auth

package
v1.62.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 16, 2026 License: MIT Imports: 20 Imported by: 62

Documentation

Overview

Package auth implements authentication to Microsoft Live Connect accounts, XBOX Live accounts and ultimately Minecraft accounts associated with them. Microsoft Live Connect auth is performed using device auth.

The auth package provides token sources for Microsoft Live Connect auth with an oauth2-style interface, with token sources that may be plugged into services directly.

Index

Constants

This section is empty.

Variables

View Source
var (
	// AndroidConfig is the configuration used in Minecraft: Bedrock Edition for Android devices.
	AndroidConfig = Config{
		sisu.Config{
			Config: xal.Config{

				Device: xal.Device{
					Type:    xal.DeviceTypeAndroid,
					Version: "13",
				},
				UserAgent: "XAL Android 2025.04.20250326.000",
				TitleID:   1739947436,
				Sandbox:   "RETAIL",
			},
			ClientID:    "0000000048183522",
			RedirectURI: "ms-xal-0000000048183522://auth",
		},
	}

	// IOSConfig is the configuration used in Minecraft: Bedrock Edition for iOS devices.
	IOSConfig = Config{
		sisu.Config{
			Config: xal.Config{
				Device: xal.Device{
					Type:    xal.DeviceTypeIOS,
					Version: "15.6.1",
				},
				UserAgent: "XAL iOS 2021.11.20211021.000",
				TitleID:   1810924247,
				Sandbox:   "RETAIL",
			},
			ClientID:    "000000004c17c01a",
			RedirectURI: "ms-xal-000000004c17c01a://auth",
		},
	}

	// Win32Config is the configuration for Minecraft: Bedrock Edition on Windows
	// devices. It is provided for reference only and is not functional, as retrieving
	// the RPS ticket required for device token requests is not yet known.
	Win32Config = Config{
		sisu.Config{
			Config: xal.Config{

				Device: xal.Device{
					Type:    xal.DeviceTypeWin32,
					Version: "10.0.28000",
				},
				UserAgent: "XAL GRTS 2025.11.20251105.000",
				TitleID:   896928775,
				Sandbox:   "RETAIL",
			},
			ClientID:    "0000000040159362",
			RedirectURI: "ms-xal-0000000040159362://auth",
		},
	}
	// NintendoConfig is the configuration used in Minecraft: Bedrock Edition for Nintendo Switch.
	NintendoConfig = Config{
		sisu.Config{
			Config: xal.Config{
				Device: xal.Device{
					Type:    xal.DeviceTypeNintendo,
					Version: "0.0.0",
				},
				UserAgent: "XAL",
				TitleID:   2047319603,
				Sandbox:   "RETAIL",
			},
			ClientID: "00000000441cc96b",
		},
	}
	// PlayStationConfig is the configuration used in Minecraft: Bedrock Edition for PlayStation devices.
	PlayStationConfig = Config{
		sisu.Config{
			Config: xal.Config{
				Device: xal.Device{
					Type:    xal.DeviceTypePlayStation,
					Version: "10.0.0",
				},
				UserAgent: "XAL",
				Sandbox:   "RETAIL",
				TitleID:   2044456598,
			},
			ClientID: "000000004827c78e",
		},
	}

	// ServiceConfigID is the Service Configuration ID (SCID) used in release versions of Minecraft.
	// It is used for searching/hosting multiplayer sessions and querying achievements.
	ServiceConfigID = uuid.MustParse("4fc10100-5f7a-4470-899b-280835760c07")
	// PreviewServiceConfigID is the Service Configuration ID (SCID) used in preview versions of Minecraft.
	// It is used for searching/hosting multiplayer sessions and querying achievements in preview version.
	PreviewServiceConfigID = uuid.MustParse("00000000-0000-0000-0000-0000717d695f")
)
View Source
var TokenSource = AndroidConfig.WriterTokenSource(os.Stdout)

TokenSource holds an oauth2.TokenSource which uses device auth to get a code. The user authenticates using a code. TokenSource prints the authentication code and URL to os.Stdout. To use a different io.Writer, use WriterTokenSource. TokenSource automatically refreshes tokens.

