Permissions and URLs
The pmms.* and command.pmms_* ACEs, what the shipped permissions.cfg grants, how to limit URLs to presets or Config.allowedUrls, and the points of attention found in the code.
Goal: decide who can start what, and on which entities.
Files: pmms/permissions.cfg (loaded by exec @pmms/permissions.cfg) and Config.allowedUrls in config.lua.
The permissions
PMMS only uses FiveM ACEs; no framework is queried. The server checks these permissions on every action, and sends them to the client to adapt the panel.
| ACE | Granted by the pack | Original resource | Effect |
|---|---|---|---|
pmms | group.admin | group.admin | Parent permission: grants every pmms.* permission below. |
pmms.interact | builtin.everyone | builtin.everyone | Use an unlocked media player: start, pause, stop, set volume, attenuation, range, video, loop, queue, copy. |
pmms.anyEntity | builtin.everyone | builtin.everyone | Use any entity whose model is in Config.models. Without it, only the entities allowed by the enableEntity client export or created by createMediaPlayer can be used. Vehicles are not affected. |
pmms.customUrl | builtin.everyone | commented out | Play a URL instead of a preset, limited to Config.allowedUrls unless pmms.anyUrl is granted. Without it: presets only. |
pmms.anyUrl | builtin.everyone | commented out | Play any URL, bypassing Config.allowedUrls (also requires pmms.customUrl). |
pmms.manage | group.admin | group.admin | Lock and unlock, control locked media players, save or delete model and entity settings, see active media players beyond maxDiscoveryDistance. |
A locked player (locked) can only be controlled by a player who has pmms.manage.
After changing ACEs during a session, run /pmms_refresh_perms so clients reload their permissions.
What the shipped pack grants
add_ace group.admin pmms allow
add_ace builtin.everyone pmms.interact allow
add_ace builtin.everyone pmms.anyEntity allow
add_ace builtin.everyone pmms.customUrl allow
add_ace builtin.everyone pmms.anyUrl allow
With this file, any player can play any URL on any unlocked media player. The original resource left pmms.customUrl and pmms.anyUrl disabled.
Limit URLs
Presets only: remove both the customUrl and anyUrl lines. Players can then only start Config.presets entries.
Allowed sites: remove only the anyUrl line. Players can start URLs matching a Config.allowedUrls pattern (YouTube, youtu.be and Twitch by default).
add_ace group.admin pmms allow
add_ace builtin.everyone pmms.interact allow
add_ace builtin.everyone pmms.anyEntity allow
add_ace builtin.everyone pmms.customUrl allow
Intermediate role: grant pmms.anyUrl to a specific group, for example add_ace group.dj pmms.anyUrl allow (group.dj is an example group).
Expected result: a player without pmms.anyUrl who pastes a URL outside the list gets “You do not have permission to play the specified URL”.
Command permissions
Commands are restricted: each requires command.<name>. The shipped file gives the basic commands to builtin.everyone and pmms_ctl, pmms_add, pmms_refresh_perms to group.admin; see Commands. If you change Config.commandPrefix or Config.commandSeparator, rename these lines.
Points of attention found in the code
These behaviours come from this archive’s executed code; they also exist in the original resource.
- URL checks: URL rules, presets and
Config.oneMediaPerPlayerare checked when the client requests playback. The network message sent afterwards, once the media is loaded, only checkspmms.interactand the lock again. A modified client can therefore bypassConfig.allowedUrls; do not rely on that list as the only barrier on an exposed server. - Queue: when a player is already playing, the request is added to its queue without an immediate check; the full checks happen when its turn comes.
-lockflag: a player starting a media can start it locked without havingpmms.manage; they will not be able to control it themselves.- Vehicles: with
Config.allowPlayingFromVehicles = true, any nearby vehicle is a media player, regardless ofConfig.modelsandpmms.anyEntity. - Exports: server exports check no permission and are not subject to
Config.oneMediaPerPlayer. Resources calling them must do their own checks.
Common mistakes
- Admins have no extra rights:
group.adminis assigned to no player. Add for exampleadd_principal identifier.license:… group.admin. - Restriction with no effect: you commented out
pmms.anyUrlbut another executed file still grants it tobuiltin.everyone. - ACE change not applied: run
/pmms_refresh_permsor reconnect the player.