FOnline Engine
Current master GitHub
Documentation Docs/en/reference/ai-control-protocol/security.md

AiControl Security Boundary

Generated reference. Do not edit directly. Update BuildTools/AiControlProtocol.json, then run python BuildTools/docs_ai_control_protocol.py --write.

Index Wire Methods Commands and events Security Integration and validation Canonical JSON Guide

Security rules

Stable ID Rule Requirement Why Source
ai-control-protocol.security.disabled-default Disabled by default An embedding project must require explicit configuration to start a listener. A control listener is a security-sensitive development feature. Examples/AiControlSample/README.md
ai-control-protocol.security.loopback-default Loopback first Listeners and clients default to 127.0.0.1 and refuse non-loopback operation without explicit operator opt-in. The protocol has no transport encryption or peer identity beyond a shared token. BuildTools/ai_control_client.py
ai-control-protocol.security.remote-token Remote token required A sample or project listener exposed beyond loopback requires a non-empty token in addition to explicit remote opt-in. An empty-token remote listener is an unauthenticated process-control channel. Examples/AiControlSample/ai_control_sample.py
ai-control-protocol.security.plaintext No TLS Treat the shared token and all payloads as plaintext on the TCP path; use an authenticated encrypted tunnel if non-loopback transport is unavoidable. Token authentication is not confidentiality or replay protection. Examples/AiControlSample/README.md
ai-control-protocol.security.secret-input Environment-backed token Reference tools read tokens from a named environment variable and do not accept or print raw token arguments. Command lines, process listings, shell history, and reports are common secret leak paths. BuildTools/ai_control_client.py
ai-control-protocol.security.shipping-build Compile out shipping surface Projects should compile the listener and remote-command path out of production clients, not merely disable them in a runtime config. Removing the socket and command path reduces attack and antivirus heuristic surface. Examples/AiControlSample/README.md
ai-control-protocol.security.server-authority Preserve server authority Project actions use normal client input or authenticated gameplay RPC paths; the bridge does not grant server authority or administrator capability by default. AI QA should exercise the same validation boundary as a player. Examples/AiControlSample/README.md
Start typing to search.