文档 9.6.24
服务器集成
仅从可信服务器代码调用 exports。客户端不能自行选择豁免、权限或奖励。
只读示例#
示例只检查管理员状态,不授予权限。请核对安装包中的 export 和标识格式。
local playerId = 12
local isAdmin = exports['tosun-ac']:isAdmin(playerId)豁免前验证#
在服务器验证会话、玩家、位置、权限和时长。不要通过未经验证的 RegisterNetEvent 暴露豁免功能。参考 Cfx 安全指南。
传送通知#
每个会移动玩家的服务器脚本(房屋、车库、监狱、医院、工作)都应在传送前立即调用 MarkTeleport。它无需信任列表,只会短时间放宽移动和可见性检查;武器、资金和注入防护仍然有效。当所有传送脚本都发送该通知后,你可以在反作弊设置中将 v16 传送处罚提升为踢出。
exports['tosun-ac']:MarkTeleport(source, 8000)
SetEntityCoords(GetPlayerPed(source), x, y, z)受信任的资源#
用于豁免玩家、授予权限或执行批量操作的导出(SetExempt、addAdmin、whitelistPlayer 等)只接受受信任的资源。被拒绝的调用会在控制台中打印一次,并附上需要添加的配置行。请将列表保存在 server.cfg 中,这样反作弊更新不会覆盖它。控制台命令 tosunac_integration 会显示受信任列表和最近被拒绝的调用。
set tosun_ac_trusted_resources "my-housing,my-clothing"库存之外发放的武器#
不把武器放入库存就直接发放的脚本(例如竞技场、彩弹或菜单)应在发放武器时调用 AllowWeapon,否则 9.4.0 的武器与库存检测会将其记录为刷出的武器。可以传入单个武器名称,或用星号表示所有武器;最长持续 1 小时。反作弊不认识的附加武器请加入配置中的 extraWeapons。
exports['tosun-ac']:AllowWeapon(source, "WEAPON_PISTOL", 600000)权限保留在服务端#
以安装包 TOSUN-AC-EXPORTS.md 为准。名称区分大小写。豁免时间使用毫秒;AddWhitelist 和 WhitelistArea 使用秒。先启动 tosun-ac 再启动依赖脚本;停止时不能悄悄跳过保护。调用成功不替你验证业务规则。
SetExempt、AllowWeapon 要求可信服务端资源。只加入审核过的资源,保留已有列表项,使用 tosunac_integration 查看拒绝。关闭强制验证是审计模式,调用可通过并记录告警,不应永久关闭。
set tosun_ac_trusted_resources "my-clothing,my-arena"
# 服务器控制台:
tosunac_integration合法传送前立即通知#
验证玩家、服务器确定的目的地、权限与活动,然后在移动前调用 MarkTeleport。src、destination 来自现有受验证服务端流程,不是任意客户端参数。片段不是独立网络事件。
不需要信任列表。短期放宽移动和相关可见性/godmode/镜头检查,武器、资金、事件滥用和注入保护仍然有效。使用默认设置时,非可信调用单次最多 15 秒,每个玩家十分钟内合计 180 秒。延长也消耗预算,不应每 tick 调用。
-- 在已验证的服务端流程中:
local ok = exports["tosun-ac"]:MarkTeleport(src, 8000, "house_enter")
if ok then
SetEntityCoords(GetPlayerPed(src), destination.x, destination.y, destination.z)
end只允许特定脚本武器#
竞技场不通过背包发武器时,先验证服务器比赛再由可信资源调用 AllowWeapon。优先明确武器及必要短时间,仅影响背包所有权及其伤害路径,不关闭全部 AC。
最多一小时,除非确实需要所有武器否则避免星号。SetExempt 为全面可信豁免,最多五分钟。旧 BypassDetection 忽略 detectionKey,全面豁免最多一分钟,不能当成单项绕过。
不要保留已断线玩家的临时 source 供之后奖励或豁免。执行敏感动作时确认仍属于有效服务器会话;进入信任列表不免除脚本自己的权限和目标校验。
- 正常授权操作有效,到期恢复检查。
- 伪造客户端请求不能选择其他玩家、时间、武器或目的地。
- 非可信敏感调用返回 false,并产生有用告警。
- 重启后重新核对状态与正常操作。
-- my-arena:可信服务端资源,已验证会话
local allowed = exports["tosun-ac"]:AllowWeapon(src, "WEAPON_PISTOL", 60000)
-- 只在已验证竞技场流程中发放目标武器。使用正确的服务器 API 结束临时豁免#
服务器 SetExempt 参数是 src、毫秒数和原因;客户端参数则是 state、毫秒数和原因,两者不可互换。客户端豁免不会获得服务器权限。在可信服务器流程中,SetPlayerExempt 的 state 设为 false 可移除玩家临时豁免。先协调重叠活动:这是玩家范围的临时状态,并非每个资源独立持有的令牌,移除它可能同时结束另一活动的豁免。反之,员工权限或面板白名单仍可使 IsExemptFromPunish 保持真。若足够,优先使用较窄的 MarkTeleport 或 AllowWeapon。
- 使用经过当前验证的玩家完成或取消授权活动,在不再需要时移除临时豁免。
- 测试取消、断开及正常完成,不要在后台循环持续延长完整豁免。
- 使用普通玩家确认行为,并检查剩余保护是否来自员工权限、面板白名单或另一活动。
-- Trusted server resource; src belongs to an authorised workflow.
