Files
DarkflameServer/dGame/dUtilities/Contraband.h
Aaron Kimbrell 6c414cec48 feat(dashboard): check uploaded character XML before storing it
The XML upload is the one place hand-written XML reaches the game, whose
load path trusts the XML because the server writes it itself. Instead of
making the game skip bad data at load, the upload is checked against
what the load path assumes and refused (400, with the problems) when the
game couldn't load it: required elements, attributes that must parse
(flags read with std::stoul/stoull), required item and mission fields,
known inventory types, mission states and character versions, items and
missions that exist in the CDClient, unique item IDs and slots, and the
acct attribute matching the owner.

Suspicious but loadable content is returned as warnings that need
confirm=true (409 otherwise): contraband (same matching as the world,
now shared in ContrabandRules.h), stacks above the stack size, coins,
level or u-score out of reach, a GM level above the account's.
Contraband marked flag-and-remove is removed only if the uploader asks;
once stored, findings are flagged (CONTRABAND) and audited. The XML
editor shows the findings and offers "Save anyway". Related: issue 1332.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:30:59 -05:00

52 lines
2.1 KiB
C++

#ifndef __CONTRABAND__H__
#define __CONTRABAND__H__
#include <cstdint>
#include <map>
#include <string>
#include <vector>
#include "dCommonVars.h"
#include "eInventoryType.h"
#include "eLootSourceType.h"
#include "ContrabandRules.h"
class Entity;
/**
* Contraband (issue #1563): items staff don't want players to have, listed on the dashboard's Contraband page
* (IContraband). This world loads the list when it is first needed and again when the dashboard changes it
* (ePlayerAction::RELOAD_CONTRABAND).
*
* - When a character loads (before it is sent to the client), every inventory (vault included) is checked. Each
* listed item is flagged (an economy flag of kind CONTRABAND, once per item). Items whose entry says so are removed
* too: a snapshot of the character is kept first (so the dashboard's "Give back lost items" can return them), the
* removal is audited and the player gets a mail saying why.
* - When a listed item is added (loot, trade, mail, vendors, ...), the character is flagged for that item for the
* day, and an item to remove is removed right after it arrives, with a chat message saying why.
*
* Staff accounts (GM level above civilian) are not checked unless contraband_ignore_staff is 0.
*/
namespace Contraband {
// ---- Pure rules, unit tested (Entry, List, HeldItem, Finding, Find and Applies are in ContrabandRules.h) ----
// Whether an added item should be checked: moves between a player's own inventories are not new items
bool CountsAsAdded(eLootSourceType source, eInventoryType sourceInventory);
// ---- This world ----
// Load the list again from the database. Returns 1 (one world reloaded).
uint32_t Reload();
// The list as loaded (loads it the first time)
const List& Get();
// Check a player's inventories when their character loads, before it is sent to the client
void CheckOnLoad(Entity* player);
// A listed item was added to a player's inventory (called for every add; cheap when the LOT isn't listed)
void OnItemAdded(Entity* owner, LOT lot, uint32_t count, eLootSourceType source, eInventoryType sourceInventory);
}
#endif //!__CONTRABAND__H__