From e19b16931d95b9c8a009395eaa718de64715b199 Mon Sep 17 00:00:00 2001 From: Brettflan Date: Fri, 16 Dec 2011 04:21:21 -0600 Subject: [PATCH] Color tags shouldn't work in descriptions any more; no more purple "[SERVER]" description messages to impersonate the console --- src/com/massivecraft/factions/cmd/CmdDescription.java | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/src/com/massivecraft/factions/cmd/CmdDescription.java b/src/com/massivecraft/factions/cmd/CmdDescription.java index a80f023c..01190f51 100644 --- a/src/com/massivecraft/factions/cmd/CmdDescription.java +++ b/src/com/massivecraft/factions/cmd/CmdDescription.java @@ -32,13 +32,13 @@ public class CmdDescription extends FCommand // if economy is enabled, they're not on the bypass list, and this command has a cost set, make 'em pay if ( ! payForCommand(Conf.econCostDesc, "to change faction description", "for changing faction description")) return; - myFaction.setDescription(TextUtil.implode(args, " ")); - + myFaction.setDescription(TextUtil.implode(args, " ").replaceAll("(&([a-f0-9]))", "& $2")); // since "&" color tags seem to work even through plain old FPlayer.sendMessage() for some reason, we need to break those up + // Broadcast the description to everyone for (FPlayer fplayer : FPlayers.i.getOnline()) { fplayer.msg("%s changed their description to:", myFaction.describeTo(fplayer)); - fplayer.msg(""+myFaction.getDescription()); + fplayer.sendMessage(myFaction.getDescription()); // players can inject "&" or "`" or "" or whatever in their description, thus exploitable (masquerade as server messages or whatever); by the way, &k is particularly interesting looking } }