Functions

func ContextClient added in v1.59.0

func ContextClient(ctx context.Context) *http.Client

ContextClient returns the HTTP client configured on ctx for auth requests. If no client is configured, http.DefaultClient is returned.

func ContextSession added in v1.59.0

func ContextSession(ctx context.Context, src oauth2.TokenSource) *sisu.Session

ContextSession attempts to obtain sisu.Session from the given context.Context. The oauth2.TokenSource is used to create a SISU session on the cache when needed. Callers can set their own session to the context by using ReuseTokenCache.

func RefreshTokenSource

func RefreshTokenSource(t *oauth2.Token) oauth2.TokenSource

RefreshTokenSource returns a new oauth2.TokenSource using the oauth2.Token passed that automatically refreshes the token everytime it expires. Note that this function must be used over oauth2.ReuseTokenSource due to that function not refreshing with the correct scopes.

func RefreshTokenSourceWriter

func RefreshTokenSourceWriter(t *oauth2.Token, w io.Writer) oauth2.TokenSource

RefreshTokenSourceWriter returns a new oauth2.TokenSource using the oauth2.Token passed that automatically refreshes the token everytime it expires. It requests from io.Writer if the oauth2.Token is invalid. Note that this function must be used over oauth2.ReuseTokenSource due to that function not refreshing with the correct scopes.

func RequestLiveToken

func RequestLiveToken() (*oauth2.Token, error)

RequestLiveToken does a login request for Microsoft Live Connect using device auth. A login URL will be printed to the stdout with a user code which the user must use to submit. RequestLiveToken is the equivalent of RequestLiveTokenWriter(os.Stdout).

func RequestLiveTokenContext added in v1.59.0

func RequestLiveTokenContext(ctx context.Context, w io.Writer) (*oauth2.Token, error)

RequestLiveTokenContext does a login request for Microsoft Live Connect using device auth. A login URL will be printed to the io.Writer passed with a user code which the user must use to submit. Once fully authenticated, an oauth2 token is returned which may be used to login to XBOX Live. The context is used to control the deadline for polling the OAuth2 device authorization endpoint.

func RequestLiveTokenWriter

func RequestLiveTokenWriter(w io.Writer) (*oauth2.Token, error)

RequestLiveTokenWriter does a login request for Microsoft Live Connect using device auth. A login URL will be printed to the io.Writer passed with a user code which the user must use to submit. Once fully authenticated, an oauth2 token is returned which may be used to login to XBOX Live.

func RequestMinecraftChain

func RequestMinecraftChain(ctx context.Context, client *xsapi.Client, key *ecdsa.PrivateKey) (string, error)

RequestMinecraftChain requests a fully processed Minecraft JWT chain using the XBL client and the ECDSA private key passed. The key will later be used to initialise encryption, and must be saved for when packets need to be decrypted/encrypted.

func WithContextClient added in v1.59.0

func WithContextClient(ctx context.Context, client *http.Client) context.Context

WithContextClient stores client on ctx for auth code paths that read HTTP clients from the OAuth2 or XAL context keys.

func WithXBLTokenCache added in v1.53.0

func WithXBLTokenCache(parent context.Context, cache *XBLTokenCache) context.Context

WithXBLTokenCache returns a context.Context which contains the XBLTokenCache. The returned context.Context can be used in RequestXBLToken for re-using the device token as possible to avoid issuing too many device tokens and incurring rate limiting from XASD (Xbox Authentication Service for Devices).

func WriterTokenSource

func WriterTokenSource(w io.Writer) oauth2.TokenSource

WriterTokenSource returns a new oauth2.TokenSource which, like TokenSource, uses device auth to get a code. Unlike TokenSource, WriterTokenSource allows passing an io.Writer to which information on the auth URL and code are printed. WriterTokenSource automatically refreshes tokens.

Types

type Config added in v1.53.0

type Config struct {
	// An embedded [sisu.Config] describes the SISU configuration used in the title.
	sisu.Config
}

Config encapsulates configuration for authenticating with Xbox Live services in a specific title.

func (Config) NewTokenCache added in v1.53.0

func (conf Config) NewTokenCache() *XBLTokenCache

NewTokenCache returns an XBLTokenCache that can be used to re-use XBL tokens in RequestXBLToken.

func (Config) RefreshTokenSource added in v1.53.0

func (conf Config) RefreshTokenSource(t *oauth2.Token) oauth2.TokenSource

RefreshTokenSource returns a new oauth2.TokenSource using the oauth2.Token passed that automatically refreshes the token everytime it expires. Note that this function must be used over oauth2.ReuseTokenSource due to that function not refreshing with the correct scopes.

func (Config) RefreshTokenSourceWriter added in v1.53.0

func (conf Config) RefreshTokenSourceWriter(t *oauth2.Token, w io.Writer) oauth2.TokenSource

