GetEventClient
getEventClient
Server-side. Available since 0.1.4.
Returns the authenticated player ID that initiated the current synchronous request, or nil when no client request context exists.
Syntax
local playerId = getEventClient()
The value comes from native server context, not the writable Lua client global. It survives synchronous nested triggerEvent and executeCommandHandler calls, including cross-resource calls. Context is restored after handlers, including errors; simultaneous players do not share one persistent sender value.
Remote event contract
For a direct triggerServerEvent request:
- The first callback argument remains the authenticated sender ID inserted by the server; client arguments follow it.
sourceis the sender's player element;sourceResourceis nil;eventOriginis"client".- A client-supplied resource name is not a trusted identity.
For server Lua forwarding, sourceResource identifies the actual server resource and eventOrigin is "resource". For native server events, origin is "server". Forwarding does not erase the initiating client. In command handlers, use this function rather than relying on event-only globals.
addEvent("shop:buy", true)
addEventHandler("shop:buy", root, function(playerId, productId)
if getEventClient() ~= playerId then return end
-- Validate product ID, player session, permissions, distance, quantity,
-- price, balance and request rate using SERVER state before granting anything.
end)
Security and migration
- Leave private events remote-disabled:
addEvent(name, false). - Remote subscriptions remain global by event name.
resourceRootis not an authorization boundary; use namespaced names and validate every subscriber. - Timers and asynchronous database/password/HTTP callbacks run later; they normally have nil client context. Capture player ID and a session token before scheduling, then revalidate them and permissions on completion. nil is not proof of administrator authority.
- Existing handlers authorizing clients by
sourceResource.namemust migrate to the authenticated sender and server-owned permission checks. - This does not stop a modified client from requesting an allowed event. It prevents trusting a forged source identity; scripts must still validate the requested operation. Server-installed Lua resources remain trusted.
See TriggerServerEvent, Lua events and Update 0.1.4.