Skip to content

v2.47.0

Choose a tag to compare

@github-actions github-actions released this 14 May 08:28
· 47 commits to main since this release

This release patches some potential vulnerabilities with modifying inventory state during actions, leading to incorrect item removal.

For third-party resources, new features have been added to improve security and reliability.

You can now register stashes with an instance field, which prevents any player from accessing it unless their instance state has been set to the same value. Note this is technically only secure when using strict statebags.

I have also added post-hook events to correctly support scripts that wish to run custom logic after completing certain actions. Many third-party scripts previously registered hooks which would trigger "side-effects", such as modifying an item or giving items when the hook ran. This leads to major issues and exploits, as hooks run before such an action has been completed and could still fail for a number of reasons (including other hooks rejecting it).

Hook callbacks are intended for validation only and should avoid side effects such as modifying data, writing to a database, or triggering additional operations.

Because actions may still be in progress or may fail, modifying item or inventory state before completion can lead to race conditions or inconsistent behavior.

To avoid issues, perform state changes or follow-up logic in post-hook events.

You can now safely run such logic after actions have been validated internally and by other hooks by using the hookId (returned by registerHook) as an event. The hook callback is also now optional if you only need to use the built-in filters and don't require custom validation.

---Use filter logic so only relevant inventories trigger the post-hook event.
local hookId = exports.ox_inventory:registerHook('swapItems', nil, {
    inventoryFilter = {
        '^glove[%w]+',
        '^trunk[%w]+',
    }
})
 
---Print everytime an item is moved to or from a vehicle inventory.
---Success will be false if the hook rejected the action or it failed elsewhere.
AddEventHandler(hookId, function(success, payload)
    print(hookId, success)
    lib.print.info(payload)
end)

Features

  • server/inventory: add instance field to registered stashes (Linden)
  • server: add instance validation to openInventory callback (Linden)
  • implement basic locks manager (Linden)
  • server/hooks: new hookId format and include id in payload (Linden)
  • server/hooks: Add post-action events to event hooks (Linden)
  • server/items: add invoking resource to createItem hook payload (Linden)

Bug Fixes

  • client: ensure currentInventory is always defined, type fixes (Linden)
  • server/inventory: ensure player inventory is open before swap (Linden)
  • client: always trigger closeInventory event on close (Linden)
  • client/inventory: clear evidence.zoneId (Linden)
  • server/crafting: add locks to crafting ingredients (Linden)
  • server/crafting: return if locks fail (Linden)
  • client: set coords when opening inventory (Linden)
  • server: add locks to useItem (Linden)
  • server/inventory: extra Inventory.SetSlot arg validation (Linden)
  • server/inventory: extra Inventory.RemoveItem arg validation (Linden)
  • server/inventory: inconsistent inventory.openedBy behaviour (Linden)
  • server/inventory: SetSlot error checking (Linden)
  • server/shops: add better fallbacks for openShop hook (#1933) #1933 (JHansen2000)
  • server/inventory: disallow negative values when updating weapons (Linden)
  • client: don't set coords on default inventory (Linden)
  • client: support txadmin's heal event (Linden)
  • server/inventory: SetSlot return value on item deletion (Linden)
  • server/inventory: typo in RemoveItem (Linden)

Code Refactoring

  • sync inventory.instance to client (Linden)
  • server/inventory: use Locks with swapItems and giveItem (Linden)
  • server/inventory: use more descriptive lock ids (Linden)
  • locks: take an array rather than varargs (Linden)
  • client: allow movement while using drop (Linden)
  • server/hooks: don't format post-hook event names (Linden)

Chores