Tab completion for triggers are visible even without permissions
wysohn opened this issue · 0 comments
Describe the bug/버그 증상
Player can use tab completion function to reveal the name of triggers. This can be a problem for the non-experienced administrator, who does not know how to set permissions, because they may try to hide some hidden commands, yet it can be seen by any user using tab completion function. If the trigger has some script that may cause a huge impact on the server, it can lead to a huge security breach.
The best practice is using $haspermission or $isop to prevent players without permission to access such triggers, yet not lots of users are experienced in this area. It still leaves the hole where a random user can find such triggers by random chance, yet that's really up for the administrators to handle.
Server information/서버 정보
1.14.4 (yet it is likely to be a problem for any 1.13+ servers)
TriggerReactor 3.0.4
Error message/에러 메시지
This is not an error