Skip to content

Staff rights & server options ​

Three things configure a server: its server options (serveroptions.json, general settings), its folder config (foldersconfig.txt, where assets and levels live), and the per-account staff rights records. Staff edit all three from GRC, and changes apply without a restart. Scripts can read the options and check rights.

serveroptions.json ​

json
{
  "name": "My Server",
  "maxPlayers": 32,
  "startLevel": "start.glvl",
  "startX": 30,
  "startY": 30,
  "staff": ["YourAccount"],
  "startWeapons": ["hud", "inventory"],
  "motd": "Welcome!"
}
KeyMeaning
nameDisplay name, shown in the server list
maxPlayersSimultaneous players. 0 or less means unlimited
startLevel, startX, startYWhere new accounts start. Returning players resume where they logged out
staffAccounts allowed to connect with GRC (the remote control client)
startWeaponsNot read by the engine itself. Your server's login.ts grants these on join
gmapPlayerDistance, gmapLoadDistanceGmap visibility and streaming radii, in segments. See Levels & gmaps
anything elseCustom keys, passed through verbatim to scripts

Staff edit the file in GRC's Server Options window (serveroptions right). Apply validates the JSON, saves it and applies it live.

Hosting keys

The file may also contain keys your host manages, such as role, listenPort, publicHost and publicPort. Leave them as they are: changing them can make your server unreachable.

Reading options from scripts: serverOptions ​

Server scripts see the whole file as the global serverOptions: typed fields in camelCase, plus every custom key as written:

ts
function onPlayerJoined(player: Player) {
    if (serverOptions.motd) player.chat = String(serverOptions.motd)
    for (const wep of serverOptions.startWeapons ?? [])
        player.addWeapon(wep)
}
  • It's available from onInitialized onward, and only on the server. Clients never see it. Mirror what they need into a serverr flag.
  • It's deep-frozen. Writes are silently ignored, so scripts can't change the configuration.
  • A GRC save replaces the global with the new values. Read serverOptions.x when you need it instead of copying it into a module variable at startup, and a live edit will take effect without a script reload.
  • Only name, startLevel, startX, startY and maxPlayers are typed. Everything else (staff, startWeapons, your custom keys) types as any, so validate shapes before relying on them.

Custom keys are free configuration

Put tunables like "doubleXp": true or "shopTax": 0.05 in serveroptions.json, so staff can change them from GRC without touching scripts.

Staff and rights ​

Being on the staff list lets an account log in with GRC. What it can do there is decided by its rights record:

AccountResolved rights
Has a rights recordExactly what the record grants
On the staff list, no recordEverything (grandfathered, so existing staff keep working)
Anyone elseNothing

A record has two parts:

Named rights gate GRC tools and RC commands:

RightGates
scriptingThe Scripts, Weapons, Classes and Lib editors
serveroptions, folderconfigThe Server Options and Folder Config editors
leveleditor, ganeditorThe level and GANI editors
grantweaponsGrant/revoke weapons in the Players window
playerattrsEditing player attributes
warpplayer, kick, messageMoving, kicking and messaging players (/warp, /kick, /say)
changerightsEditing staff rights (you can't remove your own)
sql, sqladminThe SQL Explorer. See SQLite
collectionsThe Collections tool. See Replicated collections
clearnpcs/clearnpcs
warpReserved (not enforced yet)

Folder rights gate files, as lines of the form <r|w|rw> <folder>/<wildcard>, relative to data/:

rw scripts/*
r  levels/*.glvl
rw levels/events/*.glvl

A rule covers files under its folder recursively whose file name matches the wildcard. Folder matching ignores case. rw requires both read and write. Folder rights apply everywhere GRC touches files: the file browser, the script editors (so rw scripts/* is needed to save scripts), uploads, and the MCP server.

Edit a record from GRC's Players window (right-click, then Staff rights…) or by typing /openrights <account> in the main window. Records are stored under accounts/rights/. Changes apply immediately, even to an account that's already connected.

Keep the staff key lowercase

Keys in serveroptions.json are matched case-insensitively and the last one wins. Adding a second "Staff" key replaces the list instead of extending it. Edit the existing staff array.

Locked yourself out?

Another staff member with the changerights right can fix your record with /openrights <account>. Deleting an account's rights file in accounts/rights/ (GRC's File Browser) also restores the default: full rights for staff-list accounts. If nobody can get in any more, contact your host.

Checking rights from scripts: player.hasright ​

Server scripts can check a player's folder rights with player.hasright(mode, path):

ts
// A staff-only in-game command: only people who may edit the level may reset it.
function onActionServerSide(player: Player, action: string, levelName: string) {
    if (action !== 'resetlevel') return
    if (!player.hasright('w', 'levels/' + levelName)) {
        player.chat = 'Not allowed'
        return
    }
    // ...
}
  • mode is 'r', 'w' or 'rw'. path is data/-relative, like the rules.
  • It follows the same resolution as GRC: staff without a record pass everything, and non-staff without a record fail everything.
  • It's serverside only. Clients can't check rights. For client UI (showing a staff menu), have the server decide and grant a staff-only weapon, or set a clientr flag.
  • There's no script call for named rights. To gate by staff membership instead, compare against serverOptions.staff case-insensitively, or define your own list as a custom option.

foldersconfig.txt ​

foldersconfig.txt tells the server where each kind of file lives. Each line is <type> <folder>/<wildcard>, relative to data/. # starts a comment:

gan   assets/ganis/*.gan
image assets/images/*.png
head  assets/images/*.png
body  assets/images/*.png
sound assets/sounds/*.wav
file  assets/*
level levels/*
  • Types: gan, image, head, body, sound, level, and file (the fallback for anything else). A type can have several lines, searched in order. At least one level rule is required.
  • Lookup: when a client asks for an asset, rules for its type are searched before file rules. Only files covered by some rule are served, so accounts/ and scripts/ can never leak.
  • Levels: all level folders are searched. Levels created at runtime (createlevel) go into the first one.
  • Fallback to the Login Server: anything this server doesn't have (heads, bodies, default ganis, ...) is served from the Login Server's copies, so a new server only needs the files it adds or overrides.

Staff edit it in GRC's Folder Config window (folderconfig right). A save applies live and creates any missing folders. Scripts refer to assets by name ('head3.png', 'sword' for a gani). Folder config decides where those names are looked up.