SY-Pass [Fabric] 2.2.0 (1.21 - 1.21.1)
Curse Maven Snippet
What's new
# SY-Pass v2.2.0
A major update focusing on streamer privacy, enhanced chat & command security, automated testing, and general quality-of-life improvements.
---
### π₯ Streamer Mode
* **Full Host & IP Masking:** One-click toggle in Settings that completely masks server hostnames, IP addresses, and ports with asterisks (`*`) across all server cards, lists, and edit screens (e.g., `mc.hypixel.net:25565` β `********************`).
* **Neutral Server Icons:** Replaces all custom server favicons with standard, neutral Minecraft server icons (`unknown_server.png`) to prevent server identification by logos.
* **Stream-Proof Credential Safety:** Disables in-place password reveal buttons and masks password fields by default while Streamer Mode is active.
* **Strictly Scoped:** Operates strictly inside the SY-Pass mod GUI without modifying any vanilla screens.
---
### π‘οΈ Security Hardening & Leak Protection
* **Command Leak Protection:** Extended the Aho-Corasick leak protection engine to intercept outgoing client commands (`/msg`, `/tell`, `/w`, `/r`, `/say`, etc.) on both Fabric and NeoForge.
* **Smart Authentication Whitelist:** Legitimate authentication commands (`/login`, `/l`, `/register`, `/reg`, `/auth`, `/changepassword`, `/cp`, custom server login commands, and configured registration templates) as well as internal auto-login dispatches are never blocked.
* **NeoForge Anti-Spoofing:** Completely eliminated auto-login prompt scanning from player chat messages (`ClientChatReceivedEvent.Player`). Only server system packets and action bar overlays can trigger login prompts.
* **Safe Bitwarden Vault Sync:** Removed permanent duplicate deletion (`--permanent`) during remote pulls, ensuring your Bitwarden cloud vault is never modified destructively.
---
### π Master Password Enhancements
* **Configurable Auto-Lock Timeout:** Added an optional inactivity timer that clears credentials from memory and locks the vault after 5, 10, 15, 30, or 60 minutes (disabled by default).
* **Instant Manual Lock:** Added a dedicated "Lock Vault Now" button in the Master Password menu.
* **Improved Navigation:** Added "Back" buttons to both the initial Master Password setup screen and the vault unlock modal.
---
### π§ͺ Architecture, DevOps & Code Quality
* **Automated Unit Test Suite:** Introduced a 23-test JUnit 5 suite covering AES-GCM encryption/decryption, PBKDF2 key derivation, Aho-Corasick linear scanning, address masking, and multi-format CSV parsing.
* **Resource Deduplication (DRY):** Removed duplicate localization files from `fabric/` and `neoforge/`; translations (`en_us`, `uk_ua`, `ru_ru`) are now centrally maintained in `common/`.
* **CI/CD & Portability:** Modernized GitHub Actions workflow to v4 actions running Temurin JDK 21 and added automatic local JDK detection fallback in `gradlew`.
---
### π‘οΈ What's New in v2.1.0
#### π Cryptographic Security & Memory Sanitation
* **`char[]` Password In-Memory Representation:** Replaced immutable `String` objects with character arrays across memory storage, reducing the risk of plaintext credentials lingering in JVM memory dumps.
* **Proactive Memory Zeroing:** Sensitive password arrays are explicitly zeroed out (`Arrays.fill(..., '\0')`) immediately after clipboard copies, command dispatch, or vault writes.
* **Reflection-Safe Public Storage:** `PasswordManager.getAllData()` now returns sanitized, unmodifiable copies with empty passwords (`new char[0]`), preventing unauthorized mods or reflection scanners from reading stored credentials.
* **Direct Aho-Corasick Population:** The chat leak detection trie is constructed character-by-character directly from secure buffers.
#### π Optional Master Password / PIN Lock
* **Envelope Encryption (PBKDF2 + AES-GCM):** Optional startup vault protection using **PBKDF2WithHmacSHA256 (100,000 iterations)** to encrypt the local vault key (`sypass.key.enc`).
* **In-Game Lock Screen:** When enabled, the vault remains locked and unloaded on game launch until you enter your Master Password or PIN in the GUI.
* **Fail-Safe & Bitwarden Recovery:** Automatically creates backups prior to enabling lock mode, and provides an **Emergency Reset** button that re-syncs all passwords if Bitwarden is connected.
#### β‘ Enhanced Server Compatibility & Custom Prompts
* **Configurable Registration Templates:** Support for custom server registration commands (e.g., `/register %password% %password%`, `/reg %password%`, or custom auth commands).
* **Custom Smart Auto-Login Patterns:** Add custom regex patterns in Settings to support servers with non-standard chat prompts (such as `[Auth]` prefixes or custom minigame messages).
#### π₯ Universal CSV Importer
* **Cross-Manager Support:** Automatically detects column headers and formats for **Bitwarden CSV**, **KeePass (1.x & 2.x) CSV**, **1Password CSV**, and generic browser exports.
#### π Localization & Resource Cleanup
* **Audited Translation Bundles:** Purged 55 obsolete and unused localization keys; added 25 new translation keys across English (`en_us`), Ukrainian (`uk_ua`), and Russian (`ru_ru`) for 100% feature coverage (220 active keys).
---
All Relations
- All Relations
- Embedded Library
- Optional Dependency
- Required Dependency
- Tool
- Incompatible
- Include

