LuckPerms

LuckPerms

41.4k Downloads

[Suggestion] Prevent non-player sources from executing commands

shinyafro opened this issue ยท 1 comments

commented

Was asking if there was such a feature on the discord when i was informed there was not, so i was going to write my own little plugin however some of the guys thought it was a good idea to suggest it here so i did just that.

The idea would mainly be relevant for insecure servers, specifically modded - to disable command blocks and console sources from executing commands on luckperms. This could be done on a per-server basis, so you could have newer modpacks or servers where say command blocks are allowed, to not execute commands on luckperms from non-player sources, but allow it on hubs where it's pretty secure, being just vanilla and no mods with various undocumented "features" or exploits that can be abused with any number of commands such as /give. I notice a lot of servers get hit by obscure exploits, which invariably somehow give the player OP or in sponges case just really only leaves execution via a remote non-player command source. This would break any such exploit chains that do not include the player, and isolates mods from the equation and contain such exploits to their occurring server rather then allowing all other servers to be targeted. .

commented

Closing for now - please see my comment on #2633