
}
const label = [location.city, location.region, location.countryCode ?? location.country]
.filter((part): part is string => typeof part === "string" && part.trim().length > 0)
.join(", ");
return { latitude, longitude, label: label || "Approximate location unavailable" };
}
export function projectWorldPoint(latitude: number, longitude: number, width: number, height: number) {
return {
x: ((longitude + 180) / 360) * width,
y: ((90 - latitude) / 180) * height,
};
}
+1 -1
View File
@@ -31,7 +31,7 @@ This OKF bundle is the product record for implemented and proposed behavior. Sto
* [US-015 — Deploy and operate securely](us-015-platform-operations.md) - Operators have reproducible builds, migrations, credentials, and security controls. * [US-015 — Deploy and operate securely](us-015-platform-operations.md) - Operators have reproducible builds, migrations, credentials, and security controls.
* [US-016 — Build and publish versioned releases](us-016-automated-releases.md) - Gitea Actions publish the Velocity JAR and web and migration images. * [US-016 — Build and publish versioned releases](us-016-automated-releases.md) - Gitea Actions publish the Velocity JAR and web and migration images.
* [US-017 — Control admission with groups](us-017-group-access.md) - Each user has one effective group that explicitly controls Minecraft access. * [US-017 — Control admission with groups](us-017-group-access.md) - Each user has one effective group that explicitly controls Minecraft access.
* [US-018 — Monitor community account activity](us-018-admin-dashboard.md) - Administrators review registrations, monthly activity, denials, and risky networks. * [US-018 — Monitor community account activity](us-018-admin-dashboard.md) - Administrators review daily users, confirmed connections, locations, denials, and risky networks.
# Tracking # Tracking
+6
View File
@@ -1,7 +1,13 @@
# Design Update Log # Design Update Log
## 2026-08-02
* **Refine**: Replace registration counts with daily active users, collapse enriched VPN activity per user, add opt-in OpenStreetMap zoom, show managed nickname tooltips, and measure active Minecraft accounts from confirmed Velocity connections.
* **Governance**: Require user review and explicit confirmation of relevant OKF story changes before future implementation work.
## 2026-08-01 ## 2026-08-01
* **Extend**: Plot each user's latest approximate location on an accessible, server-rendered Natural Earth world map in the operations dashboard.
* **Refine**: Make group assignment exclusive with default fallback, add group deletion, automatically synchronize Discord nicknames with status notices, expose filterable event details, add an SSR operations dashboard, and improve accessibility. * **Refine**: Make group assignment exclusive with default fallback, add group deletion, automatically synchronize Discord nicknames with status notices, expose filterable event details, add an SSR operations dashboard, and improve accessibility.
* **Extend**: Add SoMC Portal branding, live Discord identity details, admin guild configuration visibility, and fail-closed group-based Minecraft admission. * **Extend**: Add SoMC Portal branding, live Discord identity details, admin guild configuration visibility, and fail-closed group-based Minecraft admission.
* **Refine**: Group repeated access networks, confirm linked Discord nickname changes before mutation, and add DMG Games sponsorship attribution. * **Refine**: Group repeated access networks, confirm linked Discord nickname changes before mutation, and add DMG Games sponsorship attribution.
+2 -1
View File
@@ -3,7 +3,7 @@ type: User Story
title: Block account additions from anonymized networks title: Block account additions from anonymized networks
description: User Minecraft-account additions fail closed for VPN, proxy, Tor, or unknown IP classifications. description: User Minecraft-account additions fail closed for VPN, proxy, Tor, or unknown IP classifications.
tags: [security, vpn, proxy, minecraft] tags: [security, vpn, proxy, minecraft]
timestamp: 2026-08-01T18:43:58Z timestamp: 2026-08-02T00:12:32Z
story_id: US-008 story_id: US-008
status: verified status: verified
--- ---
@@ -21,6 +21,7 @@ As an operator, I want account additions blocked from anonymized networks, so th
- [x] Blocked users receive a clear recovery message without provider internals. - [x] Blocked users receive a clear recovery message without provider internals.
- [x] Blocked and classification-unavailable attempts create distinct audit events with safe intelligence details. - [x] Blocked and classification-unavailable attempts create distinct audit events with safe intelligence details.
- [x] Administrative account additions remain available as an authorized recovery path. - [x] Administrative account additions remain available as an authorized recovery path.
- [x] Administrators see enriched risky-network observations collapsed to one latest summary per user.
# Implementation # Implementation
+4 -1
View File
@@ -3,7 +3,7 @@ type: User Story
title: Enforce registration at the Velocity proxy title: Enforce registration at the Velocity proxy
description: Online-mode Java connections are admitted only after a fail-closed account-manager decision. description: Online-mode Java connections are admitted only after a fail-closed account-manager decision.
tags: [minecraft, velocity, whitelist, security] tags: [minecraft, velocity, whitelist, security]
timestamp: 2026-08-01T23:10:59Z timestamp: 2026-08-02T00:12:32Z
story_id: US-009 story_id: US-009
status: verified status: verified
--- ---
@@ -25,11 +25,14 @@ As a registered player, I want the Velocity proxy to recognize my approved Java
- [x] Registered players are allowed only when their single effective group has access enabled; explicit assignments override the default group. - [x] Registered players are allowed only when their single effective group has access enabled; explicit assignments override the default group.
- [x] Unknown players, group-disabled players, API failures, malformed responses, and unauthorized requests fail closed with registration guidance. - [x] Unknown players, group-disabled players, API failures, malformed responses, and unauthorized requests fail closed with registration guidance.
