All news
UpdatesAugust 26, 2026

MLSAC b54: modules, a reserve endpoint and per-command permissions

Every feature is switched in modules.yml, the plugin fails over to a reserve API on its own, each command has its own permission, and Anti-ESP is rewritten.

The key and the preset name in config.yml, then mlsac reload: two seconds later it is connected and the preset is applied.

A large update — 1.0-b54. The config migrates to the new layout automatically; the API key and preset are kept.

modules.yml

What runs on the server is now decided by one file — modules.yml: detection, Anti-ESP, reports, menus, MLS Vision and update notifications. A disabled module stops completely: its tasks are not scheduled, its listeners are not registered and its commands answer that the feature is off. Apply changes with /mlsac reload.

Modules with many settings got their own files under modules/ — for example modules/anti-esp.yml. config.yml keeps the core: language, API key, server identity and platform.

Reserve endpoint

A new reserve-endpoint setting (https://ruapi.mlsac.net by default). If the primary address cannot be reached at all — a timeout, a refused connection or a DNS failure — the plugin switches to the reserve. An HTTP error (a wrong key, say) is an answer, not an outage, so it never triggers the switch. The primary is tried first again on the next reconnect.

Per-command permissions

Every subcommand has its own node: mlsac.command.alerts, mlsac.command.suspects, mlsac.command.punish, mlsac.command.reload and more. Notifications are separate: mlsac.notify.alerts and mlsac.notify.reports. The old coarse permissions still work, so existing rank setups need no changes.

Anti-ESP

The engine is rewritten:

  • nothing changes server-side — players are never hidden through the Bukkit API and other plugins see a normal player; only the packets to a given viewer are filtered;
  • when a player reappears their full look is restored: skin layers, armour, pose, potion invisibility, name tag;
  • a hard time budget per pass (budget_micros_per_pass), so a full server never gets a tick spike from it;
  • raytrace results are cached while neither player moves;
  • sounds and the glowing outline of hidden players can be suppressed;
  • optional hiding of players outside the field of view (hide_outside_fov), strongest against radar ESP;
  • the mlsac.bypass and mlsac.antiesp.bypass permissions exempt a player.

Reports and punishments

  • The cooldown between reports is configurable (reports-cooldown-seconds); staff with mlsac.notify.reports are not held to it.
  • A safe-name-check option: a player with an unsafe name (spaces, Geyser/Floodgate prefixes) is kicked by the API rather than by a console command that could hit someone else.