LegacyShell WikiLegacyShell Wiki
Back to LegacyShell
Home
Wiki
Plugins
Docs
Back to LegacyShell
Home
Wiki
Plugins
Docs
  • Documentation

    • Getting Started

      • What is LegacyShell?
      • Speed Setup
      • Requirements
      • Installation
      • First Run
      • Config Files
      • Making an Account
      • Troubleshooting (Getting Started)
    • Running a Server

      • Architecture Overview
      • The Database
      • Users and Ranks
      • Adding Game Servers
      • Client Mirrors
      • Perpetual
      • Backups
      • Rate Limiting
      • Moderation
      • Closed Mode
      • Deployment
      • Troubleshooting (Running a Server)
      • Hosting for Someone Else's Instance
    • Content Creation

      • Maps
      • Dealing with Babylon Models
      • Map Blocks
      • Items and Skins
      • Hats and Stamps
      • Sounds
      • Gamemodes
      • Seasonal Events
    • Plugin Development

      • Quickstart
      • I Want To...
      • Anatomy of a Plugin
      • Lifecycle
      • Dependencies
      • Events (Concept)
      • Event Reference

        • services: events
        • game: events — shared logic (src/shell/)
        • game: events — main-thread server process
        • game: events — per-connection client object
        • game: events — room lifecycle & tick loop
        • game: events — in-browser gameplay
        • client: events — client server & build pipeline
      • Commands
      • Client-Side Code
      • Static Assets
      • Content Packs
      • Networking
      • Workers and State
      • Prediction and Authority
      • Recipes

        • Recipe: Killstreaks
        • Recipe: New Pickup Item
        • Recipe: New Gamemode
        • Recipe: Custom Weapon
        • Recipe: UI Modification
        • Recipe: Discord Integration
        • Recipe: Replacing Core Behaviour
        • Recipe: Persistent Plugin Storage
        • Recipe: Rewarding Players with Currency
        • Recipe: Custom Per-Player Data
        • Recipe: Custom Theme
      • Publishing
      • Pitfalls
      • Modifiers
      • Sound and Apollo
    • Codebase Reference

      • Repo Layout
      • Shared Shell Layer
      • Server-Only Markers
      • The ss Object
      • Build Pipeline
      • Stamps and Babylons
      • Game Loop
      • Rooms and Workers
      • Wire Protocol
      • Generated

        • Wire Protocol Opcodes
        • Enums & Lookup Tables
        • Database Schema
        • Config Reference
        • Slash Command Reference
      • Services Internals
      • Catalog and Items
      • Permissions Internals
      • Physics and Collision
      • Known Quirks
      • Codebase Anecdotes
      • Development Timeline
    • Contributing

      • Documentation Style Guide
      • Generators
      • For AI Agents

Users and Ranks

Audience: Server operators · Prereqs: The Database

Canonical source: server-services/src/data_management/recordsManagement.js (users schema), src/shell/permissions.js (PermissionsConstructor), src/defaultconfig/distributed_permissions.yaml

The rank system

Every account has an adminRoles integer column in the users table (default 0). That number is compared against named rank levels defined in store/config/distributed_permissions.yaml:

LevelRank nameNotes
0GuestDefault for every new account. (marked "do not modify" in the config)
1Signed In(marked "do not modify" in the config)
5Content CreatorA middle rank, free for you to repurpose.
10Moderator(marked "do not modify" in the config)
20Admin(marked "do not modify" in the config)
255SuperuserThe highest level. (marked "do not modify" in the config)

The gaps between these numbers (2-4, 6-9, 11-19, 21-254) are intentionally left open in the default config for you to insert your own custom ranks between the built-in ones, without renumbering anything that already exists. The five "do not modify" ranks are load-bearing - several built-in commands are hardcoded to specific ones of them (e.g. the announce command requires Admin).

Granting a rank

Directly in the database (see The Database for how to open it):

UPDATE users SET adminRoles = 255 WHERE username = 'someuser';

Use whichever numeric level fits - 10 for Moderator, 20 for Admin, 255 for Superuser (or a custom in-between value you've defined). There's no in-game UI for this; it's an intentionally manual, database-level action.

How permission checks actually work

Every slash command (see the full list once you're in Plugin Development) is registered with a permission tuple: [bypassRank, privateRoomRank, requireGameOwnerInPrivate].

  • bypassRank - a player at or above this rank can always use the command, anywhere.
  • privateRoomRank - in a private room, a player at or above this (lower) rank can also use it...
  • requireGameOwnerInPrivate - ...but only if this is true and they're also the room's owner (the player who created it), or if this is false, rank alone is enough even without being the owner.

In public rooms, only the bypassRank tier can use the command at all - the private-room allowance never applies there. This is why, for example, a regular player can use gameplay-tweak commands (gravity, speed, etc.) in their own private room, but not in a public game.

Moderation: what exists, and what doesn't

LegacyShell ships one built-in moderation command: boot (Moderator rank or above), which disconnects a player from the current room. That's a kick, not a ban - there's no persistent, built-in mechanism that stops a booted player from simply reconnecting.

If you need actual bans, you have a few real options, none of them built in:

  • Revoke/rename the offending account directly in the users table (breaks their login, doesn't stop a new account).
  • Block their IP at the network/reverse-proxy level in front of your client and game servers (outside the scope of LegacyShell itself).
  • Write a plugin that checks a ban list on game:joinPlayer and disconnects/rejects matching players - see Plugin Development once you're ready; this is exactly the kind of thing the "could this be a plugin?" philosophy expects you to build rather than have LegacyShell dictate one specific ban system.

Next: Adding Game Servers.


This page was drafted with AI assistance and reviewed for accuracy. If something looks wrong, please open a PR or flag it.

Edit this page on GitHub
Prev
The Database
Next
Adding Game Servers