Skip to content

Check permission and position in the lock, door and sign dialogs - #72

Open
expanderbult wants to merge 1 commit into
gurotopia:masterfrom
expanderbult:check-edit-permissions
Open

expanderbult wants to merge 1 commit into
gurotopia:masterfrom
expanderbult:check-edit-permissions

Conversation

@expanderbult

Copy link
Copy Markdown
Contributor

These dialogs trusted the tile position and the player. Anyone could send a lock_edit reply (with a modified client or proxy) and change any world's lock settings, edit doors and signs in locked worlds, or use a position outside the world, which writes outside world.blocks. lock_edit now needs the world owner and a lock at that position, door, sign and gateway edits need owner or access in locked worlds, positions are checked, and stoi() is replaced with atoi() so a missing checkbox can't throw and stop the server.

These dialogs trusted the tile position and the player. Anyone could send a lock_edit reply (with a modified client or proxy) and change any world's lock settings, edit doors and signs in locked worlds, or use a position outside the world, which writes outside world.blocks. lock_edit now needs the world owner and a lock at that position, door, sign and gateway edits need owner or access in locked worlds, positions are checked, and stoi() is replaced with atoi() so a missing checkbox can't throw and stop the server.
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 13 complexity · -1 duplication

Metric Results
Complexity 13
Duplication -1

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant