Permissions
Staff detection and per-action gates run through the framework bridge (bridge/*.lua). Config.Permissions.* map to capability keys, and the active adapter decides who holds them.
That means the setup differs per framework: VORP uses its own groups, RSG checks rsg-core first then ACE, and RedEM:RP and standalone use ACE only.
Capability keys
| Key | Controls |
|---|---|
staff | Base staff detection — see all reports, tools shown |
close / reopen | Close and reopen reports |
delete | Delete reports |
adminActions | Go To, Bring, Revive, Freeze, Heal, Disarm, Jail — and Transfer |
punish | Warn, Kick, Ban |
priority | Change report priority — also gates tags |
notes | Player notes and internal notes |
blocks | Block and unblock players |
staffChat | The staff-only chat channel |
spectate | Spectate |
dashboard | Staff dashboard, statistics and blips |
media | Staff-triggered screenshots |
Create and Review are open to all players by default. The block list still applies to Create.
VORP — group based
Staff come from the VORP user group (user.getGroup), not the character group. Defaults live in bridge/vorp.lua:
| Group | Access |
|---|---|
owner / superadmin / admin | Everything |
headmoderator / moderator | Staff tools, no delete |
discordmoderator | Limited — no delete, adminActions, spectate or blocks |
helper | Not staff |
Edit the GROUPS table in bridge/vorp.lua to change which group gets which capability.
User group, not character group
This is the most common VORP setup mistake. A player can have an admin character group and still not be detected as staff. The user group is what counts.
RSG Core
Checks rsg-core permissions first, then falls back to ACE:
god/admin→ everythingmod/moderator→ base staff tier- otherwise ACE (
pc_reports.*)
Tune the FULL and LIMITED lists at the top of bridge/rsg.lua.
RedEM:RP & Standalone — ACE
Grant staff through ACE, in install/permissions.cfg:
add_ace group.mod pc_reports.staff allow # base staff tier
add_ace group.admin pc_reports.all allow # everything
add_principal identifier.license:xxxx group.modRemember to exec that file from your server.cfg.
What the base tier includes
pc_reports.staff grants: close, reopen, priority, notes, tags, staffChat, dashboard, media.
It deliberately withholds: delete, adminActions, spectate, blocks, punish. Grant those explicitly, or use pc_reports.all.
Granular example
add_ace group.seniormod pc_reports.staff allow
add_ace group.seniormod pc_reports.adminActions allow
add_ace group.seniormod pc_reports.delete allow
add_ace group.admin pc_reports.punish allowWhat to gate tightly
| Capability | Give it to |
|---|---|
staff, close, reopen, notes, staffChat | All staff |
adminActions, spectate | Moderators and up |
punish | Trusted staff only — this is warn/kick/ban |
delete | Trusted admins only — this destroys the record |
blocks | Moderators and up |
dashboard | Leadership |
Deleting is not closing
Closing preserves the ticket, its chat log, media and audit trail. Deleting destroys them. Staff should close; delete belongs to a very short list of people.
Refreshing permissions
If you change a player's group or ACEs while they are online, they can run:
/refresh_report_permissionsThis re-syncs without a reconnect. Run it after every permission change — otherwise you will be debugging a problem you already fixed.
Anti-exploit
Sensitive client effects — revive, freeze, heal, disarm — use a server-side grant list. A client firing those events without a staff-issued grant is dropped.
The report view and every mutating event are permission-checked server-side. The interface only draws buttons you are allowed to use, but that drawing is cosmetic: a modified client can render itself a Ban button and the server will still refuse it.
Troubleshooting access
Staff not detected — no dashboard, no tools
- Check the console for
Framework bridge: <name>. Wrong framework? SetConfig.Framework.force. - VORP — confirm the user group is in the
GROUPStable inbridge/vorp.lua. - RSG — needs
god/admin/mod, or an ACE. - RedEM / Standalone — confirm the ACEs are granted and
install/permissions.cfgisexec'd. - Run
/refresh_report_permissions.
Bridge says standalone but I run VORP or RSG
Your framework started after pc_report, or its folder name differs from Config.Framework.resourceNames. Fix the load order first.
RSG and RedEM adapters
These adapters ship with sensible defaults but were not tested against a live core. If staff detection misbehaves, edit the permission maps at the top of bridge/rsg.lua or bridge/redp.lua.