ModernUO/Projects
Kamron Batman e801a69554 fix(network): do not consume an auth id until ownership is proven
ConsumeAuthId removed the entry before checking the address or the account, so
anyone landing on a live id burned it. Its owner then arrived to "unable to find
auth id" and had to start the login over -- from a packet they had no part in.

Look, then take. A mismatch leaves the id alone and yields no entry; only a
presenter that matches both the address and the account spends it.

The reason given for taking it unconditionally -- that a guessed id must not be
reusable to probe for its owner -- does not survive checking the order. The
address is compared first, so a guesser from anywhere else is rejected before a
username is ever looked at, and one from the victim's own address is already on
their network.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-08 01:21:19 -07:00
..
Application fix: Bumps dependencies. (#2531) 2026-07-14 15:17:55 -07:00
BuildTool fix: Require only runtime packages on Linux, and check ICU and tzdata the way the runtime does (#2561) 2026-08-07 15:03:08 -07:00
Logger fix: Bumps dependencies. (#2531) 2026-07-14 15:17:55 -07:00
Server fix: Require only runtime packages on Linux, and check ICU and tzdata the way the runtime does (#2561) 2026-08-07 15:03:08 -07:00
Server.Tests feat(network): allowlist false-positive IPs, escalate on behavior (#2556) 2026-07-30 23:12:17 -07:00
UOContent fix(network): do not consume an auth id until ownership is proven 2026-08-08 01:21:19 -07:00
UOContent.Tests fix(network): do not consume an auth id until ownership is proven 2026-08-08 01:21:19 -07:00