Documentation 9.6.24
Panel connection
The server and a rented website are separate resources. Connect the anti-cheat from Servers; manage a hosted website from Websites.
Connect the correct server#
Choose the server before downloading its package or copying its license. The bridge is on by default; if you do not want panel data requests for this server, use “Disable connection” on its Tosun Connect card. Allow outbound HTTPS to the configured panel. Do not put database credentials or management keys into client scripts.
If the connection is waiting#
Check the selected server, current license, oxmysql start order, framework support and server console. The status can be disabled, waiting or stale; a saved setting is not proof of a live connection. Request a small read and inspect its result before using administrative actions.
Setting up a rented website#
Enter a name and address in Websites. An active paid subscription and available website quota are required. The database and permissions are prepared in the background; no MySQL installation or database password is required. Refresh while Setting up, then open the website when Published. If setup fails, contact support before creating another website. The website database is separate from the FiveM game database.
Separate the account, server and website selection#
Before each action, check the account and selected server. An anticheat server and a rented website are different records: connect the anticheat through Servers, and manage site appearance and provisioning through Websites.
A teammate unable to open connection settings may be missing permission rather than experiencing a connection failure. The account owner should review that role. Sharing an administrator password or using another account’s license does not resolve the mismatch; the resource being managed and the account’s permissions must agree.
With multiple servers, read the selected record again before downloading a package or copying a license. With multiple websites, check the card before opening or editing it. A custom domain opens the primary active site; do not assume every server automatically receives a separate custom domain.
Verify the connection in order#
Saving a license is not proof that the connection works. Review local startup and the panel’s latest status together. A stale status from an earlier session is not evidence that a new installation succeeded.
- Confirm the server record and store its license in server-side server.cfg using set.
- Check oxmysql and your framework dependencies. Resolve the first console error before repeatedly restarting resources.
- Check outbound HTTPS access from the server to the configured panel. Opening MySQL to the internet or entering the game database password in the panel is unnecessary for the bridge.
- The bridge is on by default on both the panel and the server; no extra server.cfg line is needed. Verify it with a small player read. To stop it for this server, use “Disable connection” on the Tosun Connect card. An unsupported schema response does not mean there are no players.
Finish two-factor setup#
Start 2FA in account Security. The QR code is generated locally on that page. Scan it with your authenticator or enter the displayed setup key manually. Merely seeing the QR image does not enable two-factor authentication.
Confirm the current code produced by the authenticator in the panel. The setup session lasts ten minutes. If it expires, start setup again and use the new key; avoid mixing an old QR with a new setup session. If a code is rejected, check the phone’s clock and the authenticator account you selected.
Store the backup codes given after activation somewhere secure. Keep the QR, setup key, backup codes and session details out of support requests. Each teammate should protect their own account. Permission to enter a website is separate from permission to manage billing or anticheat servers.
Investigate a waiting or stale status#
When a connection appears to be waiting, identify the actual console error first. Check installation, license, panel access and the bridge (Tosun Connect card state and panel permissions) individually, recording what you verified. This keeps a local dependency problem from being mistaken for an account or payment problem.
- Confirm the installed version and selected server record.
- Confirm dependencies are running and inspect the first console error.
- Check access from the server to the panel and the latest connection time.
- If unresolved, send support the error with secrets removed, the time and the server ID.
Check viewing and editing rights separately#
Being able to open a page does not imply permission to save every setting on it. The panel checks settings viewing, settings management and integration management separately. Billing also has distinct viewing and management rights. Review the affected user’s role and any individual permission overrides before diagnosing a refused save as a service outage.
For a staff member who only needs to inspect records, retain the permissions required for that work. If a save is rejected while the account owner can complete the same operation, compare their permissions on the same selected resource. Avoid granting unrelated billing or economy privileges merely to make a button work.
For bridge economy changes, the implementation requires an administrator role and both server-management and economy-management permissions. A successful player read does not prove that a write is permitted. Treat changes to these permissions as an explicit administrative decision and verify the resulting scope.
Use settings history to explain a change#
Keep your own change note before saving panel settings: selected account, tab, previous value, new value and time. Successful settings updates generate audit records with the relevant settings tab. These records help an authorized administrator or support investigator correlate a reported symptom with a change; they are not a substitute for a configuration backup.
