Skip to content

Take recent headwear off fighters who aren't in body armour - #77

Merged
XxFran10xX merged 1 commit into
mainfrom
feat/strip-recent-headwear-unarmoured
Oct 7, 2026
Merged

XxFran10xX merged 1 commit into
mainfrom
feat/strip-recent-headwear-unarmoured

Conversation

@XxFran10xX

Copy link
Copy Markdown
Contributor

What changes

Follow-up to #76. A helmet put on just before /pvp start stays on only for players who are still in body armour.

  • /pvp start first takes off any chestplate, leggings or boots put on within armour.recent-seconds (unchanged).
  • If the player is still in a real chestplate, leggings and boots, they keep their helmet, as in Let fighters in body armour keep their helmet free during /pvp start #76.
  • Anyone else also loses whatever they put on their head in that window. That covers helmets, masks, heads and carved pumpkins, which are everything tlibs counts as head-slot armour. They couldn't put it on during the fight anyway. Headwear worn for longer than the window stays.
  • The stripped message names a real helmet as "helmet" and anything else as "headwear". Removed items go back to the inventory, or drop at the player's feet if it's full, like the body pieces.
  • MaskService reads the helmet slot live, so taking a mask off ends the disguise at once.

Nothing changes during the fight: armoured players can still take their helmet off and on, and nobody else can put headwear on.

README and the pvp.yml comment are updated. There are no new config keys or messages.

Tests

  • New: ArmourDonningTest.recentHeadwearComesOffOnlyForThoseOutOfBodyArmour. It covers an armoured player keeping a recent helmet, an unarmoured player losing a recent head ("headwear"), an empty head slot, and older headwear staying on.
  • pvpStartTakesOffOnlyArmourPutOnRecently now expects the recent helmet to come off for an unarmoured player.
  • All 130 PvP tests pass locally, and ArmourDonning, PvpCommand and PvpSituation(s) have no missed lines.

🤖 Generated with Claude Code

/pvp start used to leave every helmet alone. Now only players still in a
chestplate, leggings and boots once recent armour is off keep a helmet put
on within armour.recent-seconds. Anyone else also loses whatever they put on
their head in that time: a helmet, mask, head or pumpkin, since they can't
put one on during the fight anyway. Older headwear stays.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 53712ed9-9f59-4006-9f61-27750c700218
📥 Commits

Reviewing files that changed from the base of the PR and between ca6d108 and 45e3dc2.

📒 Files selected for processing (4)
  • README.md
  • src/main/java/net/tfminecraft/rpcharacters/pvp/ArmourDonning.java
  • src/main/resources/pvp.yml
  • src/test/java/net/tfminecraft/rpcharacters/pvp/ArmourDonningTest.java

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 3 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • During /pvp start, recently equipped helmets and other headwear are now removed from participants who are not wearing a real chestplate, leggings and boots. This includes masks and player heads.
    • Participants wearing all three pieces of body armour keep their helmet and can remove and re-equip it during the fight.
    • Headwear worn for more than three minutes is unaffected. Removed headwear cannot be equipped again until the fight ends.

Walkthrough

/pvp start now removes recently equipped headwear from participants who do not wear real armour in all three body slots. The README, configuration comments, and tests describe this rule.

Changes

PvP headwear handling

Layer / File(s) Summary
Recent armour and headwear removal
src/main/java/net/tfminecraft/rpcharacters/pvp/ArmourDonning.java, src/test/java/net/tfminecraft/rpcharacters/pvp/ArmourDonningTest.java, src/main/resources/pvp.yml, README.md
takeOffRecent retains recent headwear when the player wears real armour in all three body slots. Otherwise, it removes headwear equipped within the recent-time window. Tests and descriptions cover these cases.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: drefvelin

Merge Risk: ⚪ Minimal · up to 45e3d

The change removes recently donned headwear from players without full body armour at PvP start. It is covered by tests and documentation updates, and no merge-blocking risk is evident.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 45e3d

The change is limited to nearby players’ recently equipped headwear. Normal removal preserves the item and respects the existing armour rules. However, a player with full storage can have their headwear forced into a world drop by another player, potentially allowing someone else to collect it.

Retained concerns

  • Medium · security · inferred: A normally permitted /pvp start can remove another nearby, incompletely armoured player’s recent headwear. When that player’s storage is full, the item enters a world drop without an assigned pickup owner. This extends the existing body-armour exposure to previously exempt headwear and can enable collection by others unless an external server control protects the drop.
Security review details

Security Blast Radius

  • observed — The reachable scope is online players in the initiating player’s world and configured start radius. Headwear removal additionally requires a recorded timestamp within the existing window and incomplete real body armour after recent body pieces are removed.

Security Findings and Attack Paths

  • inferred — A nearby player with the default PvP permission can trigger removal of qualifying headwear from a target whose storage is full. The resulting owner-unbound world drop creates a potential item-taking opportunity. Body armour already used this fallback; headwear exposure is the PR-specific expansion. External pickup protections may prevent collection but were not established.

Trust Boundaries and Controls

  • observed — The existing command grants initiators authority to affect radius-selected participants without a target-consent check. Recency and body-armour eligibility constrain removal, and the normal return path uses the affected player’s own storage. Only the full-storage fallback moves the item into shared world state.

Hardening Proposals

  • proposed — Preserve target ownership when forced equipment removal encounters full storage, for example through an owner-restricted drop or owner-bound recovery mechanism rather than an unrestricted world drop.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@XxFran10xX
XxFran10xX merged commit f176e7e into main Oct 7, 2026
2 checks passed
@XxFran10xX
XxFran10xX deleted the feat/strip-recent-headwear-unarmoured branch October 7, 2026 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant