DevLeoko / AdvancedBan

AdvancedBan is a Spigot plugin to manage punishments on single servers and server networks
GNU General Public License v3.0
158 stars 130 forks source link

You can ban op's as a non-op, but only when the op is offline. #582

Open cakefarmer opened 2 years ago

cakefarmer commented 2 years ago

I'm using 2.3.0, the latest.

I have a paper server 1.17.1

Paper 1.17.1

Please provide the EXACT steps required to reproduce the problem... Log off. A helper with ban perms does any /ban command to the opped Admin Admin is banned

No logss

I feel like this could be taken advantage of by many servers. The helpers of my server told me about this, being an admin on a server. It's clearly not intended because you can't ban op's when they are online.

cakefarmer commented 2 years ago

This only applies to the people with advancedban.ban perm

Hopefuls commented 2 years ago

depending on what permission system you're using, using Luckperms with exempt permissions should counter that as these ones work offline.

cakefarmer commented 2 years ago

I am using LuckPerms currently

Hopefuls commented 2 years ago

using Luckperms with exempt permissions should counter that as these ones work offline.

If you have not setup exempt perms, then banning a user offline will still ban them.