Fixes an exploit that allowed changing other people's flavour texts (#8221)

* Fixes a thing

* Changelog.

Co-authored-by: Matt Atlas <mattiathebest2000@hotmail.it>
This commit is contained in:
mikomyazaki
2020-02-08 21:46:29 +01:00
committed by GitHub
co-authored by Matt Atlas
parent 02e175870e
commit 7d4c3fa467
2 changed files with 44 additions and 0 deletions
@@ -839,6 +839,8 @@
src.examinate(M)
if (href_list["flavor_change"])
if(src != usr)
return
switch(href_list["flavor_change"])
if("done")
src << browse(null, "window=flavor_changes")
@@ -1072,6 +1074,7 @@
var/new_facial = input("Please select facial hair color.", "Character Generation",rgb(r_facial,g_facial,b_facial)) as color
if(new_facial)
r_facial = hex2num(copytext(new_facial, 2, 4))
g_facial = hex2num(copytext(new_facial, 4, 6))
b_facial = hex2num(copytext(new_facial, 6, 8))
+41
View File
@@ -0,0 +1,41 @@
################################
# Example Changelog File
#
# Note: This file, and files beginning with ".", and files that don't end in ".yml" will not be read. If you change this file, you will look really dumb.
#
# Your changelog will be merged with a master changelog. (New stuff added only, and only on the date entry for the day it was merged.)
# When it is, any changes listed below will disappear.
#
# Valid Prefixes:
# bugfix
# wip (For works in progress)
# tweak
# soundadd
# sounddel
# rscadd (general adding of nice things)
# rscdel (general deleting of nice things)
# imageadd
# imagedel
# maptweak
# spellcheck (typo fixes)
# experiment
# balance
# admin
# backend
# security
# refactor
#################################
# Your name.
author: MattAtlas
# Optional: Remove this file after generating master changelog. Useful for PR changelogs that won't get used again.
delete-after: True
# Any changes you've made. See valid prefix list above.
# INDENT WITH TWO SPACES. NOT TABS. SPACES.
# SCREW THIS UP AND IT WON'T WORK.
# Also, all entries are changed into a single [] after a master changelog generation. Just remove the brackets when you add new entries.
# Please surround your changes in double quotes ("), as certain characters otherwise screws up compiling. The quotes will not show up in the changelog.
changes:
- bugfix: "Fixes being able to edit other peoples' flavour texts."