From c8e41fd80ff3aaeae02dfc9d737ed6c843cb7266 Mon Sep 17 00:00:00 2001 From: Tim Date: Sat, 15 Aug 2026 08:06:15 -0400 Subject: [PATCH] POC mode: strip moderation controls, backlog them This is a proof of concept and the controls that kick, filter or restrict players have been costing more than they protect. Every one of them has now caused an outage or a support incident at some point, and none of them defends against a threat a five-person family server actually has. Removed: Profanity Guard chat filter mod, pure moderation FORCE_GAMEMODE forced everyone back to survival on join, overriding an op who had deliberately switched to creative Already gone for the same reason: the playtime limiter (dead since the droplet move), spawn protection (silently blocked building near the house), the airborne kick (kicked players for using Ad Astra in space), and the anticheat (kicked a whitelisted player for opening a door). Deliberately KEPT, and this is the part worth arguing about: the whitelist and online-mode. Those are not moderation. They are the difference between a private family server and an open one. The game port is scanned continuously, which any day's log shows as a stream of VANILLA connection attempts from hosts nobody invited. Turning off the whitelist puts a server with children on it in front of those. If it comes off, that should be a deliberate decision to run a public server, not a side effect of reducing friction, and everything else gets revisited at the same time. Also kept: PrismProtect, which blocks nothing and kicks nobody. It is what makes griefing reversible, so removing it removes the undo rather than a restriction. specs/0006 records what came off, what stayed and why, and the order things should return in. Anticheat only comes back with a config file, ops exemption and server-side logging, because the last one had none of those. --- docker-compose.yml | 4 +- specs/0006-poc-moderation-backlog.md | 65 ++++++++++++++++++++++++++++ 2 files changed, 67 insertions(+), 2 deletions(-) create mode 100644 specs/0006-poc-moderation-backlog.md diff --git a/docker-compose.yml b/docker-compose.yml index 3337d6e..c98f8d1 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -60,7 +60,7 @@ services: # image, so we list the jars directly. To refresh after changing the pack: # read each file's downloads[0] from the pack's modrinth.index.json where # env.server != "unsupported", and join with commas. - MODS: "https://cdn.modrinth.com/data/LNytGWDc/versions/8amzvn9x/create-1.20.1-6.0.8.jar,https://cdn.modrinth.com/data/gu7yAYhd/versions/rx9gr1rz/cc-tweaked-1.20.1-forge-1.120.0.jar,https://cdn.modrinth.com/data/fXt291FO/versions/yxrimuPr/cccbridge-mc1.20.1-v1.7.1-forge.jar,https://cdn.modrinth.com/data/SOw6jD6x/versions/mIP0ApJY/AdvancedPeripherals-1.20.1-0.7.48r.jar,https://cdn.modrinth.com/data/R2OftAxM/versions/CsjS7EkP/FarmersDelight-1.20.1-1.3.2.jar,https://cdn.modrinth.com/data/WFwYiVoG/versions/Jo8EwiDR/letsdo-bakery-forge-1.1.15.jar,https://cdn.modrinth.com/data/1DWmBJVA/versions/2I4cH49O/letsdo-vinery-forge-1.4.41.jar,https://cdn.modrinth.com/data/wvMc8AJt/versions/eAALa47O/lightmanscurrency-1.20.1-2.3.0.5.jar,https://cdn.modrinth