Distributed rules that were difficult to audit
Different resources needed consistent permission checks, including for offline characters, without duplicating hierarchies and access rules.
I developed a centralized authorization system for FiveM, with permission hierarchies and inheritance, role-based rules, access expiration, auditing and selective caching. The system centralizes access decisions on the server and integrates with ACE.
Different resources needed consistent permission checks, including for offline characters, without duplicating hierarchies and access rules.
Bring groups, inheritance, direct permissions, job and gang assignments, expiration and auditing into a single service.
I designed the database, permission compiler, cache, ACE bridge, exports for other resources and the React administration panel.
The NUI requests operations, but the server revalidates administrative permissions, input and target before any mutation.
Only online players retain compiled permissions. Changes increment versions and recompile only affected characters.
The ACE bridge synchronizes principals at runtime, while the custom engine preserves inheritance, deny rules and traceability.
The original panel brings groups, users, direct permissions, jobs, gangs, diagnostics and auditing into a single FiveM administration interface.
The demo shows the original interface in Brazilian Portuguese.
From a panel action to the response returned to another resource, each layer has a defined responsibility. Select a layer to explore the details.
The panel brings together eight administrative areas for groups, users, assignments, diagnostics and auditing. The NUI uses a generic transport, but every operation is authorized and validated again on the server.