Skip to content

Add staff command to give completed equipment with a selected material - #32

Merged
XxFran10xX merged 1 commit into
mainfrom
feat/give-equipment
Oct 4, 2026
Merged

XxFran10xX merged 1 commit into
mainfrom
feat/give-equipment

Conversation

@XxFran10xX

@XxFran10xX XxFran10xX commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Staff can use /ac give equipment <recipe> <ingredient.id|alloy.id> [player] [quality] to grant a completed item with the chosen compatible main material. The command supports online recipients, bounded quality and permission-aware completion. give-equipment-permission defaults to advancedcrafting.admin and can be reloaded.

Uses the existing equipment builder for stats, sockets, appearance, tier and provenance. Secondary ingredients select the lowest configured tier, then ID. No station state, inventory consumption, XP or progression events; full inventories drop at the recipient.

Validation:

  • Linux CI: 118 tests pass; 100% instruction, branch and line coverage; runtime JAR validation passes.
  • Local command/station tests: 23 pass. The unchanged full suite has Windows filesystem failures.
  • TFMCDev01: backed up the previous JAR and YAML configuration, installed the CI development JAR, restarted, and confirmed AdvancedCrafting enabled and Paper printed its current startup Done line. Actual grant delivery is exercised by the automated tests; no in-game staff grant was performed.
  • Diff reviewed; CodeRabbit approved with no actionable findings.

Deployment: release and routine Main PUSH follow merge. Tutorial requires a coordinated upgrade because its installed legacy TLibs is incompatible; its preparation is approved separately.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 80a93a6e-0d36-4ba2-9d41-bc358a9b52dc
📥 Commits

Reviewing files that changed from the base of the PR and between 34c6ffe and 7b035ea.

📒 Files selected for processing (9)
  • README.md
  • src/main/java/net/tfminecraft/advancedcrafting/cache/Cache.java
  • src/main/java/net/tfminecraft/advancedcrafting/loaders/ConfigLoader.java
  • src/main/java/net/tfminecraft/advancedcrafting/managers/CommandManager.java
  • src/main/java/net/tfminecraft/advancedcrafting/managers/EquipmentGiveCommand.java
  • src/main/java/net/tfminecraft/advancedcrafting/objects/crafting/CraftingStation.java
  • src/main/resources/config.yml
  • src/test/java/net/tfminecraft/advancedcrafting/CommandCoverageTest.java
  • src/test/java/net/tfminecraft/advancedcrafting/EquipmentGiveCommandTest.java

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Summary

Summary by CodeRabbit

  • New Features
    • Added a staff command to grant completed equipment to online players, with configurable permission, recipe and material selection, and optional quality. Items that do not fit in a player’s inventory are dropped nearby.
    • Added tab completion for equipment recipes, compatible materials, player names and quality values.
    • Documented the command, its defaults, item effects and permission configuration.

Walkthrough

The pull request adds a permission-configured command to grant completed equipment to a selected player. It validates command inputs, builds items without crafting delivery, and documents permission settings, item selection, and grant behaviour.

Changes

Staff equipment grant

Layer / File(s) Summary
Permission configuration and command routing
src/main/java/net/tfminecraft/advancedcrafting/cache/Cache.java, src/main/java/net/tfminecraft/advancedcrafting/loaders/ConfigLoader.java, src/main/resources/config.yml, src/main/java/net/tfminecraft/advancedcrafting/managers/CommandManager.java, src/test/java/net/tfminecraft/advancedcrafting/CommandCoverageTest.java, src/test/java/net/tfminecraft/advancedcrafting/EquipmentGiveCommandTest.java
A configurable permission defaults to advancedcrafting.admin. CommandManager routes and completes the equipment command according to permission access. Tests cover permission loading and command completion.
Build and grant completed equipment
src/main/java/net/tfminecraft/advancedcrafting/objects/crafting/CraftingStation.java, src/main/java/net/tfminecraft/advancedcrafting/managers/EquipmentGiveCommand.java, src/test/java/net/tfminecraft/advancedcrafting/EquipmentGiveCommandTest.java, README.md
CraftingStation can build a completed item without dropping it. The command validates grant inputs, builds the item, and delivers it to the target; tests cover validation, grants, and build failures. The README documents the command and its settings.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  actor Staff
  participant CommandManager
  participant EquipmentGiveCommand
  participant CraftingStation
  participant TargetPlayer
  Staff->>CommandManager: Run /ac give equipment
  CommandManager->>EquipmentGiveCommand: Route command and arguments
  EquipmentGiveCommand->>CraftingStation: Build completed item at requested quality
  CraftingStation-->>EquipmentGiveCommand: Return completed item
  EquipmentGiveCommand->>TargetPlayer: Add item to inventory
  EquipmentGiveCommand->>TargetPlayer: Drop overflow at target location
Loading

Suggested reviewers: ryanbarlow97

Merge Risk: ⚪ Minimal · up to 7b035

The change adds a permission-gated staff command for granting completed equipment. No concrete merge-blocking risk was identified; the remaining step is the Linux CI full verify and coverage gate.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 7b035

The new grant capability checks the sender’s configured permission before building or delivering equipment, and normal crafting retains its existing delivery behavior. No authorization bypass was identified in the inspected paths. Production permission integration and interrupted delivery remain unconfirmed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — A sender holding the configured grant permission can repeatedly create equipment from compatible configured recipes and materials for any online recipient. Effects reach the recipient’s inventory and world location; overflow becomes a world item rather than remaining exclusively in the recipient’s inventory.

Security Findings and Attack Paths

  • inferred — No permission-bypass attack was established through the inspected command path. Sender authorization occurs before recipient selection and item creation, including delegated-recipient and console execution. This conclusion is limited to the inspected route and does not establish complete security coverage.

Trust Boundaries and Controls

  • observed — The sender’s permission, not the recipient’s permissions, authorizes the grant. Controlled recipe and material lookup and bounded finite quality constrain command inputs before the shared item builder is invoked. Completion independently applies the same permission gate.

Resilience and Maintainability Implications

  • inferred — The current grant path has no consumed materials, registered station or pending reservation to restore after failure. A retry can nevertheless repeat an authorized grant if delivery partly succeeded. That uncertainty is not an established unauthorized duplication path because the same sender already has repeated minting authority.

Hardening Proposals

  • proposed — For grant accountability, record sender, recipient, recipe, material and delivery outcome, and distinguish a build failure from uncertain delivery. This would support recovery without treating authorized repeated grants as an observed vulnerability.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@XxFran10xX
XxFran10xX merged commit b33c29e into main Oct 4, 2026
2 checks passed
@XxFran10xX
XxFran10xX deleted the feat/give-equipment branch October 4, 2026 00:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant