add_ace identifier.<id> <permission> allow, so ACE checks everywhere, including IsPlayerAceAllowed in other resources, see it.
Setup
ug-core needs permission to runadd_ace and remove_ace:
server.cfg
ug-core cannot run add_ace. Add add_ace resource.ug-core command allow to server.cfg. in red, and grants cannot be applied.
Two ways to give permissions
- server.cfg
- UgCore API
Classic ACEs and principals keep working:
server.cfg
UgCore.Permissions.Has(source, permission) is a plain ACE check, so both ways count.
Permissions used by ug-core
Resources declare their own permissions on callbacks, net events and commands with the
permission option.
Safety
Permission names and identifiers end up in a server command, so UgCore only accepts letters, digits, dots, dashes and underscores for permissions, andtype:value identifiers. Anything else raises before reaching ExecuteCommand.