Admin checks
sv_admins is the simple switch between admins and everybody else. For finer roles such as moderators or VIPs use groups and permissions, see Bans, whitelist and permissions.
Admins are the Steam IDs in sv_admins in server.cfg.
sv_admins 76561198000000001,76561198000000002
The runner uses the list twice. It writes the IDs into Game.ini as game admins, and it hands them to the server plugin for scripts. A change needs a server restart.
Three ways to check
Admin-only command. The check happens before your function runs.
modkit.commands.add("kickall", function(player)
for _, other in ipairs(modkit.players.list()) do
if not other.admin then other:kick("server cleanup") end
end
end, true)
The admin field of a player table.
modkit.events.add("requestAdminPanel", function(player)
if not player.admin then
print(player.steamId .. " asked for the admin panel without rights")
return
end
player:call("openAdminPanel")
end)
A Steam ID you got from somewhere else.
if modkit.isAdmin(steamId) then ... end
Always check on the server
A client script can hide a button, but that is no protection. Every client can send any event with any arguments. The server handler has to check player.admin itself. The player table on the server comes from the connection and can not be faked by the message.
Where to put admin actions
player.steamId in chat commands and game events comes from the game server itself.
- Chat commands are the right place for admin actions.
- Do not put destructive admin actions behind a client event (
callRemote) alone. Run them through a chat command.