Skip to content

handle_click_slot_inner should not trust client-suggested slot changesΒ #931

@TestingPlant

Description

@TestingPlant

handle_click_slot_inner currently uses packet.slot_changes directly without verifying that they are valid. This means a malicious client can create their own items by placing them in slot_changes in the click slot packet.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions