Skip to content

Add staff command to give assembled guns - #30

Merged
XxFran10xX merged 1 commit into
mainfrom
feat/give-guns
Oct 4, 2026
Merged

XxFran10xX merged 1 commit into
mainfrom
feat/give-guns

Conversation

@XxFran10xX

@XxFran10xX XxFran10xX commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Adds /gg give <player> <rifle|pistol|shotgun|launcher> <part> [part...] to deliver an assembled, unloaded gun using the normal stats, skin and provenance builder. Validates enabled compatible parts, one part per required category, class compatibility and inventory space. Spawned guns record zero crafting cost.

give-permission defaults to gunsandgadgets.give and supports a custom staff node; blank disables giving. Reload and refresh retain their existing permission checks, while the root command no longer blocks staff with only the configured give permission. Includes completion, documentation and command tests.

Validation: full unit suite plus targeted command tests pass; JaCoCo reports zero missed instructions, branches or lines and the configured coverage check passes. CI clean verify passed.

On TFMCDev01 (Paper 1.21.10 / Java 21), CI artifact DEV-20261004-0804 loaded successfully. In-game smoke checks passed permission denial, give permission without reload permission, invalid part rejection and delivery of Rifle, Pistol, Shotgun and Launcher. Inspected item data includes gun type, identity and zero-cost provenance. Test items and temporary permission grants were removed.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 4c2b8e02-7808-4831-9997-20ca792fa6cc
📥 Commits

Reviewing files that changed from the base of the PR and between b32e4c3 and 65b1d4d.

📒 Files selected for processing (9)
  • README.md
  • src/main/java/net/tfminecraft/gunsandgadgets/cache/Cache.java
  • src/main/java/net/tfminecraft/gunsandgadgets/loader/ConfigLoader.java
  • src/main/java/net/tfminecraft/gunsandgadgets/manager/GgCommand.java
  • src/main/java/net/tfminecraft/gunsandgadgets/manager/GunGiveCommand.java
  • src/main/resources/config.yml
  • src/main/resources/plugin.yml
  • src/test/java/net/tfminecraft/gunsandgadgets/GunGiveTest.java
  • src/test/java/net/tfminecraft/gunsandgadgets/GunsLifecycleCommandTest.java

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 6 remain after this review.


📝 Summary

Summary by CodeRabbit

  • New Features
    • Added a permission-controlled /gg give command for granting completed weapons to online players. It checks weapon and part compatibility, required parts and inventory space, and offers tab completion.
    • Added a configurable permission for the command; leaving the setting blank disables it.
  • Documentation
    • Documented the command’s arguments, requirements, permission setting and reload interaction.

Walkthrough

Adds /gg give to grant a completed gun to an online player. The command checks permission, gun and part requirements, class compatibility, and inventory capacity. It also adds configurable permission settings, tab completion, tests, and usage documentation.

Changes

Gun-giving command

Layer / File(s) Summary
Give permission and command configuration
src/main/java/net/tfminecraft/gunsandgadgets/cache/Cache.java, src/main/java/net/tfminecraft/gunsandgadgets/loader/ConfigLoader.java, src/main/resources/config.yml, src/main/resources/plugin.yml
Adds the configurable give-permission setting, with gunsandgadgets.give as its default. Declares the give permission with an operator default in the plugin configuration.
Command execution and delivery
src/main/java/net/tfminecraft/gunsandgadgets/manager/GgCommand.java, src/main/java/net/tfminecraft/gunsandgadgets/manager/GunGiveCommand.java, src/test/java/net/tfminecraft/gunsandgadgets/GunGiveTest.java, src/test/java/net/tfminecraft/gunsandgadgets/GunsLifecycleCommandTest.java, README.md
Routes /gg give to permission and input checks, gun assembly, and inventory delivery. Adds permission-gated tab completion, tests, and command documentation.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Staff
  participant GgCommand
  participant GunGiveCommand
  participant InventoryManager
  participant Recipient
  Staff->>GgCommand: Run /gg give
  GgCommand->>GunGiveCommand: Execute command
  GunGiveCommand->>GunGiveCommand: Check permission and validate recipient, gun, and parts
  GunGiveCommand->>InventoryManager: Build gun
  InventoryManager-->>GunGiveCommand: Return item
  GunGiveCommand->>Recipient: Add item to inventory
  GunGiveCommand-->>Staff: Send delivery confirmation
Loading

Merge Risk: ⚪ Minimal · up to 65b1d

No confirmed issue blocks merging after normal checks. The deployed item templates’ stack sizes remain unverified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 65b1d

The grant permission is enforced independently of reload and refresh, with validation before inventory delivery. No authorization bypass was established. Deployed permission assignments and the guarantee that configured templates produce exactly one unloaded gun remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A sender holding the configured permission can repeatedly grant supported guns without crafting costs to any online player on the server. The visible authority affects player inventories and the in-game equipment economy; it is not restricted to granting only to the sender.

Trust Boundaries and Controls

  • observed — Sender-controlled recipient, type, and part arguments pass through authorization and design validation before inventory mutation. Execution and completion share the same configured permission predicate, while reload and refresh remain separately authorized.

Resilience and Maintainability Implications

  • inferred — Repository-side rejection paths precede recipient inventory insertion, containing ordinary validation and invalid-output failures. After insertion begins, there is no explicit reconciliation of partial results. The direct command flow does not establish an asynchronous race, and intentional repeated grants do not by themselves establish a duplication vulnerability.

Hardening Proposals

  • proposed — Make fresh-issuance quantity and unloaded-state postconditions explicit at the trusted assembly boundary, or establish a versioned external creator contract that guarantees them without relying on template conventions.
  • proposed — Check insertion results before confirming delivery and define partial-delivery handling without unintentionally widening access through world-dropped grant items.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@XxFran10xX
XxFran10xX merged commit 403603f into main Oct 4, 2026
2 checks passed
@XxFran10xX
XxFran10xX deleted the feat/give-guns branch October 4, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant