From 7d4c3fa4672dbf81cb0ab663ad5fe4135e711d41 Mon Sep 17 00:00:00 2001 From: mikomyazaki <47489928+mikomyazaki@users.noreply.github.com> Date: Sat, 8 Feb 2020 20:46:29 +0000 Subject: [PATCH] Fixes an exploit that allowed changing other people's flavour texts (#8221) * Fixes a thing * Changelog. Co-authored-by: Matt Atlas --- code/modules/mob/living/carbon/human/human.dm | 3 ++ html/changelogs/flavourtextbugfix.yml | 41 +++++++++++++++++++ 2 files changed, 44 insertions(+) create mode 100644 html/changelogs/flavourtextbugfix.yml diff --git a/code/modules/mob/living/carbon/human/human.dm b/code/modules/mob/living/carbon/human/human.dm index d0d62880985..474dca2f60d 100644 --- a/code/modules/mob/living/carbon/human/human.dm +++ b/code/modules/mob/living/carbon/human/human.dm @@ -839,6 +839,8 @@ src.examinate(M) if (href_list["flavor_change"]) + if(src != usr) + return switch(href_list["flavor_change"]) if("done") src << browse(null, "window=flavor_changes") @@ -1072,6 +1074,7 @@ var/new_facial = input("Please select facial hair color.", "Character Generation",rgb(r_facial,g_facial,b_facial)) as color if(new_facial) + r_facial = hex2num(copytext(new_facial, 2, 4)) g_facial = hex2num(copytext(new_facial, 4, 6)) b_facial = hex2num(copytext(new_facial, 6, 8)) diff --git a/html/changelogs/flavourtextbugfix.yml b/html/changelogs/flavourtextbugfix.yml new file mode 100644 index 00000000000..6708ee881f3 --- /dev/null +++ b/html/changelogs/flavourtextbugfix.yml @@ -0,0 +1,41 @@ +################################ +# Example Changelog File +# +# Note: This file, and files beginning with ".", and files that don't end in ".yml" will not be read. If you change this file, you will look really dumb. +# +# Your changelog will be merged with a master changelog. (New stuff added only, and only on the date entry for the day it was merged.) +# When it is, any changes listed below will disappear. +# +# Valid Prefixes: +# bugfix +# wip (For works in progress) +# tweak +# soundadd +# sounddel +# rscadd (general adding of nice things) +# rscdel (general deleting of nice things) +# imageadd +# imagedel +# maptweak +# spellcheck (typo fixes) +# experiment +# balance +# admin +# backend +# security +# refactor +################################# + +# Your name. +author: MattAtlas + +# Optional: Remove this file after generating master changelog. Useful for PR changelogs that won't get used again. +delete-after: True + +# Any changes you've made. See valid prefix list above. +# INDENT WITH TWO SPACES. NOT TABS. SPACES. +# SCREW THIS UP AND IT WON'T WORK. +# Also, all entries are changed into a single [] after a master changelog generation. Just remove the brackets when you add new entries. +# Please surround your changes in double quotes ("), as certain characters otherwise screws up compiling. The quotes will not show up in the changelog. +changes: + - bugfix: "Fixes being able to edit other peoples' flavour texts."