Compare commits

...

2 Commits

Author SHA1 Message Date
Jim Shield
0bc3c0f9b4 Update itemcontrol.lua 2025-10-03 17:44:29 +01:00
Jim Shield
672dd7684b Fix ESX authtoken callback saying possible exploit 2025-10-03 13:51:15 +01:00
2 changed files with 22 additions and 5 deletions

View File

@@ -7,14 +7,22 @@ AuthEvent = nil
currentToken = nil
if isServer() then
local excludeRes = {
[Exports.QBExport] = true,
[Exports.ESXExport] = true,
[Exports.VorpExport] = true,
}
local AuthEvent = getScript()..":"..keyGen()..keyGen()..keyGen()..keyGen()..":"..keyGen()..keyGen()..keyGen()..keyGen()
validTokens = validTokens or {}
createCallback(AuthEvent, function(source)
local src = source
local token = keyGen()..keyGen()..keyGen()..keyGen() -- Use a secure random generator here
--debugPrint(GetInvokingResource())
if GetInvokingResource() and GetInvokingResource() ~= getScript() and GetInvokingResource() ~= Exports.QBExport and GetInvokingResource() ~= Exports.VorpExport then
local invokingRes = GetInvokingResource()
debugPrint(invokingRes)
if invokingRes and invokingRes ~= getScript() and not excludeRes[invokingRes] then
debugPrint("^1Error^7: ^1Possible exploit^7, ^1vital function was called from an external resource^7")
return ""
end
@@ -47,9 +55,9 @@ if isServer() then
createCallback(getScript()..":callback:GetAuthEvent", function(source)
local src = source
--debugPrint(GetInvokingResource())
local invokingRes = GetInvokingResource()
if GetInvokingResource() and GetInvokingResource() ~= getScript() and GetInvokingResource() ~= Exports.QBExport and GetInvokingResource() ~= Exports.VorpExport then
if invokingRes and invokingRes ~= getScript() and not excludeRes[invokingRes] then
debugPrint("^1Error^7: ^1Possible exploit^7, ^1vital callback was called from an external resource^7")
return ""
end

View File

@@ -1338,10 +1338,12 @@ end
--- ```
function getPlayerInv(src)
local grabInv = nil
local foundInv = ""
for i = 1, #InvFunc do
local inv = InvFunc[i]
if isStarted(inv.invName) then
foundInv = inv.invName
grabInv = inv.getPlayerInv(src)
break
end
@@ -1364,6 +1366,7 @@ function getPlayerInv(src)
grabInv = xPlayer and xPlayer.inventory or {}
end
end
--jsonPrint(grabInv)
end
if grabInv == nil then
@@ -1958,7 +1961,7 @@ function getCurrentInvWeight(src)
if weight == 0 then
local itemcheck = getPlayerInv(src)
for _, v in pairs(itemcheck) do
weight += ((v.weight * v.amount) or 0)
weight += ((v.weight * (v.amount or v.count)) or 0)
end
end
return weight
@@ -2356,6 +2359,8 @@ function stashRemoveItem(stashItems, stashName, items)
return
end
end
-- Fallback to core functions
if isStarted(QBExport) then
local stashItems = getStash(stashName[1])
for k, v in pairs(items) do
@@ -2382,6 +2387,10 @@ function stashRemoveItem(stashItems, stashName, items)
end
RegisterNetEvent(getScript()..":server:stashRemoveItem", stashRemoveItem)
function stashAddItem(stashItems, stashName, items)
-- wip
end
-------------------------------------------------------------
-- Stash Item Availability Check
-------------------------------------------------------------