Free, open-source anti-VPN and country rules. Every decision explained, with an optional free dashboard.
0.4.10
Maintenance release for Spigot, BungeeCord and Velocity.
Fixes
- Wait for cache initialization before registering connection checks and commands. A failed or stalled cache setup stops plugin initialization with a bounded timeout.
- Retry VPN detection after incomplete provider responses instead of caching an unreliable negative verdict. Healthy provider votes still count towards the configured threshold.
- Bundle and isolate OkHttp, Okio and Kotlin dependencies so HTTP detection does not depend on libraries supplied by another plugin.
- Reuse a bounded HTTP client, close responses, reject unsuccessful HTTP responses and malformed/missing detection fields, and keep provider URLs, API keys and response messages out of failure logs.
- Use HTTPS for ProxyCheck and IPHub requests. The free IP-API endpoint remains HTTP.
- Cache successful geo lookups and treat failed geo lookups as unavailable so later queries can retry. IP-API error responses no longer require location fields.
- Read both custom-provider nested fields using the documented
#separator, preserve colons in header values and substitute%IP%in headers. - Substitute message placeholders literally, including ISP names containing dollar signs or backslashes.
- Restore reproducible builds, verify all three plugin descriptors and runtime HTTP dependencies, and run regression tests in CI.
- Preserve Velocity's pre-login authentication mode when Connection Guard allows a connection.
Upgrade
Stop the server/proxy, replace the existing Connection Guard JAR with connection-guard-0.4.10-all.jar, and restart. Existing configuration and translations are retained. Provider and cache changes require a restart; /cg reload reloads configuration and messages.
Older versions may have cached negative VPN verdicts during a provider outage. After upgrading, use /cg clear <IP> for affected addresses or /cg clear to clear the whole cache (permission: connectionguard.command.clear). Clearing the cache also clears geo entries and increases provider requests until it fills again.
The existing availability policy is unchanged: missing VPN votes do not count as positive votes; if the threshold is not met, the connection proceeds. A missing geo response supplies no geo verdict. This is not a fail-closed mode.
Validation and compatibility
- 48 Java 8 regression tests, including local HTTP fixtures, thresholds, provider recovery, geo caching and cache startup.
- Combined JAR packaging and Java bytecode checks: Java 8 for core/Spigot/BungeeCord, Java 17 for Velocity; server software can require a newer Java version.
- Real Velocity 3.4.0 build 566 on Java 21: startup, controlled HTTP VPN detection, pre-login rejection, SQLite cache reuse, provider HTTP-503 recovery, negative verdict passing the plugin, command output, reload and shutdown.
- Repeated builds compared by SHA-256. GitHub CI checks the archive independently.
Spigot and BungeeCord retain their existing APIs. This release does not claim a new Minecraft version range. Full backend joins, all server versions, LuckPerms/Floodgate integration and Redis runtime operation are not covered by this release's proxy fixture. Provider fixtures establish behavior for controlled responses, not real-world detection accuracy.
Full changelog: https://github.com/gerolndnr/connection-guard/compare/0.4.9...0.4.10