🔒 Security & Whitelist Fixes
• Refused Before They Join - Players who are not on the list are refused while they log in. OrangeWhitelist 3 let them into the world first: they showed up in the tab list, got player data files, and the kick message was sometimes lost
• A Typo Never Empties the List - A YAML error in Settings.yml used to reset it to the defaults, put the example list back and kick everyone. Now the file is never overwritten: the previous settings stay (at startup the whitelist stays ON with the defaults) and the console says what is wrong
• Whitelist.yml - The list has its own file, created on the first start and written safely so it is never half-saved; the list of OrangeWhitelist 3 moves there by itself. A Whitelist.yml with an error is never written over
• Bans That Hit the Right Player - Mode: BAN used the server's ban list by name, which before 1.20.4 asks Mojang for the account: on offline-mode servers the ban could land on another account, and the server froze while Mojang answered. Bans now go to OrangeWhitelist's own list, Bans.yml, by the UUID the player joined with, the same on every version
• No Example Players - New installs start with an empty list (3.x came with Notch and TeoremalDev); if your list still has them, the console tells you
• Removing Kicks Only When It Should - /owl remove no longer kicks a player while the whitelist is OFF or when the player has the bypass permission
• Safe Mode Values - An unknown Mode (like KIK) turned the whitelist off without a word; now it warns and uses KICK. The same goes for Hook
• Permission Defaults - The bypass and anti-remove permissions are no longer given to every operator by default
• Discord Bot Locked Down - With no Authorized-Roles, anyone could use the bot, even in private messages. Now only the listed roles and the bot's owner (or its team) can use it, and only inside Discord servers
🤖 Discord Bot Rebuilt
• No Reconnect Loops - A wrong token no longer reconnects forever and piles up threads: the bot stops with one clear message, and /owl reload tries again
• Stays Connected - Heartbeats, session resuming and reconnection follow Discord's rules, so the bot comes back by itself for as long as it is enabled
• Never Blocks the Server - Everything that talks to Discord runs off the main thread; whitelist changes are then made on it
• /whitelist list - A new subcommand, plus autocomplete: recently refused players for add, whitelisted players for remove
• Tidy Answers - Errors and the list are only shown to the member who used the command; changes are posted in the channel
• No Extra Libraries - The bot no longer needs OkHttp or Kotlin, and Application-ID is not needed any more (the bot reads it from Discord)
✨ New Features
• /owl list - Shows who is on the whitelist
• Name Checks - /owl add refuses names that cannot be Minecraft players; Bedrock names with a Floodgate prefix (like .Steve) are accepted
• Bans Lifted on Add - In Mode: BAN, adding a player lifts the ban OrangeWhitelist gave them; bans made by anyone else (or through LiteBans) stay
• Colored Ban Reasons - Ban-Message accepts MiniMessage
• Smarter Tab Completion - /owl only offers the subcommands you may use; add suggests recently refused players and remove suggests names on the list
• Honest Replies - When Settings.yml, Whitelist.yml or Bans.yml cannot be read or written, the command says so (Messages.Write-Failed) and nothing changes, and /owl reload no longer answers "Plugin ready!" over a file with an error
• Settings.yml Kept Up To Date - Missing keys come back with their comments while your values stay; the old file is copied to old-configs/ and %player% becomes {player}. The file is no longer rewritten on every start, and blank lines in Kick-Message survive
• Update Notice - The update check can be turned off (Update-Checker), only reports versions newer than yours, and also tells admins (orangewhitelist.admin) when they join
• Empty-List Warning - The console warns when the whitelist is ON and nobody is on it
🕹️ Built for 1.8.8 - 26.3
• One Jar, Every Version - Spigot and Paper from 1.8.8 up to 26.3, on Java 8 and every newer Java
• Nothing Downloaded at Startup - OrangeWhitelist 3 made servers 1.16.5+ download Adventure from Maven Central at every first start without using it; now nothing is downloaded
• Hex Colors Where They Show - Hex colors are used on 1.16+ and the nearest classic color before
• Quiet on Paper 1.21.6+ - Unless the bypass permission is on, OrangeWhitelist no longer listens to the login step, so Paper keeps its re-configuration features and does not warn about it
• LiteBans - LiteBans is detected when a ban is made; the Hook setting is never rewritten, and the soft dependency works again
• Clean Logs - One startup line with the version, whitelist state, players and mode; no banner or escape codes in the log files
⚠️ Important Changes
• Whitelist.yml - The whitelist is no longer in Settings.yml: it moves to Whitelist.yml by itself
• Bans.yml - Mode: BAN bans in Bans.yml now. Players banned by OrangeWhitelist 3 stay in the server's ban list: lift them with /pardon <name>
• Discord Permissions - Without Authorized-Roles only the bot's owner can use /whitelist: add your staff role IDs, in quotes
📋 Update Instructions
1. BACKUP YOUR DATA - copy plugins/OrangeWhitelist before updating
2. Stop your server
3. Replace the old jar with OrangeWhitelist-4.0.jar
4. Start your server: Settings.yml is updated keeping your values and your list moves to Whitelist.yml
5. Using the Discord bot? Put your staff role IDs in Discord-Bot.Authorized-Roles
🔍 Technical Details
For server administrators interested in the technical details:
• Rewritten against Spigot API 1.8.8 for Java 8: one jar for Spigot and Paper 1.8.8 - 26.3 on Java 8 to 25
• Adventure 4.26.1 (MiniMessage, legacy and plain text) relocated and trimmed to the classes used; no other libraries. The jar is 0.8 MB
• Discord: its own WebSocket client (RFC 6455) on gateway v10 with heartbeats, resume and reconnection, and REST v10 with rate limits; /whitelist is registered only when it changed
• 58 automated tests, including the Discord bot against a local gateway and API, the ban list and the conversion of OrangeWhitelist 3 settings
• Tested with bot players on Paper 1.8.8, 1.12.2, 1.16.5, 1.21.11 and 26.3 and on Spigot 1.21.11 and 26.3: refusals at login (every kick message delivered, nothing saved for refused players), Mode: BAN with Bans.yml and /owl add, broken Settings.yml and Whitelist.yml at startup and on /owl reload, fresh installs, the bypass permission, tab completion, RCON and the aliases
• Settings of OrangeWhitelist 3.0 and 3.1 converted on each of those versions, custom messages included; a refused Discord token stops the bot cleanly and /owl reload tries once more