People and access
Members, clans, roles and every role permission, personal overrides, flags, bans, the lock, greetings and farewells, the audit log, and who bypasses it all.
Who may do what inside a protection is decided by its roles. Members and clans are given a role, anybody else is a visitor, and single members can be given overrides on top of their role. How the land itself behaves for everybody — PvP, fire, mobs — is a set of flags.
All of it is edited from the protection's screen: People holds members, roles and bans, Access holds flags, the lock and the greeting. See Menus.
How a player's rights are decided
For anything a player does inside a protection, the first rule that answers wins:
- A player with
exyliaprotections.bypassset for them may do everything. - While the protection is raidable, its enemies may do what
raids.raidable-permissionslists; while it is abandoned, so may everybody who is neither its owner nor a member. - The owner may do everything.
- Inside a plot: a plot member's own override, then their role in
the plot. A private plot refuses everybody else who lacks
manage-subregions. - A personal override for that player, allow or deny.
- The player's own role.
- The role given to their clan.
- The
visitorrole.
A player who is both a member and in a clan that was added uses their own role; the clan's role only counts for players without one. A tenant whose rent ran out counts as a visitor from that moment.
Members and clans
People → Members lists every member with their role and how many overrides they have, then every clan added.
| Click | What it does |
|---|---|
| Add player | Asks for a name. The player must have played on the network before. Then asks which role they get. |
| Add clan | Asks for a clan tag, then the role. Needs a clan plugin; without one, "There is no clan plugin on this server." |
| Left-click a member or clan | Changes their role. |
| Shift + left-click a member | Opens their overrides. Clans have none. |
| Right-click a member or clan | Removes them, with their overrides. A tenant cannot be removed while they rent. |
All of it needs manage-members. The role prompt only offers roles whose every permission the player
holds themselves: nobody but the owner hands out a permission they do not have. visitor is never
offered. With level upgrades on, each level caps how many members and
clans together a protection holds (upgrades.base-max-members, 8, before any upgrade).
A clan's role applies to every member of the clan, including players who join it later.
Roles
People → Roles lists every role with how many permissions it grants and how many members and
clans hold it, visitor last. It needs manage-roles.
| Click | What it does |
|---|---|
| Create role | Asks for a name and opens the new, empty role. |
| Left-click a role | Opens its permission switches. |
| Right-click a role | Renames it. Everybody holding it keeps it under the new name. |
| Shift + right-click a role | Deletes it after a confirmation. Everybody holding it — members, clans and plot members — stops being a member. |
A role name is up to 16 of a-z, 0-9, - and _, cannot be owner and cannot repeat another role.
visitor cannot be renamed or deleted.
New protections start with the roles section of config.yml:
roles:
member:
permissions: [break, place, containers, doors, redstone, buckets, animals, ride,
decorations, trade, leash, bank-deposit]
trusted:
permissions: [break, place, containers, doors, redstone, buckets, animals, ride,
decorations, trade, leash, manage-members, set-home, bank-deposit]
visitor:
permissions: []Flag keys written into a role are ignored. Each protection keeps its own copy of its roles: editing this section changes new protections only.
Rules that protect the protection
- Toggling a role's permission needs
manage-rolesand holding that permission yourself. - Nobody but the owner edits the role they hold themselves, or their own overrides, role or membership: "Only the owner can change your own access."
- The
visitorrole holds everybody who is not a member, so it can only be given the land permissions (breaktoleashbelow). Management permissions are refused for it, and never granted by it even if written into the file by hand. - Opening the protection's screen and teleporting home need membership. Deleting, picking up the core, selling, giving away, upgrading, merging and turning perks on are the owner's alone.
Role permissions
| Permission | What it allows | Offered while |
|---|---|---|
break | Break blocks, trample farmland, damage minecarts and boats, break blocks with a projectile | always |
place | Place blocks, edit signs, place boats, minecarts and armour stands, use spawn eggs, bone meal, flint and steel and fire charges, light fires, use clickable blocks that hold no inventory (crafting tables, anvils, beds…), let a portal form | always |
containers | Open anything with an inventory (chests, barrels, furnaces, shulkers, hoppers…), lecterns and taking their book, jukeboxes, chiseled bookshelves | always |
doors | Doors, trapdoors and fence gates | always |
redstone | Buttons, levers, repeaters, comparators, daylight detectors, note blocks, pressure plates and tripwires; arrows and thrown items on them count as the shooter | always |
buckets | Fill and empty buckets | always |
animals | Hurt, feed, interact with and shear animals and other non-hostile mobs, pull them with a fishing rod | always |
ride | Mount horses, boats and minecarts | always |
decorations | Place, break and use item frames, paintings and armour stands | always |
trade | Trade with villagers and wandering traders | always |
leash | Leash and unleash mobs | always |
manage-members | Add and remove members and clans, choose their role, set overrides | always |
manage-roles | Create, rename, delete and edit roles | always |
edit-flags | Change the flags | always |
rename | Rename the protection, edit its greeting and farewell | always |
set-home | Move the home to where they stand, inside the protection | always |
manage-core | Hide, show and move the core | always |
manage-bans | Ban and unban players | submodules.bans |
toggle-lock | Lock and unlock | submodules.lock |
view-logs | Read the audit log | submodules.logs |
bank-deposit, bank-withdraw | Use the bank | submodules.bank |
manage-subregions | Create, edit and delete plots | submodules.subregions |
manage-rent | Offer the land and its plots for rent | submodules.rent |
manage-warp | Publish and edit the public warp | submodules.warps |
edit-environment | Change the time and weather inside | submodules.environment |
"Offered while" is when the permission appears on role and override screens. A permission whose feature
is off is hidden, not removed: it comes back as it was when the feature is turned on. Hostile mobs are
never protected, and players attacking players are decided by the pvp flag, not by a permission.
Overrides
An override sets one permission for one member, ignoring their role. Each click on a permission in a member's override screen moves it through role (follow the role) → allow → deny → back to role. The members list shows how many overrides each member has.
Overrides need manage-members, and changing one needs holding that permission yourself. They exist for
players only, not for clans, and go when the member is removed. Plot members have overrides of their own
inside their plot, set from the plot's screen.
Flags
A flag is the land's own switch. It applies to everybody inside, members or not. Access → Flags
toggles them; it needs edit-flags.
| Flag | While it is off |
|---|---|
pvp | Players cannot hurt each other, with weapons, projectiles, harmful potions or clouds, or pull each other with a rod, when either of them stands in land with it off |
mob-spawning | No natural spawns: natural, jockeys, patrols, reinforcements, village invasions, raids, traps. Spawners, eggs and breeding still work |
explosions | Explosions break no blocks and no hanging decorations. Endermen, ravagers, withers, the dragon, zombies breaking doors and silverfish change no blocks either |
fire-spread | Fire does not spread or burn blocks, and nothing but flint and steel lights it |
liquid-flow | Water and lava do not flow |
crop-growth | Crops and plants do not grow |
leaf-decay | Leaves do not decay |
visitor-entry | Non-members cannot walk in: the protection is locked |
Some rules hold whatever the flags say:
- Liquids never flow into a protection from outside it.
- Pistons never move a block into, out of or across a protection other than their own.
- Hoppers and hopper minecarts outside a protection never pull from a container inside it, and dispensers outside never fire into it.
- Falling blocks never land in a protection other than the one they fell from, and projectiles nobody shot (from a dispenser outside, for instance) change no block inside.
- Mobs never trample farmland inside a protection.
A player lighting a fire needs place. settings.deny-message-cooldown-millis (1500) is how long a player
waits between two "This land is protected." messages.
Until every protection has been read from the database, worlds where land can be protected refuse building and interacting, and explosions, fire spread and liquid flow there, so a slow database never leaves land open. Only a player with the bypass acts during that time.
Bans
With submodules.bans, a player with manage-bans bans somebody from the protection. A banned player is
pushed just past the nearest border and cannot come back: walking, riding, ender pearls, chorus fruit,
commands, plugin teleports, spectating and portals into it are all stopped. Logging in or respawning
inside pushes them out again.
People → Bans lists the bans still running with their reason, who banned and the time left;
right-click one to lift it. Ban player asks two questions, then shows a summary before anything is
written: the player's name, then "How long, and why?". The answer is a duration followed by an optional
reason: 7d griefing, 2h, 30m spam, or permanent (also perm or forever) for a ban that never
ends.
The same from chat, standing in the protection:
/protections ban <player> [duration] [reason]
/protections unban <player>With no duration at all the ban is permanent; a reason needs a duration before it. A reason is plain text
of up to bans.reason-max-length (64) characters: colours and placeholders are removed.
These players cannot be banned: the owner, members (clan members included) and tenants — "is a member. Remove them first." — and, while online, anybody with the admin permission or the bypass.
A ban holds even while the protection is open to visitors. A raid or an abandonment opens the land to
everybody, whatever its bans and lock say. Turning submodules.bans off stops enforcing bans but keeps
them; they apply again when it is turned back on.
Lock
With submodules.lock, a player with toggle-lock locks the protection so only the owner, members,
tenants and plot members may enter. Locking is turning the visitor-entry flag off, from Access →
Lock or /protections lock standing inside. Visitors already inside are pushed out.
submodules.lock: false hides the lock button and refuses /protections lock, but visitor-entry stays
on the flags screen. Anybody with edit-flags can still lock the land from there.
Greetings and farewells
With submodules.enter-leave, walking into a protection shows a title and walking out shows an action
bar. A player with rename sets the protection's own lines from Access → Greeting & farewell:
| Click | What it does |
|---|---|
| Left-click | Asks for the greeting. |
| Right-click | Asks for the farewell. |
| Shift + right-click | Clears both, back to the defaults. |
Both are plain text, cut to enter-leave.message-max-length (64) characters. Without one of its own a
protection uses enter-default ("Owned by %owner%") and leave-default ("« You left %name%") from
messages.yml.
config.yml key | Default | What it does |
|---|---|---|
enter-leave.enter-sound | BLOCK_AMETHYST_BLOCK_CHIME|0.6|1.4 | Played walking in |
enter-leave.leave-sound | empty | Played walking out |
enter-leave.message-max-length | 64 | Longest greeting or farewell |
enter-leave.cooldown-millis | 1500 | Crossing a border again within it shows nothing, so walking along one stays quiet |
enter-leave.show-to-members | true | Off shows them to visitors only |
The titles themselves are the enter-leave section of messages.yml: enter-title (%name% over
%message%), enter-actionbar (empty), leave-title (empty) and leave-actionbar (%message%).
Placeholders: %name%, %owner% and %message%, which is the greeting or farewell. Stepping straight from
one protection into another only greets. Stepping into a plot shows enter-subregion in the action bar.
With ExyliaSurvivalCore installed, players can mute all of it with its protection-messages setting.
Audit log
With submodules.logs, every protection keeps a history. A player with view-logs opens it from
Defense → Logs or /protections logs standing inside. Left-click Filter by action cycles
through the actions, right-click clears it; left-click Filter by player asks for a name, right-click
clears it.
| Action | What is logged |
|---|---|
break | A block broken, with its type |
place | A block placed, with its type |
container | A container opened: chest, barrel, shulker, furnace, blast furnace, smoker, hopper, dispenser, dropper, brewing stand |
member | A member or clan added, removed or given another role, and override changes |
role | A role created, renamed, deleted, or one of its permissions toggled |
flag | A flag toggled |
ban | A ban or unban |
lock | Locked or unlocked |
core | The core hidden, shown or moved. Picking up and deleting are recorded too, but the log of a protection that no longer exists cannot be opened |
settings | Renamed, home moved, greeting or farewell changed |
raid | A life lost, the protection raided, a life bought back, lives set or a raid cleared by an admin |
bank | Deposits and withdrawals |
upkeep | Upkeep paid by a member |
market | Listed, unlisted, bought, given away (by the owner or an admin) |
subregion | Plots and their members, overrides and flags |
rent | Offered, offer cancelled, rented, renewed, tenant evicted |
upgrade | Upgraded, or level set by an admin |
warp | Published, unpublished, moved, renamed, described, icon changed |
merge | Another protection merged into this one |
break, place and container record only what actually happened; everything else is a change made
through a screen or a command. Each entry keeps who, what (up to 128 characters), where, on which server
and when.
| Key | Default | What it does |
|---|---|---|
logs.retention-days | 14 | Days an entry is kept. 0 keeps them forever. Old entries are purged every six hours. |
logs.flush-seconds | 10 | Seconds between two writes of the queued entries. |
logs.skip-actions | [] | Actions not logged. Everything else is, including actions added in later versions. |
logs.owner-blocks | false | Whether the owner's own break, place and container are logged. |
logs.menu-rows | 500 | How many of the newest entries the log screen reads. |
The log screen reads the newest logs.menu-rows entries and filters those. An older entry of a player is
not found by filtering for them. The player filter matches the exact name.
Bypass and admins
| Permission | What it does |
|---|---|
exyliaprotections.admin | Opens every protection's screens, enters every protection, cannot be banned while online, and counts as the owner in every menu and command. It does not let anybody break, place or use anything inside. |
exyliaprotections.bypass | Builds, opens and enters anywhere, ignoring every protection, even while protections are still loading. |
The bypass only counts when the permission is set for the player, by a permissions plugin or by
plugin.yml's default. That default gives both permissions to operators, so operators bypass every
protection. To make
an operator play by the rules, set exyliaprotections.bypass to false for them in your permissions
plugin. The old names exyliasurvivalcore.protections.admin and exyliasurvivalcore.protections.bypass
grant the same.
Something missing on this page? Tell us on Discord