Velocity admission plugin
The plugin checks every online-mode Java login against the account-manager API. It fails closed: unavailable, unauthorized, stale, replayed, malformed, and unknown requests are denied.
Build
cd plugins/velocity
./gradlew clean test shadowJar
Copy build/libs/minecraft-account-manager-velocity-0.1.0.jar to Velocity's plugins/ directory and start Velocity once to create plugins/minecraft-account-manager/config.properties.
Provision a credential
From the repository root, with DATABASE_URL configured:
npm run plugin:create-credential --workspace @minecraft-account-manager/database -- velocity-main
Copy the displayed token into the plugin's api-token. Configure the HTTPS account-manager URL and ensure server-id matches. Restrict access to the plugin configuration because it contains the bearer token, then restart Velocity.
The proxy must run in online mode. Unknown players and API failures receive the configured registration message.