Jump to content

Recommended Posts

Posted

Hello, I bring you an item that allows the player to recover an item that fails in an enchant. It shows the last 10 items of the player that have failed with the enchants.

 

 

I would like if someone is encouraged to add a filter because now it shows them to all types of item and I think it would be better if they are separated by armor weapon and jewels

 

 code

 sql

 

config

#==========================================================================
#   BLACK COUPON RECOVERY 1 ITEM ENCHANT FAILED
#==========================================================================

BlackCouponId = 6392

 

 

preview

  • Like 1
Posted (edited)

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

Edited by melron
Posted
40 minutes ago, melron said:

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

@tensador3 this is a big issue. You could send the obj_id first of the item on the bypass instead of itemid and enchant value and also save the char_id of the person that broke the item in the sql table. Then see if obj_id and char_id exists in sql. Then return the provided item_id and enchant value.

Also, rework your try catch, I recommend using try with resources. 

Posted
42 minutes ago, melron said:

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

 

 

Excuse me, I'm not very good at this, would this be enough to prevent that from happening?

 

	private static void recoverSelectedItem(L2PcInstance player, int itemId, int enchantLevel)
	{
		// Comprueba si el jugador tiene suficientes items del ID 6392
		L2ItemInstance recoveryItem = player.getInventory().getItemByItemId(Config.BLACK_COUPON_ID);
		if (recoveryItem == null || recoveryItem.getCount() < 1)
		{
			player.sendMessage("No tienes suficientes items para recuperar este item.");
			return;
		}
		
		// Verifica el nivel de enchant del item recuperable en la base de datos
		if (!isValidEnchantLevel(itemId, enchantLevel, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item con ese nivel de enchant.");
			return;
		}
		
		// Verifica que el artículo que se está recuperando coincide con el artículo original
		if (!isValidRecoveryItem(itemId, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item.");
			return;
		}
		
		// Crea el item a recuperar con el ID y enchantLevel proporcionados
		L2ItemInstance recoveredItem = ItemTable.getInstance().createItem("RecoverItem", itemId, 1, player);
		recoveredItem.setEnchantLevel(enchantLevel);
		
		// Agrega el item recuperado al inventario del jugador
		player.getInventory().addItem("RecoverItem", recoveredItem, player, player);
		
		// Cobra 1 item del ID 6392
		player.getInventory().destroyItemByItemId("RecoveryCost", Config.BLACK_COUPON_ID, 1, player, player);
		
		// Elimina el item recuperado de la base de datos
		removeRecoverableItem(itemId, player.getObjectId());
		
		// Actualiza el inventario del jugador para que aparezca el item recuperado
		player.sendPacket(new ItemList(player, true));
		
		// Envía un mensaje al jugador con el nombre del item y su nivel de enchant
		String itemName = recoveredItem.getItemName();
		String message = "Has recuperado el item " + itemName;
		if (enchantLevel > 0)
		{
			message += " +" + enchantLevel;
		}
		player.sendMessage(message);
	}
	
	private static boolean isValidRecoveryItem(int itemId, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT item_id FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			return resultSet.next(); // Si hay un resultado, el artículo es válido
			
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el artículo recuperable de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false; // Si ocurre alguna excepción o no se encuentra el artículo, se considera inválido
	}
	
	private static boolean isValidEnchantLevel(int itemId, int enchantLevel, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT enchant_level FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			if (resultSet.next())
			{
				int validEnchantLevel = resultSet.getInt("enchant_level");
				return enchantLevel == validEnchantLevel;
			}
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el nivel de enchant válido de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false;
	}

 

Posted
2 hours ago, tensador3 said:

 

 

Excuse me, I'm not very good at this, would this be enough to prevent that from happening?

 

	private static void recoverSelectedItem(L2PcInstance player, int itemId, int enchantLevel)
	{
		// Comprueba si el jugador tiene suficientes items del ID 6392
		L2ItemInstance recoveryItem = player.getInventory().getItemByItemId(Config.BLACK_COUPON_ID);
		if (recoveryItem == null || recoveryItem.getCount() < 1)
		{
			player.sendMessage("No tienes suficientes items para recuperar este item.");
			return;
		}
		
		// Verifica el nivel de enchant del item recuperable en la base de datos
		if (!isValidEnchantLevel(itemId, enchantLevel, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item con ese nivel de enchant.");
			return;
		}
		
		// Verifica que el artículo que se está recuperando coincide con el artículo original
		if (!isValidRecoveryItem(itemId, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item.");
			return;
		}
		
		// Crea el item a recuperar con el ID y enchantLevel proporcionados
		L2ItemInstance recoveredItem = ItemTable.getInstance().createItem("RecoverItem", itemId, 1, player);
		recoveredItem.setEnchantLevel(enchantLevel);
		
		// Agrega el item recuperado al inventario del jugador
		player.getInventory().addItem("RecoverItem", recoveredItem, player, player);
		
		// Cobra 1 item del ID 6392
		player.getInventory().destroyItemByItemId("RecoveryCost", Config.BLACK_COUPON_ID, 1, player, player);
		
		// Elimina el item recuperado de la base de datos
		removeRecoverableItem(itemId, player.getObjectId());
		
		// Actualiza el inventario del jugador para que aparezca el item recuperado
		player.sendPacket(new ItemList(player, true));
		
