Add account connections, guild wallets and admin fixes [skip ci]
This commit is contained in:
1 parent
7076e847ea
commit
004862ea88
38 files changed
+1696
-458
No files matched your search
+9
-2
@@ -4,7 +4,7 @@
|
||||
|
||||
```bash
|
||||
cp .env.example .env # set ADMIN_PASSWORD
|
||||
docker compose up -d
|
||||
docker compose up -d --build
|
||||
docker compose logs -f panel # first start prints the admin account
|
||||
```
|
||||
|
||||
@@ -19,7 +19,7 @@ Everything the panel stores lives in the `panel-data` volume (`/data`):
|
||||
|
||||
**Backups:** stop the container (or use `sqlite3 panel.db ".backup backup.db"`) and copy the volume.
|
||||
|
||||
**Updating:** `docker compose pull && docker compose up -d`. Database migrations run automatically.
|
||||
**Updating this checkout:** `docker compose up -d --build`. Database migrations run automatically.
|
||||
|
||||
### HTTPS
|
||||
|
||||
@@ -66,6 +66,13 @@ Official servers use `online-mode=true`, authlib-injector and the SCOPENET serve
|
||||
- Each account has a permanent UUID. New accounts receive a random UUID; existing accounts keep theirs. Username changes preserve inventory and reserve prior names. Players change username, skin and permitted capes from the launcher.
|
||||
- Disabling an account signs it out everywhere on the next request.
|
||||
- Ten failed logins lock an account for five minutes.
|
||||
- **Username blacklist:** Settings → Username blacklist. Each entry matches a complete name; wrap it as `*word*` to block it inside longer names. The short starter list covers obvious offensive terms and can be edited. New registrations, admin-created accounts, Discord-created accounts, and username changes all use it.
|
||||
|
||||
### Discord and password reset email
|
||||
|
||||
Set **Settings → Auth server → Public address** to the HTTPS URL players use. In **Settings → Discord**, save the application client ID and client secret, and add `https://your-panel.example/api/v1/auth/discord/callback` to the Discord application's OAuth2 redirect URLs. Players can sign in with Discord in the launcher or connect an existing account under **Accounts → Connections → Discord**. With registration closed, Discord sign-in works for linked accounts only; open or approval mode can create new player accounts.
|
||||
|
||||
In **Settings → Resend SMTP**, save a Resend API key and a sender email from a verified domain. The panel sends password reset links through `smtp.resend.com` over TLS. A reset link expires after 30 minutes and works once. Use **Send a test email** and check the destination inbox and Resend activity log: SMTP acceptance confirms submission, while the inbox confirms delivery. Credentials are stored in the panel data volume and are not returned to the browser after saving; protect the volume and restrict access to the Admin Panel.
|
||||
|
||||
## Launcher design
|
||||
|
||||
|
||||
Reference in new issue
Block a user