mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-02 02:43:44 +00:00
The XML upload is the one place hand-written XML reaches the game, whose load path trusts the XML because the server writes it itself. Instead of making the game skip bad data at load, the upload is checked against what the load path assumes and refused (400, with the problems) when the game couldn't load it: required elements, attributes that must parse (flags read with std::stoul/stoull), required item and mission fields, known inventory types, mission states and character versions, items and missions that exist in the CDClient, unique item IDs and slots, and the acct attribute matching the owner. Suspicious but loadable content is returned as warnings that need confirm=true (409 otherwise): contraband (same matching as the world, now shared in ContrabandRules.h), stacks above the stack size, coins, level or u-score out of reach, a GM level above the account's. Contraband marked flag-and-remove is removed only if the uploader asks; once stored, findings are flagged (CONTRABAND) and audited. The XML editor shows the findings and offers "Save anyway". Related: issue 1332. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
52 lines
2.1 KiB
C++
52 lines
2.1 KiB
C++
#ifndef __CONTRABAND__H__
|
|
#define __CONTRABAND__H__
|
|
|
|
#include <cstdint>
|
|
#include <map>
|
|
#include <string>
|
|
#include <vector>
|
|
|
|
#include "dCommonVars.h"
|
|
#include "eInventoryType.h"
|
|
#include "eLootSourceType.h"
|
|
#include "ContrabandRules.h"
|
|
|
|
class Entity;
|
|
|
|
/**
|
|
* Contraband (issue #1563): items staff don't want players to have, listed on the dashboard's Contraband page
|
|
* (IContraband). This world loads the list when it is first needed and again when the dashboard changes it
|
|
* (ePlayerAction::RELOAD_CONTRABAND).
|
|
*
|
|
* - When a character loads (before it is sent to the client), every inventory (vault included) is checked. Each
|
|
* listed item is flagged (an economy flag of kind CONTRABAND, once per item). Items whose entry says so are removed
|
|
* too: a snapshot of the character is kept first (so the dashboard's "Give back lost items" can return them), the
|
|
* removal is audited and the player gets a mail saying why.
|
|
* - When a listed item is added (loot, trade, mail, vendors, ...), the character is flagged for that item for the
|
|
* day, and an item to remove is removed right after it arrives, with a chat message saying why.
|
|
*
|
|
* Staff accounts (GM level above civilian) are not checked unless contraband_ignore_staff is 0.
|
|
*/
|
|
namespace Contraband {
|
|
// ---- Pure rules, unit tested (Entry, List, HeldItem, Finding, Find and Applies are in ContrabandRules.h) ----
|
|
|
|
// Whether an added item should be checked: moves between a player's own inventories are not new items
|
|
bool CountsAsAdded(eLootSourceType source, eInventoryType sourceInventory);
|
|
|
|
// ---- This world ----
|
|
|
|
// Load the list again from the database. Returns 1 (one world reloaded).
|
|
uint32_t Reload();
|
|
|
|
// The list as loaded (loads it the first time)
|
|
const List& Get();
|
|
|
|
// Check a player's inventories when their character loads, before it is sent to the client
|
|
void CheckOnLoad(Entity* player);
|
|
|
|
// A listed item was added to a player's inventory (called for every add; cheap when the LOT isn't listed)
|
|
void OnItemAdded(Entity* owner, LOT lot, uint32_t count, eLootSourceType source, eInventoryType sourceInventory);
|
|
}
|
|
|
|
#endif //!__CONTRABAND__H__
|