AllowSpectatorJoin set to true (default) makes autohosts insecure
Posted: 10 Sep 2015, 16:16
@all autohosts admins:
please set AllowSpectatorJoin to false as it allows everyone to connect using any username which breaks permission checking of spads (and possible other stuff like stats on replays.springrts.com)
for some reason (which i don't really understand) its not wanted that the default value is changed to false:
https://github.com/spring/spring/commit ... dc016c85aa
this basicly applies to self-hosted games, too.
the default of AllowSpectatorJoin is true, so if you didn't change this value, your autohost is affected!
related bug reports:
https://springrts.com/mantis/view.php?id=3662
https://springrts.com/mantis/view.php?id=4949
please set AllowSpectatorJoin to false as it allows everyone to connect using any username which breaks permission checking of spads (and possible other stuff like stats on replays.springrts.com)
for some reason (which i don't really understand) its not wanted that the default value is changed to false:
https://github.com/spring/spring/commit ... dc016c85aa
this basicly applies to self-hosted games, too.
the default of AllowSpectatorJoin is true, so if you didn't change this value, your autohost is affected!
related bug reports:
https://springrts.com/mantis/view.php?id=3662
https://springrts.com/mantis/view.php?id=4949