Mojira Archive
MC-155711

Functions capable of running commands they shouldn't be able to (publish, debug ...)

Functions are able to run commands that mess with server-wide lists (/op, /deop, /ban, /pardon, /whitelist), mess with filesystem (/save-all, /save-off, /save-on, /debug), and mess with network stuff (/publish).

Restricting functions to a lower OP level would cause problems as maps (including on realms) now rely on functions being able to run commands like /forceload. The following commands that maps may rely on should first be moved to OP level 2:

  • /reload - Niche uses for packs with optional add-ons, can also be achieved with /datapack so no security benefit for restricting
  • /forceload - Widespread usage for maps loading arenas and keeping chunks loaded for storage, negative effects are limited to world (as with mass-summoning entities)
  • /kick - Convenient way to remove a player, no permanent effects

Fixed

SirBenet

[Mojang] Bartosz Bok

2019-07-01, 02:16 AM

2020-08-13, 06:50 PM

2019-07-10, 02:27 PM

1

3

Unconfirmed

(Unassigned)

Minecraft 1.14.3

Minecraft 1.14.4 Pre-Release 4