mojira.dev

Yive

Assigned

No issues.

Reported

No issues.

Comments

Edit 3 hours later: Looks like it was patched again, I feel it was likely an issue with being rate limited for offline UUIDs as a global rate limit instead of them acting like unique UUIDs.

Not sure why this got marked as resolved, but this issue still exists. I tested 11 profile URLs (10 of which were using offline server UUIDs) and got rate limited on the 11th UUID which was an online server UUID. I didn't notice this issue until yesterday so maybe something got changed again to cause this bug again.

Servers also rely on this API at times and if a server were to get hit by a bot attack, then you'll have quite a few issues, especially if it's relating to a login process.

Here's a list of UUIDs that I tested, all of them are from an offline server except the last one so the first 10 will return with 204 - No Content. Either way you'll get a rate limit on the last one if you go through them all at once within a minute.

https://sessionserver.mojang.com/session/minecraft/profile/437e69cba37037fe93743187d0b8fc6f
https://sessionserver.mojang.com/session/minecraft/profile/ede117a453863cdc95ed84d6ddab81e5
https://sessionserver.mojang.com/session/minecraft/profile/843ad167150d37a0af23625ed605f9aa
https://sessionserver.mojang.com/session/minecraft/profile/1e7acb2b05af331fae2b214e1e245f6a
https://sessionserver.mojang.com/session/minecraft/profile/fac52c0d303f346899921c2b145db937
https://sessionserver.mojang.com/session/minecraft/profile/8e17869595d637b5a717928e158606aa
https://sessionserver.mojang.com/session/minecraft/profile/d1934ed3e2e032efb38c03640cfe9c61
https://sessionserver.mojang.com/session/minecraft/profile/08f4c8168aca39d39d5d87de89fc2845
https://sessionserver.mojang.com/session/minecraft/profile/1cf2c20051283b12a73e416f5882f804
https://sessionserver.mojang.com/session/minecraft/profile/cd05124a339e37e38b874353f520d93c
https://sessionserver.mojang.com/session/minecraft/profile/da6ab8ee71ad46d29529cf95df6902b9