Skip to content

Permissions ​

Every Nayretis action that needs rights checks a scope. You grant scopes with ACE, with rules stored in the database, or from the Permissions tab of /nay.

Scopes ​

ScopeGrants
nay.adminEverything: every script, the Nayretis settings, permissions, API tokens, webhooks and the audit log.
nay.configThe settings of every script.
nay.auditThe audit log.
<resource>.configThe settings of one script, for example nay_car_wash.config.
<resource>.<name>A permission declared by a script, listed on its page.
<resource>.*Every scope of one script. Works with rules (nay_grant), not with ACE.

With ACE ​

An ACE on a scope grants it. Grant each scope by its full name (wildcard scopes such as nay_car_wash.* only work as rules). In server.cfg:

cfg
add_ace group.admin nay.admin allow
add_ace group.mod nay_car_wash.config allow

With rules ​

Rules are stored in the database and can target a player directly. A rule has a type, an identifier and a scope. The types are:

  • ace: every player allowed on that ACE object;
  • discord, steam, fivem, license: one player, by identifier.

From the server console:

text
nay_grant license 1a2b3c4d5e6f nay.admin
nay_grant discord 123456789012345678 nay_car_wash.config
nay_revoke discord 123456789012345678 nay_car_wash.config
nay_rules

nay_grant and nay_revoke take <ace|discord|steam|fivem|license> <identifier> <scope>. nay_rules lists every rule with its number.

In game, the Permissions tab of /nay (scope nay.admin) lists, adds and removes the same rules. Every change is written to the audit log.