dmg c1bd4406d2
Release / release (push) Successful in 4m55s
CI / build (push) Successful in 2m47s
feat(stealth): break concealed sessions on player damage
Resolve direct native damage sources and explicitly observed poison/wither provenance, including hidden layers and effective replacements. Preserve progression and potion effects while reusing identity/session cleanup. Verify native effect application, ticks, tab codecs and plugin registration. No deployment is included.
2026-09-12 21:09:10 -04:00

Purpur Stealth

Progression-gated identity concealment for Purpur 26.2 build 2618, built and tested with Java 25. ProtocolLib 5.4.0 is required.

Build

./gradlew clean check jar

Artifacts are written to build/libs/purpur-stealth-<version>.jar. Gitea CI verifies pushes/pull requests; approved main-branch conventional commits drive versioned releases. The distribution tests inspect the built JAR, embedded version/runtime identity, Java 25 bytecode, and workflow naming.

Combat breaks stealth

Dealing uncancelled positive damage to another player ends the attacker's concealed session and tells them: Your stealth was broken because you hurt another player. Melee, player-attributed projectiles and potions qualify; misses, cancelled/zero hits, self-damage, attacking mobs and merely taking damage do not. Identity and prior sleep-count participation are restored, including withdrawing Eye projections. Progress, unlocks and unrelated invisibility remain intact; re-entry uses the existing qualifying logout/login process.

Delayed poison/wither use explicitly observed application sources and read-only native effect-layer snapshots, including hidden-layer restoration and rejected/cosmetic replacements. No nearby-player or wall-clock guess is made. Provenance is runtime-only and discarded on victim disconnect; unknown effects loaded after reconnect/restart are not assigned an invented attacker. The separately tracked signed-chat validation/system-message work remains pending.

Eye of True Seeing

Earn a separate, personal unlock through eight cumulative online hours of Night Vision from directly drunk potions. Splash/lingering potions, commands, plugins and other sources do not count. Rejected and cosmetic-only replacements do not change attribution. Unattributed restored effects cannot inherit the drink timer; a new effective drink can start a new interval. Offline time is excluded.

After the unlock is saved, craft an Eye of True Seeing with eight Netherite Blocks around an Eye of Ender. Right-click an authenticated Eye in either hand to move it into an empty helmet slot. Existing helmets are not replaced. Traded Eyes still require the holder's own saved unlock; renamed ordinary Eyes do not qualify. Automated crafters cannot bypass progression. Vanilla handles crafting ingredient consumption.

While worn by an eligible player, the Eye reveals active Stealth targets' real overhead names within 16 blocks in three dimensions and line of sight. It also reveals their bodies if they have gameplay invisibility, only to that observer. Ordinary invisible players without a concealed Stealth session are not revealed. Platform hiding, spectator mode, vanished metadata and effective team name-visibility restrictions take precedence. Eligibility is checked even for an Eye manually placed in the helmet slot.

Revelation uses private client-only teams and recipient-specific metadata; it does not change server teams, remove potion effects or end Stealth sessions. Tab-list, chat, suggestions and server-list concealment remain unchanged, including for the wearer. Unequipping, leaving range/sight, lifecycle changes and disable withdraw the projection and restore current raw state. Failed deliveries revoke authorization and queue cleanup before recreation. Live-client appearance/timing and compatibility remain separate validation follow-ups.

Eye records are independently UUID-keyed in plugins/SpigotStealth/state.yml (schema 2). Legacy Stealth records and extension fields are preserved. Crafting/use wait for successful save acknowledgement. Shutdown queues a final snapshot without blocking the tick thread, and initialization callbacks cannot revive a disabled or superseded lifecycle. Unacknowledged progress at abrupt process/power loss is not guaranteed.

check includes nativeStealthTest, which downloads SHA-256-pinned Purpur 2618, patches it without starting a listening server, and exercises real potion events, items, recipes, event dispatch and plugin lifecycle with external platform doubles. Live-client appearance and gameplay checks remain separate follow-ups.

Migration compatibility

The repository and checkout are now purpur-stealth (previously remote spigot-stealth, local spigot-invisibilty). Runtime identity remains SpigotStealth, including plugins/SpigotStealth/, the existing Java entrypoint/packages, command names, spigotstealth permission/namespace identifiers, and persisted progression/session data. Java 17 is no longer supported for new builds or artifacts.

Replace the old plugin JAR when installing the new distribution; never load both JARs together. Old tags and spigot-stealth-* release assets are preserved. Repository rename redirects have been checked against the previously deployed v1.5.0 download. Publishing a release does not authorize deployment.

The v2.0.0 migration itself left the Eye, combat reveal and concealed-chat stories pending. Subsequent Eye acquisition, local revelation and combat-session breaking are described above; system-chat routing remains a separate unfinished story. Runtime plugin metadata is unchanged.

See the canonical project, stories, and development cycle.

S
Description
Spigot plugin that rewards invisibility potion use with identity-concealed sessions
Readme
298 KiB
v2.4.0
Latest
2026-09-13 02:05:08 +00:00
Languages
Java 100%