VoltMod
C++23 framework for CS2 server plugins
Loading...
Searching...
No Matches
VoltMod::Policy Class Reference

The one permission and targeting gate, plus the plugin's reply callback. More...

#include <Policy.hpp>

Public Member Functions

 Policy (PlayerManager &players)
 
 Policy (const Policy &)=delete
 
Policy & operator= (const Policy &)=delete
 
Result< Authorized > Authorize (PlayerRef caller, std::optional< PlayerRef > target, std::string_view permission) const
 The single gate. Commands, target resolution and menu rows call exactly this.
 
Status AuthorizeSteamId (PlayerRef caller, int64_t targetSteamId, std::string_view permission) const
 Authorize for a target that may be offline, addressed by SteamID.
 

Public Attributes

std::function< bool(int64_t steamId, std::string_view permission)> HasPermission
 
std::function< bool(int64_t callerSteamId, int64_t targetSteamId)> CanTarget
 
std::function< void(int slot, std::string_view message)> Reply
 

Detailed Description

The one permission and targeting gate, plus the plugin's reply callback.

The runtime sets HasPermission to ask the published IPermissions; a plugin fills the others it enforces once in Plugin::Load. Every policy-aware framework subsystem - command dispatch, target resolution, menu rows - goes through Authorize to reach them. An unset CanTarget or Reply means "no rule / no callback"; an unset HasPermission denies, because there is then no trusted permission source.

Policy is not assignable as a whole: it is constructed with the roster it resolves refs against. Assign the members you enforce.

Definition at line 40 of file Policy.hpp.

Constructor & Destructor Documentation

◆ Policy() [1/2]

VoltMod::Policy::Policy ( PlayerManager &  players)
inlineexplicit

players must outlive the policy; the Runtime declares the roster above it.

Definition at line 44 of file Policy.hpp.

◆ Policy() [2/2]

VoltMod::Policy::Policy ( const Policy &  )
delete

Member Function Documentation

◆ Authorize()

Result< Authorized > VoltMod::Policy::Authorize ( PlayerRef  caller,
std::optional< PlayerRef >  target,
std::string_view  permission 
) const

The single gate. Commands, target resolution and menu rows call exactly this.

Outcomes, in the order they are decided:

Condition Result
caller is not connected ErrorCode::NotFound, no Key
target given but not connected ErrorCode::NotFound, Key target.noMatch
permission non-empty, HasPermission unset ErrorCode::Denied, Key cmd.noPermission (logged once)
HasPermission says no ErrorCode::Denied, Key cmd.noPermission
CanTarget says no ErrorCode::Immune, Key target.immune
otherwise the Authorized pair

An empty permission skips the permission check. Targeting yourself is always allowed: the rule lives here rather than in each plugin's CanTarget, so CanTarget only ever answers "may this caller act on somebody else".

Denial is a value. Nothing is nulled out to signal it, so a caller that ignores the Result cannot accidentally run the action anyway.

Definition at line 52 of file Policy.cpp.

References VoltMod::Authorized::Caller, VoltMod::PlayerManager::Get(), VoltMod::NotFound, VoltMod::Error::NotFound(), and VoltMod::ReadFile().

Referenced by VoltMod::CommandRouter::Dispatch(), and VoltMod::EngineArgBinder::Resolve().

◆ AuthorizeSteamId()

Status VoltMod::Policy::AuthorizeSteamId ( PlayerRef  caller,
int64_t  targetSteamId,
std::string_view  permission 
) const

Authorize for a target that may be offline, addressed by SteamID.

Same decision order minus the target-connected check. Returns Status rather than Authorized because an offline target has no Player to hand back: the answer is "allowed" or the Error saying why not, and there is nothing to act on that the caller did not already have.

Use this wherever a command binds Args::PlayerOrSteamId or a bare SteamID. Reaching past it to a plugin's own immunity table is what let offline targets skip the gate.

Definition at line 87 of file Policy.cpp.

References VoltMod::PlayerManager::Get(), VoltMod::Error::NotFound(), and VoltMod::ReadFile().

◆ operator=()

Policy & VoltMod::Policy::operator= ( const Policy &  )
delete

Member Data Documentation

◆ CanTarget

std::function<bool(int64_t callerSteamId, int64_t targetSteamId)> VoltMod::Policy::CanTarget

May the caller act on the target (immunity, same-team rules)? Never consulted for the server console, which has no caller, nor for a caller targeting themselves.

Takes SteamIDs rather than Player& so the same rule answers for an offline target - see AuthorizeSteamId. An immunity comparison never needed the connected object.

Definition at line 59 of file Policy.hpp.

◆ HasPermission

std::function<bool(int64_t steamId, std::string_view permission)> VoltMod::Policy::HasPermission

Does steamId hold permission? Unset denies every permission-gated action.

Definition at line 50 of file Policy.hpp.

◆ Reply

std::function<void(int slot, std::string_view message)> VoltMod::Policy::Reply

Deliver a command result or error line (e.g. as a colored chat reply); unset falls back to a plain runtime.Messages.Send.

Definition at line 63 of file Policy.hpp.

Referenced by VoltMod::CenterHtmlMenu::CloseAll(), and VoltMod::PanoramaMenu::CloseAll().


The documentation for this class was generated from the following files: