MrPoulpi Labs
PMMS

Available scripts

FR
Documentation centre

Permissions and URLs

The pmms.* and command.pmms_* ACEs, what the shipped permissions.cfg grants, how to limit URLs to presets or Config.allowedUrls, and the points of attention found in the code.

Goal: decide who can start what, and on which entities. Files: pmms/permissions.cfg (loaded by exec @pmms/permissions.cfg) and Config.allowedUrls in config.lua.

The permissions

PMMS only uses FiveM ACEs; no framework is queried. The server checks these permissions on every action, and sends them to the client to adapt the panel.

ACE Granted by the pack Original resource Effect
pmms group.admin group.admin Parent permission: grants every pmms.* permission below.
pmms.interact builtin.everyone builtin.everyone Use an unlocked media player: start, pause, stop, set volume, attenuation, range, video, loop, queue, copy.
pmms.anyEntity builtin.everyone builtin.everyone Use any entity whose model is in Config.models. Without it, only the entities allowed by the enableEntity client export or created by createMediaPlayer can be used. Vehicles are not affected.
pmms.customUrl builtin.everyone commented out Play a URL instead of a preset, limited to Config.allowedUrls unless pmms.anyUrl is granted. Without it: presets only.
pmms.anyUrl builtin.everyone commented out Play any URL, bypassing Config.allowedUrls (also requires pmms.customUrl).
pmms.manage group.admin group.admin Lock and unlock, control locked media players, save or delete model and entity settings, see active media players beyond maxDiscoveryDistance.

A locked player (locked) can only be controlled by a player who has pmms.manage.

After changing ACEs during a session, run /pmms_refresh_perms so clients reload their permissions.

What the shipped pack grants

add_ace group.admin pmms allow
add_ace builtin.everyone pmms.interact allow
add_ace builtin.everyone pmms.anyEntity allow
add_ace builtin.everyone pmms.customUrl allow
add_ace builtin.everyone pmms.anyUrl allow

With this file, any player can play any URL on any unlocked media player. The original resource left pmms.customUrl and pmms.anyUrl disabled.

Limit URLs

Presets only: remove both the customUrl and anyUrl lines. Players can then only start Config.presets entries.

Allowed sites: remove only the anyUrl line. Players can start URLs matching a Config.allowedUrls pattern (YouTube, youtu.be and Twitch by default).

add_ace group.admin pmms allow
add_ace builtin.everyone pmms.interact allow
add_ace builtin.everyone pmms.anyEntity allow
add_ace builtin.everyone pmms.customUrl allow

Intermediate role: grant pmms.anyUrl to a specific group, for example add_ace group.dj pmms.anyUrl allow (group.dj is an example group).

Expected result: a player without pmms.anyUrl who pastes a URL outside the list gets “You do not have permission to play the specified URL”.

Command permissions

Commands are restricted: each requires command.<name>. The shipped file gives the basic commands to builtin.everyone and pmms_ctl, pmms_add, pmms_refresh_perms to group.admin; see Commands. If you change Config.commandPrefix or Config.commandSeparator, rename these lines.

Points of attention found in the code

These behaviours come from this archive’s executed code; they also exist in the original resource.

  • URL checks: URL rules, presets and Config.oneMediaPerPlayer are checked when the client requests playback. The network message sent afterwards, once the media is loaded, only checks pmms.interact and the lock again. A modified client can therefore bypass Config.allowedUrls; do not rely on that list as the only barrier on an exposed server.
  • Queue: when a player is already playing, the request is added to its queue without an immediate check; the full checks happen when its turn comes.
  • -lock flag: a player starting a media can start it locked without having pmms.manage; they will not be able to control it themselves.
  • Vehicles: with Config.allowPlayingFromVehicles = true, any nearby vehicle is a media player, regardless of Config.models and pmms.anyEntity.
  • Exports: server exports check no permission and are not subject to Config.oneMediaPerPlayer. Resources calling them must do their own checks.

Common mistakes

  • Admins have no extra rights: group.admin is assigned to no player. Add for example add_principal identifier.license:… group.admin.
  • Restriction with no effect: you commented out pmms.anyUrl but another executed file still grants it to builtin.everyone.
  • ACE change not applied: run /pmms_refresh_perms or reconnect the player.

Search

Type a term: setting, export, error…