Permissions
Every Nayretis action that needs rights checks a scope. You grant scopes with ACE, with rules stored in the database, or from the Permissions tab of /nay.
Scopes
| Scope | Grants |
|---|---|
nay.admin | Everything: every script, the Nayretis settings, permissions, API tokens, webhooks and the audit log. |
nay.config | The settings of every script. |
nay.audit | The audit log. |
<resource>.config | The settings of one script, for example nay_car_wash.config. |
<resource>.<name> | A permission declared by a script, listed on its page. |
<resource>.* | Every scope of one script. Works with rules (nay_grant), not with ACE. |
With ACE
An ACE on a scope grants it. Grant each scope by its full name (wildcard scopes such as nay_car_wash.* only work as rules). In server.cfg:
cfg
add_ace group.admin nay.admin allow
add_ace group.mod nay_car_wash.config allowWith rules
Rules are stored in the database and can target a player directly. A rule has a type, an identifier and a scope. The types are:
ace: every player allowed on that ACE object;discord,steam,fivem,license: one player, by identifier.
From the server console:
text
nay_grant license 1a2b3c4d5e6f nay.admin
nay_grant discord 123456789012345678 nay_car_wash.config
nay_revoke discord 123456789012345678 nay_car_wash.config
nay_rulesnay_grant and nay_revoke take <ace|discord|steam|fivem|license> <identifier> <scope>. nay_rules lists every rule with its number.
In game, the Permissions tab of /nay (scope nay.admin) lists, adds and removes the same rules. Every change is written to the audit log.