-- Clear the temporary exemption when that workflow finishes or is cancelled.
local cleared = exports["tosun-ac"]:SetPlayerExempt(src, false, 0, "menu_finished")使用辅助文件时明确处理结果#
桥接辅助文件加入你自己的资源 manifest,不会替代权限校验。TosunAC.IsAvailable 检查 AC 是否启动;TosunAC.IsTrusted 检查调用者是否可信。PlayerExempt 返回 ok 和 mode:full 代表可信的完整豁免,soft 只提供有限移动与可见性宽限。不要把任意真值理解为完整免疫。如果活动确实需要 full,必须决定只获得 soft 时怎样停止或拒绝活动,而非在不同保护范围下默默继续。PlayerExemptOff 通过服务器 API 移除临时完整豁免。
- 先加载服务器辅助文件,再加载使用 TosunAC 的脚本,同时保留 manifest 中其他依赖。
- 活动开始时检查 ok 与 mode,只记录资源、原因和非机密结果。
- 明确处理 AC 未启动或调用被拒绝分支,重试前调查启动顺序与信任配置。
-- Add these lines to your own resource manifest:
client_script "@tosun-ac/bridge/tosun_ac_client.lua"
server_script "@tosun-ac/bridge/tosun_ac_server.lua"将只读导出用于诊断,而非判决#
GetStatus 提供小型运行摘要,包括配置中的框架和在线人数,不是全部集成审计。GetIntegrationStatus 描述调用资源的信任,不代表所有脚本。IsMovementExempt 与 IsExemptFromPunish 回答不同问题。GetDetections 是历史名称,实际读取玩家在 ts_anticheat 中的封禁,不是所有最近检测日志。空结果不等于玩家无违规证明。数据库与广泛玩家查询应按需执行,不要每 tick 调用。返回对象应按文档目的使用,公开调试输出不要附带凭证或多余个人资料。
- 排查时记录调用资源以及具体查看了哪个状态或豁免检查。
- 先将已知流程预期范围与实际结果对照,再考虑改变处罚。
- 更新后重新阅读安装包中的 TOSUN-AC-EXPORTS.md,重点核对旧别名和服务器、客户端参数顺序。
让延迟移动受玩家连接和 resource 生命周期约束#
进入房屋需要短暂等待时,仅保存玩家的 source 数字还不够。玩家断开后,新连接可能重新使用同一个数字。下面的 server.lua 片段是供已获授权的服务器流程调用的本地函数,不是客户端可访问的网络事件。目标位置必须经过服务器验证。pending 中独立的 Lua 对象把延迟移动绑定到这次流程。玩家离开时删除记录;定时回调找不到同一个对象便不执行。因此,之后取得旧 source 的新玩家不会受到原来那次移动影响。函数没有自动赋予房屋访问权限。
tosun-ac 停止或当前 resource 关闭时,例子会清除待处理记录。等待结束后重新检查 resource 状态、玩家是否在线,以及 ped 是否存在。pcall 捕获 export 调用错误,只有 MarkTeleport 返回 true 才移动玩家。这些检查不能授予房屋所有权、职业角色或目标地点权限,相关条件应在调用前确认。代码只申请移动宽限,不撤销全局临时豁免,也不改变其他脚本的权限。分别测试等待期间断线、AC 停止和正常进入。无需常驻循环或扫描全体玩家的定时器,每个实际启动的流程只创建一次等待。
-- server.lua: call only from an already authorised server workflow.
-- destination is a server-validated location, never raw client input.
local pending = {}
local function scheduleValidatedMove(src, destination)
src = tonumber(src)
if not src or not GetPlayerName(src) then return false end
if GetResourceState("tosun-ac") ~= "started" then return false end
local ticket = {}
local target = {x = destination.x, y = destination.y, z = destination.z}
pending[src] = ticket
SetTimeout(1500, function()
if pending[src] ~= ticket then return end
pending[src] = nil
if not GetPlayerName(src) then return end
if GetResourceState("tosun-ac") ~= "started" then return end
local ped = GetPlayerPed(src)
if not ped or ped == 0 then return end
local called, allowed = pcall(function()
return exports["tosun-ac"]:MarkTeleport(src, 8000, "house_delayed_entry")
end)
if called and allowed == true then
SetEntityCoords(ped, target.x, target.y, target.z)
end
end)
return true -- Scheduled, not yet moved.
end
AddEventHandler("playerDropped", function() pending[source] = nil end)
AddEventHandler("onResourceStop", function(name)
if name == GetCurrentResourceName() or name == "tosun-ac" then
pending = {}
end
end)在执行集成的 resource 内检查信任状态#
修改信任名单后,应把这个诊断放在真正调用 export 的 resource 内。下面的命令只接受服务器控制台调用;玩家调用的 src 不为零,会被直接忽略。运行一次 my-resource-ac-check 即可。GetIntegrationStatus 返回调用 resource 的名称,以及 trusted 和 enforcing。其他 resource 内得到 true,并不能证明你的服装或竞技场脚本也受到信任。GetStatus 只是包含版本和配置 framework 的小型运行摘要,不是对所有集成的审核报告。诊断应明确对应实际调用者。
即使 pcall 成功,返回值也必须是表。调用出错与返回 false 是两种不同观察;export 无法调用时,不应声称配置已经验证。若 trusted=false 且 enforcing=true,请核对调用者名称和已审查的信任名单。enforcing=false 可能属于审核模式,并不表示所有敏感操作都受到了安全限制。输出只包含 resource、版本、framework 和两个布尔值,不导出玩家标识或密钥。不要每个 tick 都运行诊断。更新后仍需分别测试正常流程和预期拒绝流程;只读状态检查不能保证处罚类 export 的授权边界。
-- Place in the integrating resource's server.lua.
RegisterCommand("my-resource-ac-check", function(src)
if src ~= 0 then return end -- Server console only.
if GetResourceState("tosun-ac") ~= "started" then
print("[integration] tosun-ac is not started")
return
end
local okTrust, trust = pcall(function()
return exports["tosun-ac"]:GetIntegrationStatus()
end)
local okStatus, status = pcall(function()
return exports["tosun-ac"]:GetStatus()
end)
if not okTrust or type(trust) ~= "table"
or not okStatus or type(status) ~= "table" then
print("[integration] status query failed")
return
end
print(("[integration] resource=%s version=%s framework=%s trusted=%s enforcing=%s")
:format(GetCurrentResourceName(), tostring(status.version),
tostring(status.framework), tostring(trust.trusted), tostring(trust.enforcing)))
end, false)为自定义事件注册服务器验证#
在服务器脚本中使用 RegisterSafeEvent,事件名称必须以调用资源的名称开头。验证器必须检查服务器保存的玩家、任务、位置、物品及权限,并且严格返回 true,处理器才会执行。客户端事件密钥不是权限。完成的任务只能在服务器消费一次,避免重复奖励。
客户端使用导出 TriggerSafeServerEvent。sent 仅表示已发送,不表示付款或奖励成功。queued_until_key 最多等待30秒;队列已满时拒绝新调用。不要自动重复经济操作。AC 重启后需重新注册。
必须迁移并移除原有直接 RegisterNetEvent 处理器。Tosun AC 无法取消其他资源的处理器;保留旧的敏感操作会留下绕过入口。旧版 ProtectedEvents 的 :safe 处理器只能在服务器通过 AddEventHandler 注册。
-- my-job/server.lua: own server-owned job state and framework adapter.
local activeJobs = {}
local function registerActions()
if GetResourceState("tosun-ac") ~= "started" then return end
local ok, reason = exports["tosun-ac"]:RegisterSafeEvent("my-job:finish",
function(src)
local job = activeJobs[src]
return job ~= nil and job.completed == true
-- Also verify server-owned position, role and inventory as required.
end,
function(src)
local job = activeJobs[src]
if not job then return end
activeJobs[src] = nil -- consume before any yielding reward operation
-- Give the server-owned reward through your validated framework adapter.
end, {rateLimit=5, windowMs=10000, maxArgs=0})
if not ok then print("[my-job] SafeEvent: " .. tostring(reason)) end
end
AddEventHandler("onResourceStart", function(name)
if name == GetCurrentResourceName() or name == "tosun-ac" then registerActions() end
end)
AddEventHandler("playerDropped", function() activeJobs[source] = nil end)
-- my-job/client.lua:
local sent, state = exports["tosun-ac"]:TriggerSafeServerEvent("my-job:finish")
-- Read state; implement a separate application acknowledgement if needed.
准确配置调用资源名称#
在 server.cfg 添加 set tosun_ac_trusted_resources "my-housing,my-clothing",保留其他已审查的名称。填写资源/文件夹名,不是显示名称、玩家或 Discord 角色。使用 set,而不是 setr;保持 ts.EnforceExportCallerWhitelist = true。信任允许调用敏感 export,但不验证房屋所有权、物品、职业或目标玩家。必须在实际执行操作的资源内诊断,检查 trusted=true 和 enforcing=true。
set tosun_ac_trusted_resources "my-housing,my-clothing"
# txAdmin server console:
tosunac_integration
-- In the invoking integration resource server script:
local status = exports["tosun-ac"]:GetIntegrationStatus()
print(status.resource, status.trusted, status.enforcing)五种列表有五种用途#
可信资源列表允许敏感服务器 export。玩家白名单保护玩家。假触发器白名单仅关闭一个陷阱,不授权真实事件。ts.ProtectedEvents 是旧的密钥传输层,默认包含 test:event。资源 baseline 记录已审查文件,用于完整性检查。加入一个列表不会加入其他列表。不要把所有发现的框架事件复制到 ProtectedEvents 或标记为陷阱。
本安装包的完整服务器 export 目录#
以下名称和参数声明由本包实际服务器源码清单生成。这是参考,不是按顺序执行的脚本。大小写以及服务器/客户端端别必须准确。也列出内部诊断、扫描和传输助手,避免把相似名称误认为安全业务 API。修改数据前阅读契约和返回语义;知道名称不代表有权限。
-- tosun-ac / server
-- AddWhitelist(target, durationSec)
-- AllowWeapon(src, weapon, ms)
-- BanPlayerExt(playerId, reason)
-- BypassDetection(playerId, detectionKey, durationMs)
-- ClearArea(playerId, areaName)
-- ForensicLinksOf(license)
-- GetCloudThreatScore(src)
-- GetDetections(playerId, limit)
-- GetIntegrationStatus()
-- GetNearbyPlayers(playerId, radius)
-- GetPlayerInfo(playerId)
-- GetPlayerShieldData(src)
-- GetServerAuthorityStatus()
-- GetStatus()
-- IsExemptFromPunish(src)
-- IsInArea(playerId, areaName)
-- IsMovementExempt(src)
-- IsPlayerProtected(playerId)
-- IsWhitelisted(playerId)
-- KickPlayer(playerId, reason)
-- MarkTeleport(src, ms, reason)
-- NoteCloudViolation(src, reason, punishment)
-- OpenScanCache(sealed)
-- PauseAllDetections(durationMs)
-- PausePlayerDetections(playerId, durationMs)
-- RateLimit(src, key, max, windowMs)
-- RegisterSafeEvent(eventName, validator, handler, options)
-- RemoveWhitelist(target)
-- RequestShieldScreenshot(src)
-- ScanPolicyFingerprint(moduleFile, policy)
-- ScanResourceSnapshot(name, expected, callback)
-- SealScanCache(raw)
-- SetExempt(playerId, durationMs, reason)
-- SetPlayerExempt(playerId, state, durationMs, reason)
-- WhitelistArea(playerId, areaName, durationSec)
-- acV2Challenge(build, license, fp, version)
-- acV2Fingerprint()
-- acV2Integrity(raw)
-- acV2VerifyResponse(raw, build, license, fp, version, nonce, httpCode)
-- addAdmin(playerId)
-- addCheatSignature(pattern, signatureName, severity)
-- addSignatureEscrowSkip(resourceName, note)
-- addSignatureException(resourceName, filePath, signatureName, note)
-- applyTimeWithFramework(h, m)
-- applyWeatherWithFramework(weather)
-- approveResource(resourceName, approvedBy)
-- ban(playerId, reason)
-- batchDetection(playerName, license, steam, discord, ip, dtype, reason, punishment, banID, screenshot, configKey)
-- batchLog(message, playerId, playerName)
-- batchWebhook(url, payload)
-- blockResource(resourceName, reason)
-- centralHandshake()
-- centralPoll()
-- centralStatus()
-- checkIpReputation(ip)
-- cipherHasSession(src)
-- cipherIssueKey(src)
-- cipherVerify(src, payload, signature)
-- clearInventory(src)
-- crashGuardInspect(v)
-- crashGuardReject(src, p)
-- emergencyLockdown(reason)
-- fakeTriggerTrap(eventName, typ)
-- fakeTriggerWhitelist(eventName)
-- freezePlayer(src, freeze)
-- getAdminType(playerId)
-- getBanInfo(banID)
-- getBans(limit, offset)
-- getBaseline()
-- getBatchStats()
-- getCleanupStats()
-- getConfig(configType)
-- getInfectedFiles()
-- getOnlinePlayers()
-- getPlayerLocale(src)
-- getResources()
-- getRuntimeStats()
-- getSourceKey()
-- getStats()
-- getSuspicious()
-- giveWeapon(src, weapon, ammo)
-- healAll()
-- invalidateSignatureCache()
-- isAdmin(playerId)
-- isAdminMenuAllowed(playerId)
-- isPlayerFrozen(src)
-- isPlayerMuted(src)
-- isQuarantined(src)
-- isStaffPlayer(playerId)
-- issueEventKey(src)
-- licenseStatus()
-- lockdownStatus()
-- massFreeze(state)
-- mutePlayer(src, durationSec, reason, actor)
-- offlineBan(data, reason)
-- offlineBanByLicense(...)
-- phoneNotify(targetSrc, title, body, opts)
-- phoneNotifyAdmins(title, body, opts)
-- punish(playerId, reason, image, config, punish)
-- quarantine(src, reason, sec)
-- quarantineList()
-- refreshPanelPermissions()
-- refreshPanelWhitelist()
-- releaseQuarantine(src)
-- reloadSignatureExceptions()
-- reloadSignatureScanCaches()
-- removeAdmin(playerId)
-- removeSignatureEscrowSkip(idOrName)
-- removeSignatureException(id)
-- removeWhitelist(playerId)
-- reportInfection(resource, file, sigs, severity, callback)
-- rescanResources()
-- runCleanup()
-- scanAllResources()
-- scanSingleResource(name)
-- screenCapture(src, requestedBy)
-- setLockdown(state, reason)
-- setPlayerArmor(src, armor)
-- setPlayerHealth(src, hp)
-- setPlayerLocale(src, lang)
-- setSpeedLimit(kmh)
-- slayPlayer(src)
-- spectatePlayer(adminSrc, targetSrc)
-- stripWeapons(src)
-- translate(key, ...)
-- translateForPlayer(src, key, ...)
-- tsAutoSetup()
-- tsBackdoorScanStatus()
-- tsLicenseRecheck()
-- tsScanBackdoors(callback)
-- tsScanEvents()
-- tsSignatureScanStatus()
-- unban(banID)
-- unmutePlayer(src)
-- v6ScreenWatchLatest(serverId)
-- v6ScreenWatchPoll(rid)
-- v6ScreenWatchRequest(serverId, mode, requestedBy, panelUrl, forceBase64)
-- v9StreamHasSession(serverId)
-- warnPlayer(src, reason, actor)
-- webBridgeApplyInventory(src, action, itemName, count, slot)
-- webBridgeApplyMoney(src, moneyType, amount, action)
-- webBridgeFindByCitizen(cid)
-- webBridgeFindByLicense(license)
-- webBridgeGrantAdmin(src)
-- webBridgeRevokeAdmin(src)
-- whitelistPlayer(playerId, duration)
-- tosun-ac-guardian / server
-- guardianAlive()
-- guardianHold(reason,seconds)
-- tosun_render / server
-- GetStatus()客户端 export 与有限本地宽限#
客户端 SetExempt 接收状态、毫秒、原因;服务器版本接收玩家 source、毫秒、原因。客户端 PauseDetections 仅提供同样有限的外观、移动、相机宽限,不是全局暂停。本地调用共用每十分钟240秒延长预算,最多32个原因。IsExempt(config) 必须提供准确检测键;IsExempt() 只表示已验证人员或可信完整/暂停许可。武器、事件、注入、未知检测仍工作。处理 false,不要每帧重试。
-- tosun-ac / client
-- GetExemptions()
-- IsExempt(config)
-- IsPlayerAdmin()
-- NativeGuardThreat()
-- NativeGuardToken()
-- PauseDetections(durationMs)
-- SetExempt(state, durationMs, reason)
-- SetSpawned(state)
-- ShieldCaptureForBan(callback)
-- ShieldFlushBanVideo(callback)
-- TriggerSafeServerEvent(eventName, ...)
-- getConfig()
-- getV12Tolerance(key, default)
-- incNetRequest()
-- incScreenshotEvent()
-- shieldHook(hookType, detailJson)理解私有状态和返回值#
TosunAcState 是 AC 资源内部 API;其他资源使用公开 export。服务器 setExempt、setPause、setMovement 返回布尔值,许可最长五分钟。通知失败不会保存新增延长;撤销或缩短即使返回 false 仍保留在私有记录。完整、暂停、移动许可独立。setStaff 只写兼容镜像,不能授予已验证管理权限。isExemptFromBag/isPausedFromBag 读取已验证私有许可,不读取玩家可写 bag。成功不证明所有客户端收到,也不表示所有服务器检测暂停。
-- Internal AC server API; external resources use guarded exports.
-- TosunAcState.setExempt(id, active, ms) -> boolean
-- TosunAcState.setPause(id, ms) -> boolean
-- TosunAcState.setMovement(id, ms) -> boolean
-- TosunAcState.remaining(id, kind) -> remaining milliseconds
-- TosunAcState.setStaff(id, staff) -> compatibility mirror only
-- AddWhitelist(target, durationSec): seconds
-- WhitelistArea(playerId, areaName, durationSec): seconds
-- IsInArea: named record lookup, not a coordinate/permission check
-- WhitelistArea grants broad client relief, not one chosen detector.
-- BypassDetection: detectionKey is ignored; full exemption, <=60000ms
-- Client: IsExempt("ts.antiFreeCam") -> scoped camera grace
-- Client: IsExempt() -> verified staff/full/pause only事件名称目录不等于授权#
此源码目录按注册端列出固定 AC 协议事件。无法涵盖计算出的名称或您资源的所有事件。不要手动重放内部密钥、处罚、配置或菜单事件。发现名称与方向不能判断物品所有者或奖励是否应得。敏感自定义操作使用经过验证的 RegisterSafeEvent。面板保护和 ac_protected_events 生成假触发器/honeypot 规则,不生成服务器验证器;安装时保留 EventScanner.autoProtect=false。
-- tosun-ac/client/AddEventHandler
-- CEventShockingGunshotFired
-- baseevents:onPlayerDied
-- baseevents:onPlayerKilled
-- esx:onPlayerDeath
-- esx_ambulancejob:revive
-- esx_basicneeds:onRevive
-- gameEventTriggered
-- hospital:client:Revive
-- hospital:client:SetDeathState
-- hospital:client:SetLaststand
-- hospital:client:isDead
-- onClientResourceStart
-- onClientResourceStop
-- playerSpawned
-- qb-ambulancejob:client:RevivePlayer
-- qb-medical:client:OnDeath
-- qb-medical:client:OnRevive
-- tosun-ac:nui:pushToolState
-- tosun-ac:uploadTokenUpdated
-- ts_anticheat:adminStateChanged
-- ts_anticheat:adminStatus
-- ts_anticheat:bridge:capture
-- ts_anticheat:bridge:clearInventory
-- ts_anticheat:bridge:freeze
-- ts_anticheat:bridge:giveWeapon
-- ts_anticheat:bridge:heal
-- ts_anticheat:bridge:mute
-- ts_anticheat:bridge:revive
-- ts_anticheat:bridge:setArmor
-- ts_anticheat:bridge:setHealth
-- ts_anticheat:bridge:slay
-- ts_anticheat:bridge:speedLimit
-- ts_anticheat:bridge:stripWeapons
-- ts_anticheat:bridge:teleport
-- ts_anticheat:bridge:time
-- ts_anticheat:bridge:warning
-- ts_anticheat:bridge:weather
-- ts_anticheat:checkTaze
-- ts_anticheat:cipher:assigned
-- ts_anticheat:cipher:request_refresh
-- ts_anticheat:clearDone
-- ts_anticheat:configUpdated
-- ts_anticheat:detectclient
-- ts_anticheat:internal:receiveKey
-- ts_anticheat:internal:trapsChanged
-- ts_anticheat:isAdmin
-- ts_anticheat:joinBundle
-- ts_anticheat:liveSSRequest
-- ts_anticheat:newDetection
-- ts_anticheat:openAdminMenu
-- ts_anticheat:openAdminMenuAuthorized
-- ts_anticheat:panelBroadcast
-- ts_anticheat:panelHeal
-- ts_anticheat:panelRevive
-- ts_anticheat:panelTime
-- ts_anticheat:panelWeather
-- ts_anticheat:promptOpenMenu
-- ts_anticheat:receiveKey
-- ts_anticheat:receiveLiveSS
-- ts_anticheat:receiveLiveVideo
-- ts_anticheat:receivePlayerCount
-- ts_anticheat:receiveScreenshot
-- ts_anticheat:requestCoords
-- ts_anticheat:resourceGuardSync
-- ts_anticheat:shield:requestScreenshot
-- ts_anticheat:shield:uploadConfig
-- ts_anticheat:startVideoLiveStream
-- ts_anticheat:startVideoLiveWeb
-- ts_anticheat:startVideoRecording
-- ts_anticheat:stopVideoLiveStream
-- ts_anticheat:stopVideoLiveWeb
-- ts_anticheat:stopVideoRecording
-- ts_anticheat:syncBanList
-- ts_anticheat:syncConfig
-- ts_anticheat:syncIdentifiers
-- ts_anticheat:syncLogs
-- ts_anticheat:syncPlayers
-- ts_anticheat:takeScreenshot
-- ts_anticheat:unbanDone
-- ts_anticheat:webPanelScreenshot
-- tosun-ac/client/RegisterNUICallback
-- Armour
-- DeleteAll
-- DeleteObjects
-- DeletePeds
-- DeleteVehicles
-- GetPlayerIdentifiers
-- Health
-- addLog
-- armourPlayer
-- banPlayer
-- bringAll
-- bringPlayer
-- cancelAnimation
-- clearNearbyObjects
-- clearNearbyPeds
-- clearNearbyVehicles
-- devtoolsdetected
-- exit
-- freezeAll
-- freezePlayerToggle
-- getBans
-- getLogs
-- getPlayerCount
-- getPlayers
-- giveWeaponPlayer
-- healAll
-- healPlayer
-- isInVehicle
-- kickPlayer
-- liveWatchStart
-- liveWatchStop
-- nuiDependencyMissing
-- nuiWatermark
-- repair
-- returnOCRResult
-- reviveAll
-- revivePlayer
-- screenshotPlayer
-- selfRevive
-- setHealthPlayer
-- setTime
-- setWeather
-- shield_devtools
-- shield_heartbeat
-- shield_heartbeat_fail
-- shield_screenshot
-- shield_tokens
-- shield_video_final
-- shield_video_segment
-- slayPlayer
-- spawnVehicle
-- spectatePlayer
-- stopSpectate
-- stripWeaponsPlayer
-- toggleESP
-- toggleFreecam
-- toggleGodmode
-- toggleInvisible
-- toggleNoclip
-- tosunRenderResult
-- tpToPlayer
-- unbanPlayer
-- verifyModel
-- videoLiveSegmentResult
-- videoRecordingResult
-- videoRecordingStartResult
-- warnPlayerNUI
-- tosun-ac/client/RegisterNetEvent
-- QBCore:Client:OnPlayerLoaded
-- QBCore:Client:OnPlayerUnload
-- esx:onPlayerDeath
-- esx:onPlayerLogout
-- esx:playerLoaded
-- esx_ambulancejob:revive
-- esx_basicneeds:onRevive
-- hospital:client:Revive
-- hospital:client:SetDeathState
-- hospital:client:SetLaststand
-- hospital:client:isDead
-- qb-ambulancejob:client:RevivePlayer
-- qb-medical:client:OnDeath
-- qb-medical:client:OnRevive
-- qbx_core:client:playerLoggedIn
-- qbx_multicharacter:client:chooseChar
-- ts_anticheat:adminStateChanged
-- ts_anticheat:adminStatus
-- ts_anticheat:bridge:capture
-- ts_anticheat:bridge:clearInventory
-- ts_anticheat:bridge:freeze
-- ts_anticheat:bridge:giveWeapon
-- ts_anticheat:bridge:heal
-- ts_anticheat:bridge:mute
-- ts_anticheat:bridge:revive
-- ts_anticheat:bridge:setArmor
-- ts_anticheat:bridge:setHealth
-- ts_anticheat:bridge:slay
-- ts_anticheat:bridge:speedLimit
-- ts_anticheat:bridge:stripWeapons
-- ts_anticheat:bridge:teleport
-- ts_anticheat:bridge:time
-- ts_anticheat:bridge:warning
-- ts_anticheat:bridge:weather
-- ts_anticheat:checkTaze
-- ts_anticheat:cipher:assigned
-- ts_anticheat:cipher:request_refresh
-- ts_anticheat:clearDone
-- ts_anticheat:detectclient
-- ts_anticheat:isAdmin
-- ts_anticheat:joinBundle
-- ts_anticheat:liveSSRequest
-- ts_anticheat:newDetection
-- ts_anticheat:openAdminMenu
-- ts_anticheat:openAdminMenuAuthorized
-- ts_anticheat:panelBroadcast
-- ts_anticheat:panelHeal
-- ts_anticheat:panelRevive
-- ts_anticheat:panelTime
-- ts_anticheat:panelWeather
-- ts_anticheat:promptOpenMenu
-- ts_anticheat:receiveEventKey
-- ts_anticheat:receiveKey
-- ts_anticheat:receiveLiveSS
-- ts_anticheat:receiveLiveVideo
-- ts_anticheat:receivePlayerCount
-- ts_anticheat:receiveScreenshot
-- ts_anticheat:requestCoords
-- ts_anticheat:resourceGuardSync
-- ts_anticheat:shield:requestScreenshot
-- ts_anticheat:shield:uploadConfig
-- ts_anticheat:startVideoLiveStream
-- ts_anticheat:startVideoLiveWeb
-- ts_anticheat:startVideoRecording
-- ts_anticheat:stopVideoLiveStream
-- ts_anticheat:stopVideoLiveWeb
-- ts_anticheat:stopVideoRecording
-- ts_anticheat:syncBanList
-- ts_anticheat:syncConfig
-- ts_anticheat:syncIdentifiers
-- ts_anticheat:syncLogs
-- ts_anticheat:syncPlayers
-- ts_anticheat:takeScreenshot
-- ts_anticheat:unbanDone
-- ts_anticheat:uploadToken
-- ts_anticheat:webPanelScreenshot
-- tosun-ac/server/AddEventHandler
-- QBCore:Server:OnPlayerLoaded
-- QBCore:Server:PlayerLoaded
-- chatMessage
-- clearPedTasksEvent
-- entityControlEvent
-- entityCreated
-- entityCreating
-- esx:playerLoaded
-- eventTriggered
-- explosionEvent
-- fireEvent
-- giveWeaponEvent
-- onResourceStart
-- onResourceStop
-- onServerResourceStart
-- playerConnecting
-- playerDropped
-- playerJoining
-- ptFxEvent
-- qbx_core:server:playerLoaded
-- rconCommand
-- removeAllWeaponsEvent
-- removeWeaponEvent
-- requestControlEvent
-- respawnPlayerPedEvent
-- startProjectileEvent
-- tosun-ac:nuiPermissionRefreshed
-- tosun-ac:panel:characterReady
-- tosun-ac:server:detection
-- tosun-ac:server:logResourceActivity
-- tosun-ac:server:nuiWatermark
-- tosun-ac:server:signedDetection
-- tosun-ac:settingsReloaded
-- ts_anticheat:GetPlayerIdentifiers
-- ts_anticheat:addAdmin_internal
-- ts_anticheat:addLog
-- ts_anticheat:adminDelEntity
-- ts_anticheat:banCommitted
-- ts_anticheat:banPlayer
-- ts_anticheat:banRelay
-- ts_anticheat:bridge:freeze
-- ts_anticheat:bringAllPlayers
-- ts_anticheat:bringPlayer
-- ts_anticheat:cipher:detection
-- ts_anticheat:cipher:request
-- ts_anticheat:clearTasks
-- ts_anticheat:client:scriptsReady
-- ts_anticheat:configUpdated
-- ts_anticheat:deleteObjects
-- ts_anticheat:deletePeds
-- ts_anticheat:deleteVehicles
-- ts_anticheat:freezeAllPlayers
-- ts_anticheat:getBanList
-- ts_anticheat:getLogs
-- ts_anticheat:getPlayerCount
-- ts_anticheat:getPlayers
-- ts_anticheat:healAllPlayers
-- ts_anticheat:internal:pushResourceGuard
-- ts_anticheat:internal:suspicious
-- ts_anticheat:kickPlayer
-- ts_anticheat:liveSSResult
-- ts_anticheat:liveWatchStart
-- ts_anticheat:liveWatchStop
-- ts_anticheat:logAdminMenu
-- ts_anticheat:newLog
-- ts_anticheat:playerBanned
-- ts_anticheat:requestAdminStatus
-- ts_anticheat:requestEventKey
-- ts_anticheat:requestKey
-- ts_anticheat:requestOpenAdminMenu
-- ts_anticheat:returnCoords
-- ts_anticheat:reviveAllPlayers
-- ts_anticheat:screenshotPlayer
-- ts_anticheat:screenshotResult
-- ts_anticheat:server:<computed suffix> [template only; not a runnable exact event]
-- ts_anticheat:server:checkIsAdmin
-- ts_anticheat:server:clientXkzuqBwmTjN7Gab4QzuN9QYZJ1WxxU
-- ts_anticheat:server:requestJoinHandshake
-- ts_anticheat:server:requestResourceGuard
-- ts_anticheat:server:requestSyncData
-- ts_anticheat:server:tazed
-- ts_anticheat:serverClear
-- ts_anticheat:setInvisible
-- ts_anticheat:setTime
-- ts_anticheat:setWeather
-- ts_anticheat:shield:ban_video_saved
-- ts_anticheat:spawnVehicle
-- ts_anticheat:targetArmour
-- ts_anticheat:targetFreeze
-- ts_anticheat:targetGiveWeapon
-- ts_anticheat:targetHeal
-- ts_anticheat:targetRevive
-- ts_anticheat:targetSetHealth
-- ts_anticheat:targetSlay
-- ts_anticheat:targetStripWeapons
-- ts_anticheat:targetWarn
-- ts_anticheat:tpToPlayer
-- ts_anticheat:unbanPlayer
-- ts_anticheat:v10:exec
-- ts_anticheat:v6:detection
-- ts_anticheat:v6:screenshotResult
-- ts_anticheat:verifyModel
-- ts_anticheat:videoResult
-- vehicleComponentControlEvent
-- weaponDamageEvent
-- tosun-ac/server/RegisterNetEvent
-- tosun-ac:panel:characterReady
-- tosun-ac:server:detection
-- tosun-ac:server:logResourceActivity
-- tosun-ac:server:nuiWatermark
-- tosun-guard:acMissing
-- tosun-guard:hello
-- tosun-guard:tick
-- tosun:nativeGuard:status
-- ts_anticheat:GetPlayerIdentifiers
-- ts_anticheat:addLog
-- ts_anticheat:adminDelEntity
-- ts_anticheat:banPlayer
-- ts_anticheat:banRelay
-- ts_anticheat:bridge:freeze
-- ts_anticheat:bringAllPlayers
-- ts_anticheat:bringPlayer
-- ts_anticheat:cipher:detection
-- ts_anticheat:cipher:request
-- ts_anticheat:client:scriptsReady
-- ts_anticheat:deleteObjects
-- ts_anticheat:deletePeds
-- ts_anticheat:deleteVehicles
-- ts_anticheat:freezeAllPlayers
-- ts_anticheat:getBanList
-- ts_anticheat:getLogs
-- ts_anticheat:getPlayerCount
-- ts_anticheat:getPlayers
-- ts_anticheat:healAllPlayers
-- ts_anticheat:kickPlayer
-- ts_anticheat:liveSSResult
-- ts_anticheat:liveWatchStart
-- ts_anticheat:liveWatchStop
-- ts_anticheat:logAdminMenu
-- ts_anticheat:requestAdminStatus
-- ts_anticheat:requestEventKey
-- ts_anticheat:requestKey
-- ts_anticheat:requestOpenAdminMenu
-- ts_anticheat:returnCoords
-- ts_anticheat:reviveAllPlayers
-- ts_anticheat:screenshotPlayer
-- ts_anticheat:screenshotResult
-- ts_anticheat:server:checkIsAdmin
-- ts_anticheat:server:clientXkzuqBwmTjN7Gab4QzuN9QYZJ1WxxU
-- ts_anticheat:server:requestJoinHandshake
-- ts_anticheat:server:requestResourceGuard
-- ts_anticheat:server:requestSyncData
-- ts_anticheat:server:tazed
-- ts_anticheat:serverClear
-- ts_anticheat:setInvisible
-- ts_anticheat:setTime
-- ts_anticheat:setWeather
-- ts_anticheat:shield:banVideo
