admin & admin2: fix missing ACL rights #664
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR fixes missing ACL rights in the admin and admin2 resources.
When an ACL right isn’t set,
hasObjectPermissionTo
in admin & admin2 resources grants the permission by default (#663 will change that). This allowed cheaters to trigger certain actions from the client-side since no ACL right were explicitly set for them.admin/conf/ACL.xml
command.removefromteam
command.warpto
command.setlights
command.setplates
admin2/conf/ACL.xml
command.unfreeze
command.unmute
command.warpto
command.createteam
command.destroyteam
command.blowvehicle
command.destroyvehicle
command.shutdown
(already exists in default acl.xml, but added here just in case)