molfar_audit / Rules / LUA001

LUA001 Client value goes straight into money, items or jobs

possible Lua code

A server net event passes an argument from the client into AddMoney, AddItem or SetJob without any check.

Why it matters

Cheaters can trigger server events with any arguments they like. Without checks on the server they can give themselves money, items or jobs. This is a heuristic: it looks for an if statement that uses the value before the call, so read the code before changing it.

How to fix

Never trust the client. Validate type and range on the server, check distance and permissions, or compute the value server-side.

Reported
RegisterNetEvent('shop:sell', function(amount)
    local player = exports.qbx_core:GetPlayer(source)
    player.Functions.AddMoney('cash', amount)
end)
Fixed
RegisterNetEvent('shop:sell', function(count)
    if type(count) ~= 'number' or count < 1 or count > 10 then return end
    local player = exports.qbx_core:GetPlayer(source)
    if not player then return end
    player.Functions.AddMoney('cash', count * Config.Price) -- server-side price
end)

Your framework uses other names? Add them to config.json: "lua": { "sensitiveFunctions": ["GiveCash"] }.

Not a problem in your case?

Add -- molfar-audit-ignore LUA001 on the reported line (or the line above it), or ignore it in config.json: "ignore": [{ "rule": "LUA001", "resource": "your_resource" }].