Skip to content

Permissions ​

Staff detection and per-action gates run through the framework bridge (bridge/*.lua). Config.Permissions.* map to capability keys, and the active adapter decides who holds them.

That means the setup differs per framework: VORP uses its own groups, RSG checks rsg-core first then ACE, and RedEM:RP and standalone use ACE only.

Capability keys ​

KeyControls
staffBase staff detection — see all reports, tools shown
close / reopenClose and reopen reports
deleteDelete reports
adminActionsGo To, Bring, Revive, Freeze, Heal, Disarm, Jail — and Transfer
punishWarn, Kick, Ban
priorityChange report priority — also gates tags
notesPlayer notes and internal notes
blocksBlock and unblock players
staffChatThe staff-only chat channel
spectateSpectate
dashboardStaff dashboard, statistics and blips
mediaStaff-triggered screenshots

Create and Review are open to all players by default. The block list still applies to Create.

VORP — group based ​

Staff come from the VORP user group (user.getGroup), not the character group. Defaults live in bridge/vorp.lua:

GroupAccess
owner / superadmin / adminEverything
headmoderator / moderatorStaff tools, no delete
discordmoderatorLimited — no delete, adminActions, spectate or blocks
helperNot staff

Edit the GROUPS table in bridge/vorp.lua to change which group gets which capability.

User group, not character group

This is the most common VORP setup mistake. A player can have an admin character group and still not be detected as staff. The user group is what counts.

RSG Core ​

Checks rsg-core permissions first, then falls back to ACE:

  • god / admin → everything
  • mod / moderator → base staff tier
  • otherwise ACE (pc_reports.*)

Tune the FULL and LIMITED lists at the top of bridge/rsg.lua.

RedEM:RP & Standalone — ACE ​

Grant staff through ACE, in install/permissions.cfg:

cfg
add_ace group.mod   pc_reports.staff allow   # base staff tier
add_ace group.admin pc_reports.all   allow   # everything
add_principal identifier.license:xxxx group.mod

Remember to exec that file from your server.cfg.

What the base tier includes ​

pc_reports.staff grants: close, reopen, priority, notes, tags, staffChat, dashboard, media.

It deliberately withholds: delete, adminActions, spectate, blocks, punish. Grant those explicitly, or use pc_reports.all.

Granular example ​

cfg
add_ace group.seniormod pc_reports.staff        allow
add_ace group.seniormod pc_reports.adminActions allow
add_ace group.seniormod pc_reports.delete       allow
add_ace group.admin     pc_reports.punish       allow

What to gate tightly ​

CapabilityGive it to
staff, close, reopen, notes, staffChatAll staff
adminActions, spectateModerators and up
punishTrusted staff only — this is warn/kick/ban
deleteTrusted admins only — this destroys the record
blocksModerators and up
dashboardLeadership

Deleting is not closing

Closing preserves the ticket, its chat log, media and audit trail. Deleting destroys them. Staff should close; delete belongs to a very short list of people.

Refreshing permissions ​

If you change a player's group or ACEs while they are online, they can run:

/refresh_report_permissions

This re-syncs without a reconnect. Run it after every permission change — otherwise you will be debugging a problem you already fixed.

Anti-exploit ​

Sensitive client effects — revive, freeze, heal, disarm — use a server-side grant list. A client firing those events without a staff-issued grant is dropped.

The report view and every mutating event are permission-checked server-side. The interface only draws buttons you are allowed to use, but that drawing is cosmetic: a modified client can render itself a Ban button and the server will still refuse it.

Troubleshooting access ​

Staff not detected — no dashboard, no tools

  1. Check the console for Framework bridge: <name>. Wrong framework? Set Config.Framework.force.
  2. VORP — confirm the user group is in the GROUPS table in bridge/vorp.lua.
  3. RSG — needs god/admin/mod, or an ACE.
  4. RedEM / Standalone — confirm the ACEs are granted and install/permissions.cfg is exec'd.
  5. Run /refresh_report_permissions.

Bridge says standalone but I run VORP or RSG

Your framework started after pc_report, or its folder name differs from Config.Framework.resourceNames. Fix the load order first.

RSG and RedEM adapters

These adapters ship with sensible defaults but were not tested against a live core. If staff detection misbehaves, edit the permission maps at the top of bridge/rsg.lua or bridge/redp.lua.

Documentation for RedMorrow. Scripts are licensed per server — redistribution is not permitted.