DAI 4.1 · SERVER AUTHORITY
The client requests. The server decides.
UI restrictions are never treated as security boundaries. A modified client can send arbitrary packets, so every authoritative path must validate the authenticated server player and the requested capability.
Required flow
client payload ↓ server obtains actual ServerPlayer from connection ↓ packet + size/rate validation ↓ capability / permission / scope validation ↓ server-owned mutation ↓ resulting state synchronized normally
4.1 protections
- Generic mutations require privileged authority and are self-scoped where applicable.
- Arbitrary commands remain owner/operator authority.
- Functions and skills require server-defined client-callable capability before an ordinary client can request them.
- Shared world/server/dimension state requires stronger authority than self-scoped player/entity state.
- Creator operations have separate normal and privileged access checks.
- Integrated-server owner trust is limited to the actual singleplayer owner, not every Open-to-LAN connection.
- Vehicle input is validated, clamped and rate-limited before applying to the actual ridden DAI vehicle.
Pack author rule
Expose only the capability you intend. Setting
client_callable: true makes that server-defined operation requestable by ordinary clients; it does not remove server-side skill requirements or other validation.