.com/data/LOpKHB2A/versions/sKoHLGbK/waystones-forge-1.20.1-14.1.20.jar,https://cdn.modrinth.com/data/SaCpeal4/versions/gBDsc134/comforts-forge-6.4.0%2B1.20.1.jar,https://cdn.modrinth.com/data/nU0bVIaL/versions/94dtOLgZ/Patchouli-1.20.1-85-FORGE.jar,https://cdn.modrinth.com/data/u6dRKJwZ/versions/vnxhddW4/jei-1.20.1-forge-15.20.0.133.jar,https://cdn.modrinth.com/data/lhGA9TYQ/versions/1MKTLiiG/architectury-9.2.14-forge.jar,https://cdn.modrinth.com/data/4XJZeZbM/versions/uEaTMht9/letsdo-API-forge-1.2.15-forge.jar,https://cdn.modrinth.com/data/MBAkmtvl/versions/8rz04Kha/balm-forge-1.20.1-7.3.38-all.jar,https://cdn.modrinth.com/data/umyGl7zF/versions/g5igndAv/kubejs-forge-2001.6.5-build.16.jar,https://cdn.modrinth.com/data/sk9knFPE/versions/maCpsT70/rhino-forge-2001.2.3-build.6.jar,https://cdn.modrinth.com/data/ordsPcFz/versions/Zsh14XeQ/kotlinforforge-4.12.0-all.jar,https://cdn.modrinth.com/data/zfbCkvdZ/versions/er56DwLJ/Kambrik-6.1.1%2B1.20.1-forge.jar,https://cdn.modrinth.com/data/BpwWFOVM/versions/EM7Su3PD/Bountiful-6.0.4%2B1.20.1-forge.jar,https://cdn.modrinth.com/data/Vebnzrzj/versions/AudvOzqV/LuckPerms-Forge-5.4.102.jar,https://cdn.modrinth.com/data/w55UhnTf/versions/lkx1EGgV/Profanity%20Guard-forge-1.20.1-1.1.0.jar,https://cdn.modrinth.com/data/swbUV1cr/versions/kC7iYqja/bluemap-5.12-mc1.20-6-forge.jar,https://cdn.modrinth.com/data/FIpr9lji/versions/LcBh53eF/prismprotect-forge-1.3.2-mc1.20.1-1.20.4.jar,https://cdn.modrinth.com/data/rsBa8ErW/versions/l7p4hUk0/playtimestatistics-1.20.x-zh-CN-1.0.1.jar,https://cdn.modrinth.com/data/8oi3bsk5/versions/WeYhEb5d/Terralith_1.20.x_v2.5.4.jar,https://cdn.modrinth.com/data/8DfbfASn/versions/6hQpx5Tc/DungeonsArise-1.20.x-2.1.58-release.jar,https://cdn.modrinth.com/data/3ufwT9JF/versions/Qf7QFXk2/ad_astra-forge-1.20.1-1.15.20.jar,https://cdn.modrinth.com/data/G1hIVOrD/versions/OhsHaCcW/resourcefullib-forge-1.20.1-2.1.29.jar,https://cdn.modrinth.com/data/M1953qlQ/versions/DERs8u7v/resourcefulconfig-forge-1.20.1-2.1.3.jar,https://cdn.modrinth.com/data/2u6LRnMa/versions/O7D6FTfW/botarium-forge-1.20.1-2.3.4.jar" + MODS: "https://cdn.modrinth.com/data/LNytGWDc/versions/8amzvn9x/create-1.20.1-6.0.8.jar,https://cdn.modrinth.com/data/gu7yAYhd/versions/rx9gr1rz/cc-tweaked-1.20.1-forge-1.120.0.jar,https://cdn.modrinth.com/data/fXt291FO/versions/yxrimuPr/cccbridge-mc1.20.1-v1.7.1-forge.jar,https://cdn.modrinth.com/data/SOw6jD6x/versions/mIP0ApJY/AdvancedPeripherals-1.20.1-0.7.48r.jar,https://cdn.modrinth.com/data/R2OftAxM/versions/CsjS7EkP/FarmersDelight-1.20.1-1.3.2.jar,https://cdn.modrinth.com/data/WFwYiVoG/versions/Jo8EwiDR/letsdo-bakery-forge-1.1.15.jar,https://cdn.modrinth.com/data/1DWmBJVA/versions/2I4cH49O/letsdo-vinery-forge-1.4.41.jar,https://cdn.modrinth.com/data/wvMc8AJt/versions/eAALa47O/lightmanscurrency-1.20.1-2.3.0.5.jar,https://cdn.modrinth.com/data/LOpKHB2A/versions/sKoHLGbK/waystones-forge-1.20.1-14.1.20.jar,https://cdn.modrinth.com/data/SaCpeal4/versions/gBDsc134/comforts-forge-6.4.0%2B1.20.1.jar,https://cdn.modrinth.com/data/nU0bVIaL/versions/94dtOLgZ/Patchouli-1.20.1-85-FORGE.jar,https://cdn.modrinth.com/data/u6dRKJwZ/versions/vnxhddW4/jei-1.20.1-forge-15.20.0.133.jar,https://cdn.modrinth.com/data/lhGA9TYQ/versions/1MKTLiiG/architectury-9.2.14-forge.jar,https://cdn.modrinth.com/data/4XJZeZbM/versions/uEaTMht9/letsdo-API-forge-1.2.15-forge.jar,https://cdn.modrinth.com/data/MBAkmtvl/versions/8rz04Kha/balm-forge-1.20.1-7.3.38-all.jar,https://cdn.modrinth.com/data/umyGl7zF/versions/g5igndAv/kubejs-forge-2001.6.5-build.16.jar,https://cdn.modrinth.com/data/sk9knFPE/versions/maCpsT70/rhino-forge-2001.2.3-build.6.jar,https://cdn.modrinth.com/data/ordsPcFz/versions/Zsh14XeQ/kotlinforforge-4.12.0-all.jar,https://cdn.modrinth.com/data/zfbCkvdZ/versions/er56DwLJ/Kambrik-6.1.1%2B1.20.1-forge.jar,https://cdn.modrinth.com/data/BpwWFOVM/versions/EM7Su3PD/Bountiful-6.0.4%2B1.20.1-forge.jar,https://cdn.modrinth.com/data/Vebnzrzj/versions/AudvOzqV/LuckPerms-Forge-5.4.102.jar,https://cdn.modrinth.com/data/swbUV1cr/versions/kC7iYqja/bluemap-5.12-mc1.20-6-forge.jar,https://cdn.modrinth.com/data/FIpr9lji/versions/LcBh53eF/prismprotect-forge-1.3.2-mc1.20.1-1.20.4.jar,https://cdn.modrinth.com/data/rsBa8ErW/versions/l7p4hUk0/playtimestatistics-1.20.x-zh-CN-1.0.1.jar,https://cdn.modrinth.com/data/8oi3bsk5/versions/WeYhEb5d/Terralith_1.20.x_v2.5.4.jar,https://cdn.modrinth.com/data/8DfbfASn/versions/6hQpx5Tc/DungeonsArise-1.20.x-2.1.58-release.jar,https://cdn.modrinth.com/data/3ufwT9JF/versions/Qf7QFXk2/ad_astra-forge-1.20.1-1.15.20.jar,https://cdn.modrinth.com/data/G1hIVOrD/versions/OhsHaCcW/resourcefullib-forge-1.20.1-2.1.29.jar,https://cdn.modrinth.com/data/M1953qlQ/versions/DERs8u7v/resourcefulconfig-forge-1.20.1-2.1.3.jar,https://cdn.modrinth.com/data/2u6LRnMa/versions/O7D6FTfW/botarium-forge-1.20.1-2.3.4.jar" # Questify (quests) was removed: it and PrismProtect both shade their own # copy of org.sqlite as plain classes under the same package name, which # Forge's module system refuses to load together ("Modules questory and @@ -174,7 +174,7 @@ services: # --- KID-SAFETY: lock down risky gameplay --- PVP: "false" # no attacking each other ENABLE_COMMAND_BLOCK: "false" # no redstone command-block exploits - FORCE_GAMEMODE: "true" # everyone stays in survival, even after an op-changed session + FORCE_GAMEMODE: "false" # everyone stays in survival, even after an op-changed session # 0 = off. Was 16, which silently blocked every non-op from placing or # breaking a block within 16 of world spawn. World spawn was moved to the # front of the owner's house, so the protected bubble landed exactly where diff --git a/specs/0006-poc-moderation-backlog.md b/specs/0006-poc-moderation-backlog.md new file mode 100644 index 0000000..57c1731 --- /dev/null +++ b/specs/0006-poc-moderation-backlog.md @@ -0,0 +1,65 @@ +--- +id: 0006 +title: POC mode - moderation stripped, backlog to restore before real use +project: minecraft +status: accepted +owner: tbgorrie +created: 2026-08-15 +--- + +# 0006 - POC mode: moderation stripped, and the backlog to restore + +EduCraft is a proof of concept. Controls that kick, filter or restrict players +have been removed so the thing can be played with without fighting it. This file +is the record of what came off and what must go back before it is anything more +than a family experiment. + +## Removed now + +| Control | Was | Now | Why it was removed | +|---|---|---|---| +| **Profanity Guard** | chat filter mod | **removed** | Filters and blocks messages. Pure moderation, no gameplay value in a POC. | +| **FORCE_GAMEMODE** | `true` | `false` | Forced every player back to survival on join, overriding an op who had switched to creative. Actively fought the people using it. | +| Playtime limiter | 120 min/day cap | **already gone** | Windows-only, dead since the droplet move. Removed in the cleanup PR; see DEPLOY.md. | +| Spawn protection | 16 blocks | **already 0** | Blocked non-ops building near the house, silently and with no error. | +| Airborne kick | `allow-flight=false` | **already true** | Kicked players for using Ad Astra in space. | +| Anticheat (MythicalAC) | installed | **gone 2026-08-02** | Kicked a whitelisted player for opening a door. No config, no exemptions. | + +## Deliberately KEPT, and why + +These are not moderation. They are the difference between a private family server +and an open one, and removing them changes who can reach children. + +- **Whitelist (`ENABLE_WHITELIST` / `ENFORCE_WHITELIST`)**: the entire access + control. Turning it off puts a server with children on it on the open internet, + where it will be found within hours; the port is scanned continuously already + (see the VANILLA connection attempts in any day's log). **Do not remove for + convenience.** If it is ever removed, it is a deliberate decision to run a public + server, and everything else in this file gets revisited at the same time. +- **`ONLINE_MODE=TRUE`**: requires a real Microsoft account. Turning it off allows + anonymous clients and lets anyone impersonate any username, including an op. +- **PrismProtect**: passive block-change logging. It blocks nothing and kicks + nobody; it is what makes griefing reversible. Removing it removes the ability to + undo, not a restriction. +- **LuckPerms**: permissions plumbing, currently only used for op levels. +- **PvP off**: kept because it prevents kids hurting each other, not because it + restricts anyone's building. Trivial to flip if they want to duel. + +## Backlog, in the order it should return + +1. **Chat filtering**, if the player group ever includes anyone not personally + known. Profanity Guard was adequate; the pinned version is in git history. +2. **Playtime limits**, as a Linux cron job driving `rcon-cli` rather than the old + Windows script. Wanted as a parenting tool, not a security control. +3. **Anticheat**, only with a config file, ops exemption and server-side logging. + The last one had none of those and had to be uninstalled. See issue #8. +4. **Spawn protection**, only if world spawn moves somewhere public. +5. **Per-role permissions** via LuckPerms, so trusted players can moderate without + full op. Attempted 2026-08-14: LuckPerms commands return nothing over RCON, so + it must be configured from in-game or by switching its storage to YAML. + +## The line + +Removing friction from a POC is right. The line is anything that controls **who +can connect**: whitelist and online-mode stay until this stops being a server with +children on it, or until someone decides otherwise knowing exactly what it means.