-- ts_anticheat:shield:heartbeat_fail
-- ts_anticheat:shield:requestUploadConfig
-- ts_anticheat:shield:screenshot
-- ts_anticheat:shield:tokens
-- ts_anticheat:spawnVehicle
-- ts_anticheat:targetArmour
-- ts_anticheat:targetFreeze
-- ts_anticheat:targetGiveWeapon
-- ts_anticheat:targetHeal
-- ts_anticheat:targetRevive
-- ts_anticheat:targetSetHealth
-- ts_anticheat:targetSlay
-- ts_anticheat:targetStripWeapons
-- ts_anticheat:targetWarn
-- ts_anticheat:tpToPlayer
-- ts_anticheat:unbanPlayer
-- ts_anticheat:v10:exec
-- ts_anticheat:v6:detection
-- ts_anticheat:v6:screenshotResult
-- ts_anticheat:verifyModel
-- ts_anticheat:videoResult
-- tosun-ac/server/RegisterServerEvent
-- ts_anticheat:clearTasks
-- tosun-ac/shared/AddEventHandler
-- onClientResourceStart
-- onResourceStop
-- playerDropped
-- ts_anticheat:locale:reload
-- ts_anticheat:locale:setSelf
-- ts_anticheat:locale:sync
-- tosun-ac/shared/RegisterNetEvent
-- ts_anticheat:locale:setSelf
-- ts_anticheat:locale:sync
-- tosun-ac-guardian/server/AddEventHandler
-- onResourceStart
-- onResourceStop
-- tosun_render/server/AddEventHandler
-- onResourceStart
-- tosun-ac/client / RegisterCommand
-- stopspectate
-- tsdelaimed
-- tsfreecam
-- tsmenu
-- unspectate
-- tosun-ac/server / RegisterCommand
-- ac_cleanup
-- acfreeze
-- acping
-- acstats
-- acunfreeze
-- acwarn
-- capture
-- clearinv
-- emergency
-- giveweapon
-- massfreeze
-- mute
-- setarmor
-- sethp
-- speedlimit
-- stripweapons
-- tosunac_backdoorscan
-- tosunac_db_check
-- tosunac_db_status
-- tosunac_doctor
-- tosunac_eventscan
-- tosunac_integration
-- tosunac_license_status
-- tosunac_setup
-- ts
-- ts_adminsync
-- ts_broadcast
-- ts_capture
-- ts_clearinv
-- ts_emergency
-- ts_freeze
-- ts_giveweapon
-- ts_healall
-- ts_kickall
-- ts_lockdown
-- ts_massfreeze
-- ts_modping
-- ts_mute
-- ts_players
-- ts_revive
-- ts_setarmor
-- ts_sethp
-- ts_settime
-- ts_setweather
-- ts_slay
-- ts_speedlimit
-- ts_stripweapons
-- ts_tphere
-- ts_tpto
-- ts_unfreeze
-- ts_unmute
-- ts_v9_help
-- ts_warn
-- ts_warnings
-- unmute
-- tosun-ac/shared / RegisterCommand
-- ts_setlang
-- tosun-ac-guardian/server / RegisterCommand
-- tosunac_guardian_pause
-- tosunac_guardian_resume
-- tosunac_guardian_status
-- tosun_render/server / RegisterCommand
-- tosun_render_statusSafeEvent 重启、队列与失败处理#
RegisterSafeEvent 要求资源名前缀的事件、validator、handler。validator 检查当前服务器状态后必须严格返回 true。删除旧的原始网络 handler;AC 不能取消其他资源独立处理器。您资源或 tosun-ac 重启后重新注册。客户端状态为 sent、queued_until_key、queue_full、invalid_event_or_arguments、resource_stopping。sent 仅表示发送,不是奖励回执。队列最多32次,30秒过期。handler 出错不会自动重放或确认成功。使用单独业务回执与幂等操作,绝不自动重试金钱或物品奖励。
-- Client TriggerSafeServerEvent results:
-- true, "sent"
-- false, "queued_until_key"
-- false, "queue_full"
-- false, "invalid_event_or_arguments"
-- false, "resource_stopping"
-- Server RegisterSafeEvent results:
-- true, "registered"
-- false + server_resource_required / use_own_resource_prefix
-- false + invalid_callbacks_or_options / already_registered / registration_capacity
-- Server log may say: application handler failed.
-- No automatic replay; implement an application receipt.报告入队不等于数据库写入确认#
reportInfection(resource, file, sigs, severity[, callback]) 仅在数据库操作入队时返回 true。可选 callback 最多一次,参数 success、affectedRows;成功要求正整数行数。driver 不响应则无法保证完成。Resource 为1–190字节字母/数字/_.-,file 1–500字节,severity 1–50 字节字母/数字/_-,默认 warning。sigs 为非空字符串或连续1–32字符串列表,合并最多255字节。拒绝 NUL/CR/LF。输入错误、driver 缺失/拒绝或同步异常返回 false。结果不确定时不可自动重放。
-- A reviewed server reporting workflow; fictional non-secret labels.
-- resource: 1..190 bytes, letters/digits/underscore/dot/hyphen
-- file: 1..500 bytes; signatures joined: 1..255 bytes
-- severity: 1..50 bytes, letters/digits/underscore/hyphen (no dot)
local queued = exports["tosun-ac"]:reportInfection(
"my-housing", "server.lua", {"reviewed_pattern"}, "warning",
function(success, affectedRows)
print(success and "[scan] report saved" or "[scan] report not confirmed")
end)
-- queued=true is dispatch only; it is not the completion callback.
-- Do not automatically retry an operation with an uncertain outcome.