RefreshTokenSourceWriter returns a new oauth2.TokenSource using the oauth2.Token passed that automatically refreshes the token everytime it expires. It requests from io.Writer if the oauth2.Token is invalid. Note that this function must be used over oauth2.ReuseTokenSource due to that function not refreshing with the correct scopes.

func (Config) RequestLiveToken added in v1.53.0

func (conf Config) RequestLiveToken() (*oauth2.Token, error)

RequestLiveToken does a login request for Microsoft Live Connect using device auth. A login URL will be printed to the stdout with a user code which the user must use to submit. RequestLiveToken is the equivalent of RequestLiveTokenWriter(os.Stdout).

func (Config) RequestLiveTokenContext added in v1.59.0

func (conf Config) RequestLiveTokenContext(ctx context.Context, w io.Writer) (*oauth2.Token, error)

RequestLiveTokenContext does a login request for Microsoft Live Connect using device auth. A login URL will be printed to the io.Writer passed with a user code which the user must use to submit. Once fully authenticated, an oauth2 token is returned which may be used to login to XBOX Live. The context is used to control the deadline for polling the OAuth2 device authorization endpoint.

func (Config) RequestLiveTokenWriter added in v1.53.0

func (conf Config) RequestLiveTokenWriter(w io.Writer) (*oauth2.Token, error)

RequestLiveTokenWriter does a login request for Microsoft Live Connect using device auth. A login URL will be printed to the io.Writer passed with a user code which the user must use to submit. Once fully authenticated, an oauth2 token is returned which may be used to login to XBOX Live.

func (Config) RequestXBLToken added in v1.53.0

func (conf Config) RequestXBLToken(ctx context.Context, liveToken *oauth2.Token, relyingParty string) (*XBLToken, error)

RequestXBLToken requests an Xbox Live token using the OAuth2 token identifying the user's Microsoft Account. If an XBLTokenCache is present in ctx (via WithXBLTokenCache), it reuses or newly creates a SISU session inside the cache.

func (Config) ReuseTokenCache added in v1.59.0

func (conf Config) ReuseTokenCache(session *sisu.Session) *XBLTokenCache

ReuseTokenCache returns an XBLTokenCache that uses the provided sisu.Session to request XBL tokens. Callers can embed the returned XBLTokenCache via WithXBLTokenCache for usage in RequestXBLToken.

func (Config) WriterTokenSource added in v1.53.0

func (conf Config) WriterTokenSource(w io.Writer) oauth2.TokenSource

type XBLToken

type XBLToken struct {
	// AuthorizationToken is the XSTS token that relies on the specific relying party.
	// Some fields are only populated on the relying party "http://xboxlive.com".
	AuthorizationToken *xsts.Token
}

XBLToken holds info on the authorization token used for authenticating with XBOX Live.

func RequestXBLToken

func RequestXBLToken(ctx context.Context, liveToken *oauth2.Token, relyingParty string) (*XBLToken, error)

RequestXBLToken requests an Xbox Live token using a default device config. If an XBLTokenCache is present in ctx (via WithXBLTokenCache), its Config is used instead.

func (XBLToken) SetAuthHeader

func (t XBLToken) SetAuthHeader(r *http.Request)

SetAuthHeader sets the 'Authorization' header used for Minecraft related endpoints that need an XBOX Live authenticated caller.

func (XBLToken) Valid added in v1.53.0

func (t XBLToken) Valid() bool

Valid returns whether the XBLToken is valid.

type XBLTokenCache added in v1.53.0

type XBLTokenCache struct {
	// contains filtered or unexported fields
}

XBLTokenCache caches device tokens for requesting Xbox Live tokens. It may be created from Config.NewTokenCache and included to a context.Context for re-using the device token in RequestXBLToken.

func ReuseTokenCache added in v1.59.0

func ReuseTokenCache(session *sisu.Session) *XBLTokenCache

ReuseTokenCache returns an XBLTokenCache that uses the provided sisu.Session to request XBL tokens. Callers can embed the returned XBLTokenCache via WithXBLTokenCache for usage in RequestXBLToken.

func (*XBLTokenCache) Device added in v1.59.0

func (cache *XBLTokenCache) Device() xasd.TokenSource

Device returns a xasd.TokenSource which supplies device tokens.

func (*XBLTokenCache) Session added in v1.59.0

func (cache *XBLTokenCache) Session() *sisu.Session

Session returns a sisu.Sesison cached in XBLTokenCache. Callers can save its snapshot via sisu.Session.Snapshot and restore it when creating a new session. The session can then be passed to Config.ReuseTokenCache for usage in RequestXBLToken again.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL