GetEventClient

From Wiki G1R-MP G1 Remake Multiplayer
Jump to navigation Jump to search

getEventClient

Server-side. Available since 0.1.4.

Returns the authenticated player ID that initiated the current synchronous request, or nil when no client request context exists.

Syntax

local playerId = getEventClient()

The value comes from native server context, not the writable Lua client global. It survives synchronous nested triggerEvent and executeCommandHandler calls, including cross-resource calls. Context is restored after handlers, including errors; simultaneous players do not share one persistent sender value.

Remote event contract

For a direct triggerServerEvent request:

  • The first callback argument remains the authenticated sender ID inserted by the server; client arguments follow it.
  • source is the sender's player element; sourceResource is nil; eventOrigin is "client".
  • A client-supplied resource name is not a trusted identity.

For server Lua forwarding, sourceResource identifies the actual server resource and eventOrigin is "resource". For native server events, origin is "server". Forwarding does not erase the initiating client. In command handlers, use this function rather than relying on event-only globals.

addEvent("shop:buy", true)
addEventHandler("shop:buy", root, function(playerId, productId)
    if getEventClient() ~= playerId then return end
    -- Validate product ID, player session, permissions, distance, quantity,
    -- price, balance and request rate using SERVER state before granting anything.
end)

Security and migration

  • Leave private events remote-disabled: addEvent(name, false).
  • Remote subscriptions remain global by event name. resourceRoot is not an authorization boundary; use namespaced names and validate every subscriber.
  • Timers and asynchronous database/password/HTTP callbacks run later; they normally have nil client context. Capture player ID and a session token before scheduling, then revalidate them and permissions on completion. nil is not proof of administrator authority.
  • Existing handlers authorizing clients by sourceResource.name must migrate to the authenticated sender and server-owned permission checks.
  • This does not stop a modified client from requesting an allowed event. It prevents trusting a forged source identity; scripts must still validate the requested operation. Server-installed Lua resources remain trusted.

See TriggerServerEvent, Lua events and Update 0.1.4.