Skip to content

handle_click_slot_inner should not trust client-suggested slot changes #931

Description

@TestingPlant

handle_click_slot_inner currently uses packet.slot_changes directly without verifying that they are valid. This means a malicious client can create their own items by placing them in slot_changes in the click slot packet.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions