XFE Git
XFE Studio Git
Git 首页 全局搜索
XFE 主站 文档 NuGet

XFEServerManager

【Java】我的世界XFE服务器管理器

公开
关注 0 Fork 0 Star 0
UTF-8

Security policy

XFEServerManager is a privileged server component. Please do not publish a working authentication bypass, command-policy escape, duplication exploit, or remote-code-execution report before maintainers have had time to respond.

Report vulnerabilities privately to the repository owner and include the affected Minecraft/Forge version, configuration, reproduction steps, and logs with credentials removed.

Deployment baseline

  • Keep the embedded HTTP listener on loopback.
  • Terminate TLS at a maintained reverse proxy.
  • Configure trusted proxy CIDRs explicitly.
  • Enable TOTP for every owner; it is mandatory for the optional web console.
  • Never restore a production database or world journal without a tested backup.
  • Treat owner sessions and the server filesystem as equivalent to full server control.

Security fixes are supported on the latest released XFEServerManager build for each of the four declared Minecraft baselines.