		// Envía un mensaje al jugador con el nombre del item y su nivel de enchant
		String itemName = recoveredItem.getItemName();
		String message = "Has recuperado el item " + itemName;
		if (enchantLevel > 0)
		{
			message += " +" + enchantLevel;
		}
		player.sendMessage(message);
	}
	
	private static boolean isValidRecoveryItem(int itemId, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT item_id FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			return resultSet.next(); // Si hay un resultado, el artículo es válido
			
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el artículo recuperable de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false; // Si ocurre alguna excepción o no se encuentra el artículo, se considera inválido
	}
	
	private static boolean isValidEnchantLevel(int itemId, int enchantLevel, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT enchant_level FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			if (resultSet.next())
			{
				int validEnchantLevel = resultSet.getInt("enchant_level");
				return enchantLevel == validEnchantLevel;
			}
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el nivel de enchant válido de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false;
	}

 

 

From a security standpoint, I would say yes, it is a concern. However, from a broader perspective, it is not an ideal approach. The code you provided establishes three separate database connections for a single click, which is highly inefficient. It would be more advisable to implement a manager that can handle all the necessary tasks and hold the relevant data, rather than querying the database each time. This approach would greatly improve the efficiency and maintainability of the code.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • sql procedure missed and wrong...fixed it...ZOUMHS 
    • Hello Dexters! https://lineage2dex.com    This is pre-announcing of NEW season server, so we want to share some key points of it. Full details with road map, patch notes we will announce a bit latter Opening September 27 at 19:00 (UTC +3) Open Beta Test from September 23 What’s New This Season?, This is just a short preview of the most exciting changes and updates. A patch note with balance change will be posted later in this thread – one topic with all patchnotes history from 2022 year EXP/SP x25 - Over the past few seasons, our servers were drifting closer to a mid-rate style. And hard to call it now pure PVP server. That’s why we’ve reduced EXP/SP rates from x50 to x25 – making progression smoother, more balanced, and more in line with the mid-rate identity., Improved Olympiad matchmaking – opponents will be matched by strength, making feeding much harder., K/D stats for CC – track your real impact!, New In-Game Shop Interface - no more running to NPCs for supplies – buy everything directly from the interface. NPC Astarte will now only handle services like WH, sales, LS insertion, etc., Balance Adjustments - small but important tweaks for a smoother PvP experience (details in patch notes)., Replica Instance System Reworked - upgrading replicas now requires not only fragments but also real jewellery from B to S grades. You can choose from 3 instance types: PvP Instance – biggest rewards (everyone spawns together for mass PvP)., CC Instance – private instance for your CC., Party Instance – private instance for your party., , Dino Island Returns - back by popular demand: Dark Zone (PvP) and Light Zone (PvE)., Newbie Pass Questline - available at character creation – helps you get familiar with the server and make start progression faster., Clan members taxation system, Full announce - read on forum, https://forum.lineage2dex.com/threads/16723/ (edited)   We’re excited to show you how the Newbie Path will look on the Seasonal Server and share a few details about it. The Newbie Path is designed to help new players on Dex adapt more easily on project. While it won’t reveal the full content of the game, it will greatly assist during the early stages of your journey. But it’s not just for newcomers! Even veteran players will find it useful — completing Newbie Path steps will grant you small progression boosts and extra rewards(exp boosts, some gear, potions etc). Definitely worth using! You’ll be able to test the full Newbie Path system yourself during the Open Beta, launching on September 23rd!
    • 📢 [OFFICIAL ANNOUNCEMENT] 🔥 Lineage 2 Interlude x10 Craft-PvP 🔥 🎮 Grand Opening — September 19 @ 19:00 [UTC +2] 🧪 Open Beta — September 15 @ 19:00 [UTC +2]    🌐 Full server description - https://lineage2.ms/en/wiki 💥 Why Interlude x10 Craft-PvP? ✅ GM Shop up to B-Grade + Full Buffs — get straight to action, no pointless grinding. ✅ Unique Geodata & Geopathfinding Engine — smooth, tactical, and truly next-gen. ✅ Two Client Options — play in Classic or Interlude style. ✅ No Pay-to-Win — donations don’t break the balance. ✅ 1+1 Mode Enabled — max 2 windows, only 1 active = no box armies. ✅ Bot-Free Zone — advanced protection + non-intrusive popup captchas. ✅ No GM Interference — fair, competitive PvP environment. ✅ No Wipes — your progress is safe. ✅ Truly International — global reach, not just CIS players. 🛡 2nd Season. Stronger, Smarter, Updated. 🎯 Pure Craft-PvP. 🌍 Real Competition. 📅 Mark your calendars. Tell your clan. Invite your friends. Let’s make this season legendary. 💪 https://discord.gg/lineage2ms
    • As far as I know, L2Gold stated (unofficially) that closed for legal reasons. Although, my estimation is that it had reached such low popularity (believe me I know, I played till the last day), so they closed it because of that. As for "other" copies or w/e. I believe that everyone has the right to do what they think is best.  I have to say, I find your claims a bit exaggerating. Many servers have done a good job at recreating such a server. There are actually leaked files of C4 L2Gold (L2OFF) so many owners started working from there (L2Gold.cc (old Avellan), L2Gold.in, L2Gold.co etc.) There are other owners that took the idea 1 step further, adapting L2Gold in higher Chronicles and started working on a brand-new style with old features along. @Trance @Brado @To4kA (those are some of the owners that I can think of right now). I think you should re-think your opinions and don't judge them all together. Many of the servers you've mentioned has actually done a decent job and tried to take the brand, one step further. The argument here is that everyone should do what they want. Community will judge if it's good or bad.
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock