Pumpkin-MC/Pumpkin · error · VelocityError
Unable to verify player details
Error message
Unable to verify player details
What it means
VelocityError variant fired when the HMAC-SHA256 integrity check over the forwarded player data fails — the payload was tampered with or the forwarding secret mismatches between Velocity and the backend.
Solutions
- Reject the connection as untrusted
- Ensure Velocity's forwarding-secret file matches the backend config
- Log the verification failure at warn level
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at crates/pumpkin/src/net/proxy/velocity.rs:33 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of Pumpkin-MC/Pumpkin@8d4639e25a (2026-09-09).
Data as JSON: /api/errors/9cb6584534275a54.
Report an issue: GitHub.
Appendix: source
Thrown at crates/pumpkin/src/net/proxy/velocity.rs:33
use std::{
io::Read,
net::{IpAddr, SocketAddr},
};
use thiserror::Error;
use tracing::debug;
use crate::net::{GameProfile, java::pending::PendingConnection};
type HmacSha256 = Hmac<Sha256>;
const MAX_SUPPORTED_FORWARDING_VERSION: u8 = 4;
const PLAYER_INFO_CHANNEL: &str = "velocity:player_info";
#[derive(Error, Debug)]
pub enum VelocityError {
#[error("No response data received")]
NoData,
#[error("Unable to verify player details")]
FailedVerifyIntegrity,
#[error("Failed to read forward version")]
FailedReadForwardVersion,
#[error("Unsupported forwarding version {0}. Maximum supported version is {1}")]
UnsupportedForwardVersion(u8, u8),
#[error("Failed to read address")]
FailedReadAddress,
#[error("Failed to parse address")]
FailedParseAddress,
#[error("Failed to read game profile name")]
FailedReadProfileName,
#[error("Failed to read game profile UUID")]
FailedReadProfileUUID,
#[error("Failed to read game profile properties")]
FailedReadProfileProperties,
}
pub async fn velocity_login(connection: &mut PendingConnection) {View on GitHub (pinned to 8d4639e25a)