-
Notifications
You must be signed in to change notification settings - Fork 0
Security and Permissions
This page is for server owners installing Arcadia Studio projects and for authors who want to build safe screens.
- Arcadia Studio never grants extra permissions. Commands run as the clicking player by default.
- Players' game clients can only say "I clicked this control". What happens next is decided by the server, from the project installed on the server.
- Treat installed projects like server configuration: they can run commands and scripts. Only install projects you trust.
- The player has an Arcadia Studio screen open, and the message carries that screen's session token.
- The control exists, supports that event, and is visible and enabled (including its panels and any conditions), according to the server's state.
- The input is the right type and size (text up to 1024 characters, numbers in range, valid row index…).
- The player meets the handler's permission level, and its cooldown has passed.
- The player hasn't sent more than 20 events this tick.
Only then are the server actions run. Commands are fixed text from the installed project; player input is never inserted into them.
- Built-in
commandactions run as the player by default, so a button can't do anything the player couldn't type. - The server config option
runCommandsAsServer(off by default) makes built-in command actions run with server authority. Enabling it means every permitted button in every installed project can run its command as the server. Only enable it if you've reviewed those projects. -
ctx.server.runCommandin Standard Server scripts always uses the player's permissions, even with that option on, because scripts can build commands from player input. - KubeJS handlers are trusted server code; KubeJS's own
runCommandSilentuses server authority.
- Use Permission level (Events → Server) for admin-only buttons.
- In server scripts, double-check with
ctx.player.hasPermission(level)before doing anything powerful. - For Item List rows, look up the row index in your own data; never trust an item ID or amount from the client.
- Keep the default cooldown (4 ticks) or raise it for expensive actions.
- For distribution to players, prefer the Installation ZIP: the client JARs don't contain your server code.
- Standard scripts run in Arcadia Studio's bundled JavaScript engine, with no access to Java classes, files, the network or processes, and with statement, time and output limits.
- Server scripts also have a per-player time budget: a player who triggers scripts too quickly has their scripts paused, and the server log says so.
- The engine runs inside Minecraft without its own memory cap. These limits stop accidents and casual abuse, but they aren't a hostile-code sandbox. Install trusted projects.
- The editor's Preview runs scripts in a separate, restricted process.
Projects are read directly from their archives without extracting. Unsafe paths, oversized files, too many files and symbolic links are rejected. A broken or unsafe project is skipped and logged; other projects still load.
The MCP server only listens on your own computer (127.0.0.1) and requires a random access token that changes every time it starts. Browser pages can't connect. Treat the copied connection settings like a password: anyone with them can read and edit the open project. See AI assistants (MCP).
Arcadia Studio 1.2 manual · Minecraft 1.21.1 / NeoForge · Home · Keyboard shortcuts · Troubleshooting
Getting started
Designing
- Projects and screens
- Controls
- Canvas editing
- Properties and appearance
- Layers and groups
- Panels and parenting
- Anchors and responsive
- Align and distribute
- Components
- Assets and items
- Pixel art and sprites
- Music and sound effects
- Item lists
Behavior
Shipping
Extras