If notifications stop after an integration edit, compare the change time with the last expected notification. If branding differs on the wrong site, confirm the selected website before editing again. Describe the changed field by its name, while removing its secret value from the note and any screenshot.
Change only the setting being investigated and verify its intended result. If the result is unsuitable, restore the known prior value and repeat the same check. Do not claim that saving a tab validated external credentials, payment status or the complete health of the game server.
Verify access after a team handover#
When staff responsibilities change, review accounts and permissions together with the resources they manage. Use named individual accounts so the person performing an action can be identified. The outgoing administrator’s knowledge of a password, integration secret or downloaded license may require a separate credential replacement decision.
Ask the incoming administrator to sign in through their own account and check only the pages needed for their responsibilities. Verify the intended server and website selection. Confirm that someone authorized still manages billing and account security; do not test a handover by charging a card or changing a player balance.
Prepare a recovery contact and store the account’s own 2FA backup codes securely. Recheck that support material contains no QR codes, setup keys or session tokens. A handover is complete when responsibility, actual access and the operating record agree, rather than when a shared password has merely been forwarded.
Build access around a new teammate’s tasks#
List a teammate’s tasks before choosing access, then identify the viewing or management right each task needs. Default roles are ordered user, support, mod, admin and owner; individual permission overrides can affect the result. A role name alone does not guarantee identical scope on every page. Profile, player records, server settings, billing and security represent different responsibilities.
Prepare a simple matrix: task, resource, read requirement, change requirement and decision owner. Someone inspecting error records may not need billing management; the subscription manager need not perform everyday player actions. Current defaults assign billing.view to admin level and billing.manage to owner level, subject to individual overrides. Do not expand unrelated access merely to simplify a test.
Have the user sign in with their own account and verify the intended resource and required access in a controlled way. Do not test refused changes through a real charge or player balance update. The matrix is your operating record, not a new automatic permission template in the panel.
Distinguish a 2FA backup code from a daily login code#
The authenticator’s temporary code and the backup code supplied after activation serve different purposes. Backup codes belong to the account and are consumed after successful use. Do not treat one as a reusable shared password in team chat. Before replacing a phone, check access to your recovery material; removing the old device does not connect the new device to the panel.
If the authenticator is unavailable, use your account’s unused code through the backup-code option offered during login. A correct password does not complete the second step. Do not expect the same backup code to work twice. When rejected, check prior use and account ownership instead of repeatedly guessing.
The Security page can show the remaining-code count; that count does not recover lost code values. If access and recovery material are missing, discuss the account situation with support without assuming automatic or immediate reset. Never include a password, setup key, QR image or backup code itself in the request.
Change a password and close sessions separately#
Password changes verify the current password and require the two new-password fields to match. This updates the password record; do not assume it clears every open session. Sessions on Security are separate records, and removing a selected session targets only that session of your own account. If you have left an old team computer, review its access as well as choosing a new password. These settings are separate from a website database password or an AC license key.
- Enter the same new password twice and check the save result; never include it in support messages or screenshots.
- Review active sessions and last activity; remove unfamiliar or unused sessions with the relevant action.
- Your session list does not manage another employee’s access. Review that person’s user status and permissions separately.
- Verify normal login on a known device and preserve access to 2FA and backup codes. Changing a password is separate from disabling 2FA.
Verify permission changes without real transactions#
Reading invoices, starting payments and editing website design use different permissions. By default billing.view starts at admin and billing.manage at owner; individual permissions can change the result. Reading the role name alone is insufficient. Check page access and visible actions first. Do not cancel real invoices, initiate payments, change balances or sanction players merely to test a permission. The purpose is to verify access scope without producing operational effects.
- Compare tenant, active user status, role and individual permissions with the task list; use each person’s own account.
- Reopen the relevant page in that user’s session. Record invoice viewing and payment management as separate checks.
- If an option is absent, check subscription conditions, resource state and required permission separately; do not grant owner merely to expose a button.
- Narrow unexpected access and review again. Menu visibility alone does not prove every server-side permission check.
Set up and test the ban screen#
The ban screen shows a banned player a full-screen page for a few seconds before they are disconnected: your image or YouTube video, a title, a message, the ban reason if you choose, the ban ID and a large countdown. It is off by default and needs tosun-ac 9.6.15 or later; older versions ignore these settings and disconnect the player at once. It works for bans from the anticheat, the in-game admin menu, the console, exports and the panel.
The countdown lasts the number of seconds you set (3 to 15, 8 by default). When it reaches zero, the player is disconnected with the normal ban message. The ban is already recorded when the screen opens, so closing the game early does not undo it.
During the countdown the player is moved to an isolated world of their own, frozen, their weapons are removed and their chat messages are blocked. The server keeps the time, not the player’s game. If the game does not confirm within 3 seconds that the screen is shown, the player is disconnected immediately. Kicks issued by tosun-ac itself do not cut the countdown short, and new detections are normally only written to the log; in rare cases a second ban record can be created for the same player. A kick from txAdmin or another resource still disconnects the player at once; the ban stays in place.
Some YouTube videos cannot be embedded because their owner has turned embedding off. The video then does not play and the background shows YouTube’s own error message, while the text and the countdown appear as usual. Use an image in that case. Image links must start with https:// and point to a public domain name. http links, IP addresses and links longer than 400 characters are not used, and the screen shows text only.
- Open Panel → AntiCheat settings and find the Ban screen card. Turn it on and set a duration between 3 and 15 seconds.
- Choose the media: upload an image, enter an https image link or paste a YouTube video link. A YouTube video plays full screen in the background behind the text (cropped to fill the screen and darkened at the bottom so the text stays readable, with the info card at the bottom), while an image is shown next to the text inside that card. For a video, decide whether it starts muted. You can also use no media.
- Write a title (up to 80 characters) and a message (up to 300 characters). The limits are the same in every language and alphabet: an accented, Cyrillic, Arabic or Chinese letter counts as one character. The counter and the preview in the panel count the same way as the game. Leave a field empty to show the default text in the player’s language.
- Decide whether to show the ban reason. The ban ID is always shown, so the player can quote it in an appeal.
- Save. When the panel can reach your server, the change applies within a few seconds. Otherwise the server picks it up at its next settings sync, which can take up to 2 minutes with the default configuration (ts.ServerPerf.configSyncIntervalSec = 120). Wait that long before you test.
- Test with the preview command. By default the anticheat does not ban staff, so you cannot test by triggering a detection on yourself. In the console, give a player ID; in game, the command shows the screen to you. The preview uses a test ID and does not ban, move or disconnect anyone. It also works before you turn the screen on.
# Server console (12 = player ID):
banscreentest 12
# In game, with ACE tosunac.banscreen.test or tosunac.admin:
/banscreentest
# server.cfg, example: allow the admin group to preview
add_ace group.admin tosunac.banscreen.test allowFirst owner login to the rented website#
Select your rented site in TosunDev and open Site management. If you are signed out, the site asks you to log in and returns you to management after success. For email signup, use the email and password that were valid when the site was provisioned. Do not assume later password changes automatically update a separately provisioned site account.
- Match the site address to the selected rental record.
- Use a private browser window to check login, successful authentication and the correct site management page.
- Associate the website with your own FiveM server record. Website password, Tosun license and MySQL password are separate values.
- Use that site’s recovery and ownership checks if access fails; do not use a shared/default administrator password.
Grant narrow permissions and verify revocation#
Server-side ACE, editable administrator identifiers and panel grants determine menu access. The word all is not an identifier or a grant. allowedIds accepts full identifiers such as license:..., discord:... and fivem:... taken from the server’s player identifiers. Example text does not grant access.
- Give a test administrator only the required role and check menu access and one allowed action.
- Revoke the panel grant and retry as the same player. The updated default poll checks approximately every five seconds; network delays must be observed separately.
- Review independent ACE/admins.lua grants too. Online-player telemetry alone is not an authority for menu access.
- A normal test player must remain denied. Test money, weapons and bans without affecting real customer records.
ts.AdminMenu.allowedIds = {
"license:YOUR_EXACT_PLAYER_IDENTIFIER",
"discord:YOUR_DISCORD_USER_ID"
}
# Examples are placeholders, not grants.