- [x] The plugin records the real Velocity connection IP and supports Java Edition online mode only. - [x] The plugin records the real Velocity connection IP and supports Java Edition online mode only.
- [x] After admission, Velocity reports `PostLoginEvent` as best-effort authenticated telemetry without disconnecting an admitted player when reporting fails.
- [x] Confirmed-connection reports use fresh timestamps and database replay protection.
# Implementation # Implementation
- [`plugins/velocity`](../plugins/velocity) - [`plugins/velocity`](../plugins/velocity)
- [`apps/web/src/app/api/velocity/access/route.ts`](../apps/web/src/app/api/velocity/access/route.ts) - [`apps/web/src/app/api/velocity/access/route.ts`](../apps/web/src/app/api/velocity/access/route.ts)
- [`apps/web/src/app/api/velocity/connection/route.ts`](../apps/web/src/app/api/velocity/connection/route.ts)
- [`packages/contracts/src/index.ts`](../packages/contracts/src/index.ts) - [`packages/contracts/src/index.ts`](../packages/contracts/src/index.ts)
- [`packages/database/src/schema.ts`](../packages/database/src/schema.ts) - [`packages/database/src/schema.ts`](../packages/database/src/schema.ts)
+2 -2
View File
@@ -3,7 +3,7 @@ type: User Story
title: Preserve a CloudEvents-style audit trail title: Preserve a CloudEvents-style audit trail
description: Authentication, UI, account, Discord, network, and game actions create searchable immutable-style events. description: Authentication, UI, account, Discord, network, and game actions create searchable immutable-style events.
tags: [audit, cloudevents, security, events] tags: [audit, cloudevents, security, events]
timestamp: 2026-08-01T23:10:59Z timestamp: 2026-08-02T00:12:32Z
story_id: US-010 story_id: US-010
status: verified status: verified
--- ---
@@ -16,7 +16,7 @@ As an operator, I want security and identity activity recorded consistently, so
- [x] Events preserve CloudEvents-style ID, specification version, source, type, subject, time, content type, and JSON data. - [x] Events preserve CloudEvents-style ID, specification version, source, type, subject, time, content type, and JSON data.
- [x] Events can include user actor, IP address, and correlation ID. - [x] Events can include user actor, IP address, and correlation ID.
- [x] Portal access, magic-link creation and consumption, account changes, nickname changes, VPN blocks, and game decisions are recorded. - [x] Portal access, magic-link creation and consumption, account changes, nickname changes, VPN blocks, game decisions, and confirmed proxy connections are recorded.
- [x] Username changes learned from Velocity create their own event. - [x] Username changes learned from Velocity create their own event.
- [x] Administrative actions include the acting SSO identity in event data. - [x] Administrative actions include the acting SSO identity in event data.
- [x] Events can be filtered by operator-friendly view and selected event types globally and from an individual user view. - [x] Events can be filtered by operator-friendly view and selected event types globally and from an individual user view.
+16 -8
View File
@@ -1,9 +1,9 @@
--- ---
type: User Story type: User Story
title: Monitor community account activity title: Monitor community account activity
description: Administrators use a server-rendered dashboard to review registrations, monthly activity, denials, and risky networks. description: Administrators use a server-rendered dashboard to review daily activity, confirmed connections, locations, denials, and risky networks.
tags: [admin, dashboard, metrics, security, ssr] tags: [admin, dashboard, metrics, security, maps, ssr]
timestamp: 2026-08-01T23:10:59Z timestamp: 2026-08-02T00:12:32Z
story_id: US-018 story_id: US-018
status: verified status: verified
--- ---
@@ -15,13 +15,17 @@ As an administrator, I want an operational dashboard of account and game activit
# Acceptance Criteria # Acceptance Criteria
- [x] The administrator landing page is a dashboard rather than a settings form. - [x] The administrator landing page is a dashboard rather than a settings form.
- [x] The dashboard graphs new registered users by UTC day for the previous 14 days. - [x] A server-rendered Natural Earth overview plots each user's latest observation with valid approximate coordinates.
- [x] Administrators can opt into a zoomable OpenStreetMap view without removing the default overview.
- [x] OpenStreetMap tiles load only after the administrator selects the interactive view and retain required attribution.
- [x] Map markers show the managed Discord nickname on hover or keyboard focus, link to user records, and have an accessible text-table equivalent.
- [x] The dashboard graphs distinct daily active users by UTC day for the previous 14 days with understandable date labels.
- [x] Monthly active users count distinct users observed through portal or game activity in the previous 30 days. - [x] Monthly active users count distinct users observed through portal or game activity in the previous 30 days.
- [x] Monthly active Minecraft accounts count distinct linked accounts observed in the previous 30 days. - [x] Monthly active Minecraft accounts count distinct accounts with a confirmed Velocity post-login connection in the previous 30 days.
- [x] The dashboard shows login denials from the previous 24 hours. - [x] The dashboard shows login denials from the previous 24 hours.
- [x] Recent VPN, proxy, and Tor observations link to affected user records. - [x] Recent VPN, proxy, and Tor observations use enriched ProxyCheck classifications, collapse repeated rows per user, and show counts, sources, and latest activity.
- [x] The graph includes an accessible title, description, point labels, and textual values. - [x] The graph includes an accessible title, description, point labels, and textual values.
- [x] Dashboard queries and rendering execute server-side without client-side data fetching. - [x] Dashboard queries and initial rendering execute server-side; only the opt-in pan-and-zoom map hydrates client-side.
- [x] Deployment-managed guild settings and denial messaging remain available on a dedicated settings page. - [x] Deployment-managed guild settings and denial messaging remain available on a dedicated settings page.
# Implementation # Implementation
@@ -29,10 +33,14 @@ As an administrator, I want an operational dashboard of account and game activit
- [`apps/web/src/app/admin/(console)/page.tsx`](../apps/web/src/app/admin/%28console%29/page.tsx) - [`apps/web/src/app/admin/(console)/page.tsx`](../apps/web/src/app/admin/%28console%29/page.tsx)
- [`apps/web/src/app/admin/(console)/settings/page.tsx`](../apps/web/src/app/admin/%28console%29/settings/page.tsx) - [`apps/web/src/app/admin/(console)/settings/page.tsx`](../apps/web/src/app/admin/%28console%29/settings/page.tsx)
- [`apps/web/src/lib/admin-metrics.ts`](../apps/web/src/lib/admin-metrics.ts) - [`apps/web/src/lib/admin-metrics.ts`](../apps/web/src/lib/admin-metrics.ts)
- [`apps/web/src/components/user-world-map.tsx`](../apps/web/src/components/user-world-map.tsx)
- [`apps/web/src/components/map-view-toggle.tsx`](../apps/web/src/components/map-view-toggle.tsx)
- [`apps/web/src/lib/user-location-map.ts`](../apps/web/src/lib/user-location-map.ts)
# Validation # Validation
- Missing-day chart behavior is covered by [`apps/web/src/lib/admin-metrics.test.ts`](../apps/web/src/lib/admin-metrics.test.ts). - Missing-day chart behavior and per-user VPN collapsing are covered by [`apps/web/src/lib/admin-metrics.test.ts`](../apps/web/src/lib/admin-metrics.test.ts).
- Coordinate parsing, projection, linked markers, text fallback, and attribution are covered by the user-world-map tests.
- The Next.js production build reports the dashboard and database-backed console pages as dynamic server-rendered routes. - The Next.js production build reports the dashboard and database-backed console pages as dynamic server-rendered routes.
# Related Stories # Related Stories
+4 -2
View File
@@ -1,6 +1,6 @@
# Accessibility review # Accessibility review
Review date: 2026-08-01 Review date: 2026-08-02
## Scope ## Scope
@@ -17,7 +17,9 @@ Player account management, administrator navigation, dashboard metrics and chart
- Added `role=status` with polite announcements for successful nickname changes and `role=alert` with assertive announcements for errors. - Added `role=status` with polite announcements for successful nickname changes and `role=alert` with assertive announcements for errors.
- Added semantic `time` elements for audit and security activity timestamps. - Added semantic `time` elements for audit and security activity timestamps.
- Made event JSON keyboard-focusable so horizontally overflowing content can be reviewed without a pointer. - Made event JSON keyboard-focusable so horizontally overflowing content can be reviewed without a pointer.
- Added an accessible title, description, per-point labels, and textual values to the registration chart. - Added an accessible title, description, date labels, per-point labels, and textual values to the daily-active-user chart.
- Added labelled, keyboard-linked world-map markers plus a complete semantic table equivalent for approximate user locations.
- Added keyboard-operable tabs for the server-rendered overview and opt-in interactive OpenStreetMap view.
- Added explicit new-tab context to the external Discord invite link. - Added explicit new-tab context to the external Discord invite link.
- Kept destructive account and group actions behind native keyboard-operable `details` confirmation disclosures. - Kept destructive account and group actions behind native keyboard-operable `details` confirmation disclosures.
- Allowed administrator navigation to wrap at narrow viewport widths instead of overflowing. - Allowed administrator navigation to wrap at narrow viewport widths instead of overflowing.
+7 -3
View File
@@ -29,12 +29,16 @@ Every error response has media type `application/problem+json` and the shape:
| Type | Status | Meaning | | Type | Status | Meaning |
| --- | ---: | --- | | --- | ---: | --- |
| `urn:error:invalid-velocity-access-request` | 400 | Request JSON does not satisfy the shared Velocity contract | | `urn:error:invalid-velocity-access-request` | 400 | Access request JSON does not satisfy the shared Velocity contract |
| `urn:error:invalid-velocity-connection-request` | 400 | Confirmed-connection JSON does not satisfy the shared Velocity contract |
| `urn:error:unauthorized` | 401 | Velocity bearer credential is missing, invalid, or revoked | | `urn:error:unauthorized` | 401 | Velocity bearer credential is missing, invalid, or revoked |
| `urn:error:expired-velocity-access-request` | 401 | Request timestamp is outside the accepted clock-skew window | | `urn:error:expired-velocity-access-request` | 401 | Access timestamp is outside the accepted clock-skew window |
| `urn:error:expired-velocity-connection-request` | 401 | Connection timestamp is outside the accepted clock-skew window |
| `urn:error:not-found` | 404 | Unknown application-owned API route | | `urn:error:not-found` | 404 | Unknown application-owned API route |
| `urn:error:unknown-minecraft-account` | 404 | Connection telemetry references an inactive or unknown account |
| `urn:error:method-not-allowed` | 405 | The endpoint does not support the requested HTTP method | | `urn:error:method-not-allowed` | 405 | The endpoint does not support the requested HTTP method |
| `urn:error:replayed-velocity-access-request` | 409 | Request ID was already processed | | `urn:error:replayed-velocity-access-request` | 409 | Admission request ID was already processed |
| `urn:error:replayed-velocity-connection-request` | 409 | Confirmed-connection request ID was already processed |
| `urn:error:unsupported-media-type` | 415 | The request does not use `application/json` | | `urn:error:unsupported-media-type` | 415 | The request does not use `application/json` |
| `urn:error:service-unavailable` | 503 | A safe access decision could not be completed | | `urn:error:service-unavailable` | 503 | A safe access decision could not be completed |
+3 -2
View File
@@ -4,7 +4,7 @@
### Web application ### Web application
The Next.js application owns user onboarding, account management, admin configuration and metrics, server-side Minecraft profile validation, sessions, and the HTTP API used by Discord and Velocity integrations. Database-backed portal and console pages are dynamic React Server Components: authentication, queries, filtering, and dashboard aggregation execute on the server and return rendered HTML. The Next.js application owns user onboarding, account management, admin configuration and metrics, server-side Minecraft profile validation, sessions, and the HTTP API used by Discord and Velocity integrations. Database-backed portal and console pages are dynamic React Server Components: authentication, queries, filtering, dashboard aggregation, and the initial Natural Earth user-location map execute on the server and return rendered HTML. Administrators can opt into a hydrated Leaflet/OpenStreetMap view; OSM receives requests only for viewed map tiles, while user marker coordinates remain local to the browser.
User authentication begins with an opaque, short-lived, single-use token created for a Discord user. Only a cryptographic hash of the token is persisted. Admin authentication is a separate Keycloak OIDC flow and requires the `minecraft-account-manager-admin` role. User authentication begins with an opaque, short-lived, single-use token created for a Discord user. Only a cryptographic hash of the token is persisted. Admin authentication is a separate Keycloak OIDC flow and requires the `minecraft-account-manager-admin` role.
@@ -16,7 +16,7 @@ The bot creates private login links in response to `/register` and `/account`. D
Velocity sends the authenticated Java UUID, current username, source IP, server ID, request ID, and occurrence time. The API matches UUID first. Username fallback is allowed only when the stored account has no UUID, after which UUID and canonical username are updated. Velocity sends the authenticated Java UUID, current username, source IP, server ID, request ID, and occurrence time. The API matches UUID first. Username fallback is allowed only when the stored account has no UUID, after which UUID and canonical username are updated.
The decision is fail closed. Unknown players, invalid responses, expired requests, authentication failures, and unavailable API responses are denied with the configured registration message. The admission decision is fail closed. Unknown players, invalid responses, expired requests, authentication failures, and unavailable API responses are denied with the configured registration message. After admission succeeds, `PostLoginEvent` reports a confirmed proxy connection through a fresh, authenticated, replay-protected request. Connection telemetry is best effort and never disconnects an already admitted player.
## Trust boundaries ## Trust boundaries
@@ -52,3 +52,4 @@ Events use reverse-DNS names beneath `games.minecraft.account-manager`, includin
- `games.minecraft.account-manager.network.vpn-blocked` - `games.minecraft.account-manager.network.vpn-blocked`
- `games.minecraft.account-manager.game.login.allowed` - `games.minecraft.account-manager.game.login.allowed`
- `games.minecraft.account-manager.game.login.denied` - `games.minecraft.account-manager.game.login.denied`
- `games.minecraft.account-manager.game.player.connected`
+3 -2
View File
@@ -1,6 +1,6 @@
# Security review # Security review
Review date: 2026-08-01 Review date: 2026-08-02
## Scope ## Scope
@@ -22,11 +22,12 @@ Next.js portal and APIs, Discord bot, PostgreSQL persistence, Keycloak admin aut
- User mutations verify ownership server-side. - User mutations verify ownership server-side.
- Mojang lookup is server-side and targets a fixed host, avoiding client-forged validation and SSRF. - Mojang lookup is server-side and targets a fixed host, avoiding client-forged validation and SSRF.
- Velocity credentials are high-entropy bearer tokens stored only as hashes. - Velocity credentials are high-entropy bearer tokens stored only as hashes.
- Velocity requests have a 45-second clock window and database-unique request IDs for cross-instance replay prevention. - Velocity admission and confirmed-connection requests have a 45-second clock window and database-unique request IDs for cross-instance replay prevention.
- Velocity and its API fail closed. - Velocity and its API fail closed.
- Registered players require an enabled effective group; explicit assignments replace rather than combine with the protected, disabled-by-default `everyone` fallback. - Registered players require an enabled effective group; explicit assignments replace rather than combine with the protected, disabled-by-default `everyone` fallback.
- Group and membership mutations re-check the Keycloak administrator role server-side; destructive group deletion and its audit event commit atomically. - Group and membership mutations re-check the Keycloak administrator role server-side; destructive group deletion and its audit event commit atomically.
- Event filters accept only event types already present in the ledger, and event detail routes remain role-protected. - Event filters accept only event types already present in the ledger, and event detail routes remain role-protected.
- The administrator-only map defaults to bundled Natural Earth boundaries. OpenStreetMap tile requests begin only after an explicit operator opt-in; marker coordinates are not transmitted as data, but the requested tiles disclose the viewed geographic extent along with the administrator's IP and portal origin.
- ORM-parameterized queries are used throughout. - ORM-parameterized queries are used throughout.
- CSP, clickjacking, MIME-sniffing, referrer, and browser-permission headers are configured. - CSP, clickjacking, MIME-sniffing, referrer, and browser-permission headers are configured.
- Forwarded IP headers are ignored unless `TRUST_PROXY=true` is explicitly configured. - Forwarded IP headers are ignored unless `TRUST_PROXY=true` is explicitly configured.
+121 -1
View File
@@ -42,17 +42,24 @@
"@minecraft-account-manager/logging": "*", "@minecraft-account-manager/logging": "*",
"@minecraft-account-manager/minecraft": "*", "@minecraft-account-manager/minecraft": "*",
"@minecraft-account-manager/network": "*", "@minecraft-account-manager/network": "*",
"d3-geo": "^3.1.1",
"drizzle-orm": "^0.45.1", "drizzle-orm": "^0.45.1",
"leaflet": "^1.9.4",
"next": "^16.2.1", "next": "^16.2.1",
"next-auth": "^4.24.13", "next-auth": "^4.24.13",
"react": "^19.2.3", "react": "^19.2.3",
"react-dom": "^19.2.3" "react-dom": "^19.2.3",
"topojson-client": "^3.1.0",
"world-atlas": "^2.0.2"
}, },
"devDependencies": { "devDependencies": {
"@tailwindcss/postcss": "^4.2.1", "@tailwindcss/postcss": "^4.2.1",
"@types/d3-geo": "^3.1.1",
"@types/leaflet": "^1.9.22",
"@types/node": "^25.0.3", "@types/node": "^25.0.3",
"@types/react": "^19.2.14", "@types/react": "^19.2.14",
"@types/react-dom": "^19.2.3", "@types/react-dom": "^19.2.3",
"@types/topojson-client": "^3.1.5",
"eslint": "^9.39.4", "eslint": "^9.39.4",
"eslint-config-next": "^16.2.1", "eslint-config-next": "^16.2.1",
"tailwindcss": "^4.2.1", "tailwindcss": "^4.2.1",
@@ -2724,6 +2731,16 @@
"assertion-error": "^2.0.1" "assertion-error": "^2.0.1"
} }
}, },
"node_modules/@types/d3-geo": {
"version": "3.1.1",
"resolved": "https://registry.npmjs.org/@types/d3-geo/-/d3-geo-3.1.1.tgz",
"integrity": "sha512-65Emv9fQiQQqphLlRkuQ5ypPsOmWPhtBGCMv61JDPEPMvsx+gzhGf74yw1a78xFKPj6zw4AgQICJoQv0vK9M2w==",
"dev": true,
"license": "MIT",
"dependencies": {
"@types/geojson": "*"
}
},
"node_modules/@types/deep-eql": { "node_modules/@types/deep-eql": {
"version": "4.0.2", "version": "4.0.2",
"resolved": "https://registry.npmjs.org/@types/deep-eql/-/deep-eql-4.0.2.tgz", "resolved": "https://registry.npmjs.org/@types/deep-eql/-/deep-eql-4.0.2.tgz",
@@ -2738,6 +2755,13 @@
"dev": true, "dev": true,
"license": "MIT" "license": "MIT"
}, },
"node_modules/@types/geojson": {
"version": "7946.0.16",
"resolved": "https://registry.npmjs.org/@types/geojson/-/geojson-7946.0.16.tgz",
"integrity": "sha512-6C8nqWur3j98U6+lXDfTUWIfgvZU+EumvpHKcYjujKH7woYyLj2sUmff0tRhrqM7BohUw7Pz3ZB1jj2gW9Fvmg==",
"dev": true,
"license": "MIT"
},
"node_modules/@types/json-schema": { "node_modules/@types/json-schema": {
"version": "7.0.15", "version": "7.0.15",
"resolved": "https://registry.npmjs.org/@types/json-schema/-/json-schema-7.0.15.tgz", "resolved": "https://registry.npmjs.org/@types/json-schema/-/json-schema-7.0.15.tgz",
@@ -2752,6 +2776,16 @@
"dev": true, "dev": true,
"license": "MIT" "license": "MIT"
}, },
"node_modules/@types/leaflet": {
"version": "1.9.22",
"resolved": "https://registry.npmjs.org/@types/leaflet/-/leaflet-1.9.22.tgz",
"integrity": "sha512-h3lhECYEKDasG7LFHu+GiHqAvsgLuQvlJvVZzJDGONo3sEL+wUOqSFLnwkZlK0qVxnxbuGFW8iBlJNYs5wgndA==",
"dev": true,
"license": "MIT",
"dependencies": {
"@types/geojson": "*"
}
},
"node_modules/@types/node": { "node_modules/@types/node": {
"version": "25.9.5", "version": "25.9.5",
"resolved": "https://registry.npmjs.org/@types/node/-/node-25.9.5.tgz", "resolved": "https://registry.npmjs.org/@types/node/-/node-25.9.5.tgz",
@@ -2781,6 +2815,27 @@
"@types/react": "^19.2.0" "@types/react": "^19.2.0"
} }
}, },
"node_modules/@types/topojson-client": {
"version": "3.1.5",
"resolved": "https://registry.npmjs.org/@types/topojson-client/-/topojson-client-3.1.5.tgz",
"integrity": "sha512-C79rySTyPxnQNNguTZNI1Ct4D7IXgvyAs3p9HPecnl6mNrJ5+UhvGNYcZfpROYV2lMHI48kJPxwR+F9C6c7nmw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@types/geojson": "*",
