Skip to main content
UgCore permissions are FiveM ACEs. A grant runs add_ace identifier.<id> <permission> allow, so ACE checks everywhere, including IsPlayerAceAllowed in other resources, see it.

Setup

ug-core needs permission to run add_ace and remove_ace:
server.cfg
Without it, boot prints ug-core cannot run add_ace. Add add_ace resource.ug-core command allow to server.cfg. in red, and grants cannot be applied.

Two ways to give permissions

Classic ACEs and principals keep working:
server.cfg
UgCore.Permissions.Has(source, permission) is a plain ACE check, so both ways count.

Permissions used by ug-core

Resources declare their own permissions on callbacks, net events and commands with the permission option.

Safety

Permission names and identifiers end up in a server command, so UgCore only accepts letters, digits, dots, dashes and underscores for permissions, and type:value identifiers. Anything else raises before reaching ExecuteCommand.