DAI 4.1 · SERVER AUTHORITY

The client requests. The server decides.

UI restrictions are never treated as security boundaries. A modified client can send arbitrary packets, so every authoritative path must validate the authenticated server player and the requested capability.

Required flow

client payload
  ↓
server obtains actual ServerPlayer from connection
  ↓
packet + size/rate validation
  ↓
capability / permission / scope validation
  ↓
server-owned mutation
  ↓
resulting state synchronized normally

4.1 protections

  • Generic mutations require privileged authority and are self-scoped where applicable.
  • Arbitrary commands remain owner/operator authority.
  • Functions and skills require server-defined client-callable capability before an ordinary client can request them.
  • Shared world/server/dimension state requires stronger authority than self-scoped player/entity state.
  • Creator operations have separate normal and privileged access checks.
  • Integrated-server owner trust is limited to the actual singleplayer owner, not every Open-to-LAN connection.
  • Vehicle input is validated, clamped and rate-limited before applying to the actual ridden DAI vehicle.

Pack author rule

Expose only the capability you intend. Setting client_callable: true makes that server-defined operation requestable by ordinary clients; it does not remove server-side skill requirements or other validation.