Client's sv_allowupload is now 0 by default

classic Classic list List threaded Threaded
4 messages Options
Reply | Threaded
Open this post in threaded view
|

Client's sv_allowupload is now 0 by default

Jonatan Matějka
Hi,
in thursdays update valve had set the cvar sv_allowupload default value to zero, on both server and client:
http://blog.counter-strike.net/index.php/2018/02/20051/
This means that if you host a server with custom files (maps, models, etc.), you need to setup a fastdl server (sv_downloadurl). If you don't have a fastdl server, no client will be able to join, unless he sets his allowupload back to 1.
Does anybody know why this has been done? The changelog implies a security issue, but I see no reason why a simple whitelist on the client side shouldn't do the trick, as this was always the case.
Or was this update aimed only at server side and the change on the client side was just a unintended side-effect?

I'd love to hear your opinion on this.
Thanks,
Jonatan

_______________________________________________
Csgo_servers mailing list
[hidden email]
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/csgo_servers
Reply | Threaded
Open this post in threaded view
|

Re: Client's sv_allowupload is now 0 by default

lay295
Why would this not let clients download files? It's not like sv_allowdownload
is 0

There was a thread on AM about someone being able to upload arbitrary .smx
files onto peoples servers giving them admin. This is probably in response
to that.



--
Sent from: http://csgo-servers.1073505.n5.nabble.com/

_______________________________________________
Csgo_servers mailing list
[hidden email]
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/csgo_servers
Reply | Threaded
Open this post in threaded view
|

Re: Client's sv_allowupload is now 0 by default

Asher Baker
On Sun, Feb 11, 2018 at 8:48 PM, lay295 <[hidden email]> wrote:
Why would this not let clients download files? It's not like sv_allowdownload is 0

 Because it was changed on the client as well as the server.

From the client's perspective, a download from the server is an upload to the client.
Therefore sv_allowupload controls downloads from the server, and sv_allowdownload controls uploads to the server.

_______________________________________________
Csgo_servers mailing list
[hidden email]
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/csgo_servers
Reply | Threaded
Open this post in threaded view
|

Re: Client's sv_allowupload is now 0 by default

lay295
Oh, I thought whether or not the client would be able to download files from
the server would be handled by cl_allowdownload, not sv_ one since it's
meant for server variables. As cl_allowdownload was still 1 thought it'd
work.

But I hope the value for clients get's changed back to 1, since this messes
up the custom sprays plugin my community uses as I can't send stuff to
clients mid game anymore :(



--
Sent from: http://csgo-servers.1073505.n5.nabble.com/

_______________________________________________
Csgo_servers mailing list
[hidden email]
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/csgo_servers