IMIsle Modkit
Pages in this area

Admin checks

sv_admins is the simple switch between admins and everybody else. For finer roles such as moderators or VIPs use groups and permissions, see Bans, whitelist and permissions.

Admins are the Steam IDs in sv_admins in server.cfg.

sv_admins 76561198000000001,76561198000000002

The runner uses the list twice. It writes the IDs into Game.ini as game admins, and it hands them to the server plugin for scripts. A change needs a server restart.

Three ways to check

Admin-only command. The check happens before your function runs.

modkit.commands.add("kickall", function(player)
  for _, other in ipairs(modkit.players.list()) do
    if not other.admin then other:kick("server cleanup") end
  end
end, true)

The admin field of a player table.

modkit.events.add("requestAdminPanel", function(player)
  if not player.admin then
    print(player.steamId .. " asked for the admin panel without rights")
    return
  end
  player:call("openAdminPanel")
end)

A Steam ID you got from somewhere else.

if modkit.isAdmin(steamId) then ... end

Always check on the server

A client script can hide a button, but that is no protection. Every client can send any event with any arguments. The server handler has to check player.admin itself. The player table on the server comes from the connection and can not be faked by the message.

Where to put admin actions

player.steamId in chat commands and game events comes from the game server itself.

  • Chat commands are the right place for admin actions.
  • Do not put destructive admin actions behind a client event (callRemote) alone. Run them through a chat command.