"@types/topojson-specification": "*"
}
},
"node_modules/@types/topojson-specification": {
"version": "1.0.5",
"resolved": "https://registry.npmjs.org/@types/topojson-specification/-/topojson-specification-1.0.5.tgz",
"integrity": "sha512-C7KvcQh+C2nr6Y2Ub4YfgvWvWCgP2nOQMtfhlnwsRL4pYmmwzBS7HclGiS87eQfDOU/DLQpX6GEscviaz4yLIQ==",
"dev": true,
"license": "MIT",
"dependencies": {
"@types/geojson": "*"
}
},
"node_modules/@types/ws": { "node_modules/@types/ws": {
"version": "8.18.1", "version": "8.18.1",
"resolved": "https://registry.npmjs.org/@types/ws/-/ws-8.18.1.tgz", "resolved": "https://registry.npmjs.org/@types/ws/-/ws-8.18.1.tgz",
@@ -4084,6 +4139,12 @@
"dev": true, "dev": true,
"license": "MIT" "license": "MIT"
}, },
"node_modules/commander": {
"version": "2.20.3",
"resolved": "https://registry.npmjs.org/commander/-/commander-2.20.3.tgz",
"integrity": "sha512-GpVkmM8vF2vQUkj2LvZmD35JxeJOLCwJ9cUkugyk2nuhbv3+mJvpLYYt+0+USMxE+oj+ey/lJEnhZw75x/OMcQ==",
"license": "MIT"
},
"node_modules/concat-map": { "node_modules/concat-map": {
"version": "0.0.1", "version": "0.0.1",
"resolved": "https://registry.npmjs.org/concat-map/-/concat-map-0.0.1.tgz", "resolved": "https://registry.npmjs.org/concat-map/-/concat-map-0.0.1.tgz",
@@ -4129,6 +4190,30 @@
"dev": true, "dev": true,
"license": "MIT" "license": "MIT"
}, },
"node_modules/d3-array": {
"version": "3.2.4",
"resolved": "https://registry.npmjs.org/d3-array/-/d3-array-3.2.4.tgz",
"integrity": "sha512-tdQAmyA18i4J7wprpYq8ClcxZy3SC31QMeByyCFyRt7BVHdREQZ5lpzoe5mFEYZUWe+oq8HBvk9JjpibyEV4Jg==",
"license": "ISC",
"dependencies": {
"internmap": "1 - 2"
},
"engines": {
"node": ">=12"
}
},
"node_modules/d3-geo": {
"version": "3.1.1",
"resolved": "https://registry.npmjs.org/d3-geo/-/d3-geo-3.1.1.tgz",
"integrity": "sha512-637ln3gXKXOwhalDzinUgY83KzNWZRKbYubaG+fGVuc/dxO64RRljtCTnf5ecMyE1RIdtqpkVcq0IbtU2S8j2Q==",
"license": "ISC",
"dependencies": {
"d3-array": "2.5.0 - 3"
},
"engines": {
"node": ">=12"
}
},
"node_modules/damerau-levenshtein": { "node_modules/damerau-levenshtein": {
"version": "1.0.8", "version": "1.0.8",
"resolved": "https://registry.npmjs.org/damerau-levenshtein/-/damerau-levenshtein-1.0.8.tgz", "resolved": "https://registry.npmjs.org/damerau-levenshtein/-/damerau-levenshtein-1.0.8.tgz",
@@ -5718,6 +5803,15 @@
"node": ">= 0.4" "node": ">= 0.4"
} }
}, },
"node_modules/internmap": {
"version": "2.0.3",
"resolved": "https://registry.npmjs.org/internmap/-/internmap-2.0.3.tgz",
"integrity": "sha512-5Hh7Y1wQbvY5ooGgPbDaL5iYLAPzMTUrjMulskHLH6wnv/A+1q5rgEaiuqEjB+oxGXIVZs1FF+R/KPN3ZSQYYg==",
"license": "ISC",
"engines": {
"node": ">=12"
}
},
"node_modules/ipaddr.js": { "node_modules/ipaddr.js": {
"version": "2.4.0", "version": "2.4.0",
"resolved": "https://registry.npmjs.org/ipaddr.js/-/ipaddr.js-2.4.0.tgz", "resolved": "https://registry.npmjs.org/ipaddr.js/-/ipaddr.js-2.4.0.tgz",
@@ -6332,6 +6426,12 @@
"node": ">=0.10" "node": ">=0.10"
} }
}, },
"node_modules/leaflet": {
"version": "1.9.4",
"resolved": "https://registry.npmjs.org/leaflet/-/leaflet-1.9.4.tgz",
"integrity": "sha512-nxS1ynzJOmOlHp+iL3FyWqK89GtNL8U8rvlMOsQdTTssxZwCXh8N2NB3GDQOL+YR3XnWyZAxwQixURb+FA74PA==",
"license": "BSD-2-Clause"
},
"node_modules/levn": { "node_modules/levn": {
"version": "0.4.1", "version": "0.4.1",
"resolved": "https://registry.npmjs.org/levn/-/levn-0.4.1.tgz", "resolved": "https://registry.npmjs.org/levn/-/levn-0.4.1.tgz",
@@ -8337,6 +8437,20 @@
"node": ">=8.0" "node": ">=8.0"
} }
}, },
"node_modules/topojson-client": {
"version": "3.1.0",
"resolved": "https://registry.npmjs.org/topojson-client/-/topojson-client-3.1.0.tgz",
"integrity": "sha512-605uxS6bcYxGXw9qi62XyrV6Q3xwbndjachmNxu8HWTtVPxZfEJN9fd/SZS1Q54Sn2y0TMyMxFj/cJINqGHrKw==",
"license": "ISC",
"dependencies": {
"commander": "2"
},
"bin": {
"topo2geo": "bin/topo2geo",
"topomerge": "bin/topomerge",
"topoquantize": "bin/topoquantize"
}
},
"node_modules/ts-api-utils": { "node_modules/ts-api-utils": {
"version": "2.5.0", "version": "2.5.0",
"resolved": "https://registry.npmjs.org/ts-api-utils/-/ts-api-utils-2.5.0.tgz", "resolved": "https://registry.npmjs.org/ts-api-utils/-/ts-api-utils-2.5.0.tgz",
@@ -9261,6 +9375,12 @@
"node": ">=0.10.0" "node": ">=0.10.0"
} }
}, },
"node_modules/world-atlas": {
"version": "2.0.2",
"resolved": "https://registry.npmjs.org/world-atlas/-/world-atlas-2.0.2.tgz",
"integrity": "sha512-IXfV0qwlKXpckz1FhwXVwKRjiIhOnWttOskm5CtxMsjgE/MXAYRHWJqgXOpM8IkcPBoXnyTU5lFHcYa5ChG0LQ==",
"license": "ISC"
},
"node_modules/ws": { "node_modules/ws": {
"version": "8.21.1", "version": "8.21.1",
"resolved": "https://registry.npmjs.org/ws/-/ws-8.21.1.tgz", "resolved": "https://registry.npmjs.org/ws/-/ws-8.21.1.tgz",
+10
View File
@@ -33,6 +33,16 @@ export const velocityAccessRequestSchema = z.object({
export type VelocityAccessRequest = z.infer<typeof velocityAccessRequestSchema>; export type VelocityAccessRequest = z.infer<typeof velocityAccessRequestSchema>;
export const velocityConnectionRequestSchema = z.object({
requestId: z.uuid(),
serverId: z.string().min(1).max(100),
minecraftUuid: minecraftUuidSchema,
username: minecraftUsernameSchema,
occurredAt: isoDateTimeSchema,
});
export type VelocityConnectionRequest = z.infer<typeof velocityConnectionRequestSchema>;
export const velocityAccessResponseSchema = z.discriminatedUnion("allowed", [ export const velocityAccessResponseSchema = z.discriminatedUnion("allowed", [
z.object({ z.object({
allowed: z.literal(true), allowed: z.literal(true),
+14
View File
@@ -3,6 +3,7 @@ import {
cloudEventSchema, cloudEventSchema,
velocityAccessRequestSchema, velocityAccessRequestSchema,
velocityAccessResponseSchema, velocityAccessResponseSchema,
velocityConnectionRequestSchema,
} from "../src/index"; } from "../src/index";
describe("shared service contracts", () => { describe("shared service contracts", () => {
@@ -37,6 +38,19 @@ describe("shared service contracts", () => {
).toThrow(); ).toThrow();
}); });
it("validates a confirmed Velocity connection report", () => {
const request = velocityConnectionRequestSchema.parse({
requestId: "8dd9dbdc-020a-4077-983c-77747522de8f",
serverId: "velocity-main",
minecraftUuid: "069a79f444e94726a5befca90e38aaf5",
username: "Notch",
occurredAt: "2026-03-06T12:00:01.000Z",
});
expect(request.username).toBe("Notch");
expect(() => velocityConnectionRequestSchema.parse({ ...request, username: "bad name" })).toThrow();
});
it("only returns explicit allow or deny decisions to Velocity", () => { it("only returns explicit allow or deny decisions to Velocity", () => {
expect( expect(
velocityAccessResponseSchema.parse({ velocityAccessResponseSchema.parse({
+1 -1
View File
@@ -1,6 +1,6 @@
# Velocity admission plugin # Velocity admission plugin
The plugin checks every online-mode Java login against the account-manager API. It fails closed: unavailable, unauthorized, stale, replayed, malformed, and unknown requests are denied. The plugin checks every online-mode Java login against the account-manager API. It fails closed: unavailable, unauthorized, stale, replayed, malformed, and unknown requests are denied. After a player completes proxy login, the plugin sends best-effort `PostLoginEvent` telemetry used for confirmed-connection activity metrics; reporting failure is logged without disconnecting the player.
## Download or build ## Download or build
@@ -59,6 +59,43 @@ final class AccountManagerClient {
} }
} }
boolean reportConnected(UUID minecraftUuid, String username) {
String compactUuid = minecraftUuid.toString().replace("-", "").toLowerCase();
ConnectionRequest payload = new ConnectionRequest(
UUID.randomUUID().toString(),
config.serverId(),
compactUuid,
username,
Instant.now().toString()
);
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create(config.apiUrl() + "/api/velocity/connection"))
.timeout(config.timeout())
.header("Authorization", "Bearer " + config.apiToken())
.header("Content-Type", "application/json")
.POST(HttpRequest.BodyPublishers.ofString(gson.toJson(payload)))
.build();
try {
HttpResponse<String> response = httpClient.send(request, HttpResponse.BodyHandlers.ofString());
return response.statusCode() == 204;
} catch (InterruptedException exception) {
Thread.currentThread().interrupt();
return false;
} catch (IOException | RuntimeException exception) {
return false;
}
}
private record ConnectionRequest(
String requestId,
String serverId,
String minecraftUuid,
String username,
String occurredAt
) {}
private record AccessRequest( private record AccessRequest(
String requestId, String requestId,
String serverId, String serverId,
@@ -5,9 +5,11 @@ import com.velocitypowered.api.event.EventTask;
import com.velocitypowered.api.event.Subscribe; import com.velocitypowered.api.event.Subscribe;
import com.velocitypowered.api.event.ResultedEvent; import com.velocitypowered.api.event.ResultedEvent;
import com.velocitypowered.api.event.connection.LoginEvent; import com.velocitypowered.api.event.connection.LoginEvent;
import com.velocitypowered.api.event.connection.PostLoginEvent;
import com.velocitypowered.api.event.proxy.ProxyInitializeEvent; import com.velocitypowered.api.event.proxy.ProxyInitializeEvent;
import com.velocitypowered.api.plugin.Plugin; import com.velocitypowered.api.plugin.Plugin;
import com.velocitypowered.api.plugin.annotation.DataDirectory; import com.velocitypowered.api.plugin.annotation.DataDirectory;
import com.velocitypowered.api.proxy.ProxyServer;
import java.io.IOException; import java.io.IOException;
import java.nio.file.Path; import java.nio.file.Path;
import net.kyori.adventure.text.Component; import net.kyori.adventure.text.Component;
@@ -22,13 +24,15 @@ import org.slf4j.Logger;
public final class MinecraftAccountManagerPlugin { public final class MinecraftAccountManagerPlugin {
private final Logger logger; private final Logger logger;
private final Path dataDirectory; private final Path dataDirectory;
private final ProxyServer proxyServer;
private volatile AccountManagerClient accountManagerClient; private volatile AccountManagerClient accountManagerClient;
private volatile String fallbackMessage = "Please register your Minecraft account in Discord before joining."; private volatile String fallbackMessage = "Please register your Minecraft account in Discord before joining.";
@Inject @Inject
public MinecraftAccountManagerPlugin(Logger logger, @DataDirectory Path dataDirectory) { public MinecraftAccountManagerPlugin(Logger logger, @DataDirectory Path dataDirectory, ProxyServer proxyServer) {
this.logger = logger; this.logger = logger;
this.dataDirectory = dataDirectory; this.dataDirectory = dataDirectory;
this.proxyServer = proxyServer;
} }
@Subscribe @Subscribe
@@ -66,4 +70,19 @@ public final class MinecraftAccountManagerPlugin {
} }
}); });
} }
@Subscribe
public void onPostLogin(PostLoginEvent event) {
proxyServer.getScheduler().buildTask(this, () -> {
AccountManagerClient client = accountManagerClient;
if (client == null) return;
boolean recorded = client.reportConnected(
event.getPlayer().getUniqueId(),
event.getPlayer().getUsername()
);
if (!recorded) {
logger.warn("Could not report confirmed Minecraft connection for {} ({})", event.getPlayer().getUsername(), event.getPlayer().getUniqueId());
}
}).schedule();
}
} }
@@ -2,9 +2,15 @@ package games.dmg.accountmanager;
import static org.junit.jupiter.api.Assertions.assertFalse; import static org.junit.jupiter.api.Assertions.assertFalse;
import static org.junit.jupiter.api.Assertions.assertEquals; import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertTrue;
import com.sun.net.httpserver.HttpServer;
import java.io.IOException;
import java.net.InetSocketAddress;
import java.nio.charset.StandardCharsets;
import java.time.Duration; import java.time.Duration;
import java.util.UUID; import java.util.UUID;
import java.util.concurrent.atomic.AtomicReference;
import org.junit.jupiter.api.Test; import org.junit.jupiter.api.Test;
class AccountManagerClientTest { class AccountManagerClientTest {
@@ -27,4 +33,55 @@ class AccountManagerClientTest {
assertFalse(decision.allowed()); assertFalse(decision.allowed());
assertEquals("Register through Discord.", decision.message()); assertEquals("Register through Discord.", decision.message());
} }
@Test
void reportsConfirmedConnectionsToTheAuthenticatedEndpoint() throws IOException {
HttpServer server = HttpServer.create(new InetSocketAddress("127.0.0.1", 0), 0);
AtomicReference<String> body = new AtomicReference<>();
AtomicReference<String> authorization = new AtomicReference<>();
server.createContext("/api/velocity/connection", exchange -> {
body.set(new String(exchange.getRequestBody().readAllBytes(), StandardCharsets.UTF_8));
authorization.set(exchange.getRequestHeaders().getFirst("Authorization"));
exchange.sendResponseHeaders(204, -1);
exchange.close();
});
server.start();
try {
PluginConfig config = new PluginConfig(
"http://127.0.0.1:" + server.getAddress().getPort(),
"velocity-test",
"test-token",
Duration.ofSeconds(2),
"Register through Discord."
);
assertTrue(new AccountManagerClient(config).reportConnected(
UUID.fromString("069a79f4-44e9-4726-a5be-fca90e38aaf5"),
"Notch"
));
assertEquals("Bearer test-token", authorization.get());
assertTrue(body.get().contains("\"minecraftUuid\":\"069a79f444e94726a5befca90e38aaf5\""));
assertTrue(body.get().contains("\"username\":\"Notch\""));
} finally {
server.stop(0);
}
}
@Test
void connectionReportingIsBestEffortWhenTheApiCannotBeReached() {
PluginConfig config = new PluginConfig(
"http://127.0.0.1:1",
"velocity-test",
"test-token",
Duration.ofMillis(100),
"Register through Discord."
);
boolean recorded = new AccountManagerClient(config).reportConnected(
UUID.fromString("069a79f4-44e9-4726-a5be-fca90e38aaf5"),
"Notch"
);
assertFalse(recorded);
}
} }