I have a question about the assignment of permissions in Minecraft.
There's the option to set a * for every plugin, so you have all the rights that the plugin includes.
The question now is, can this somehow be my undoing, because there are "wrong" permissions, especially with Essentials, which other players could exploit if I, as the admin, give myself all rights to all plugins?
Or do you think it makes more sense to laboriously look for all rights to each plugin and write them down? (Of course it is filtered out what is possibly unnecessary and so on)
Ask for your opinions, thank you very much!
No, nothing can happen.
What do you mean by "false permissions that other players could take advantage of"?
You should definitely look at what a * does. If you give someone the right to create homes by giving home. *, They can probably delete homes too. Maybe even from other players.
To save space you can, for example, Want to give everyone except a subpremission, mostly write something like:
-my.permission.admin stuff
my.permission *
Stop with a minus before (or after, depending on the plugin) remove a permission and enter the rest with *.
Well with Essentials there are e.g. A permission called "essentials.ban.offline" is supposed to ensure that a certain group or a certain player can be banned, even if you are offline. Could that now e.g. A moderator with the right to take advantage of it to ban me? (because with * I would have this "right"): D
No, he can't, because the admin role is higher. And when you have an operation, nobody can ban you without withdrawing your OP rights.
Ok, I understand, but I once heard that it would be better if there were no OPs on the server and so you should rather give yourself all rights as an admin in the admin group in case you get hacked.
One should rather do one or the other over the console.
There are plugins that prevent hacking. For example a password plugin where you have to enter a password before you can play.
If it is a normal server with online-mode set to true, you don't need this plugin. If it's a server network and it's properly configured, nothing can happen.
Because who wants to give OP and admin rank every time they join? Withdrawing OP in the console does not help if you have other permissions.