Jump to content

Recovery System of an enchant item Failed L2JOrion


Recommended Posts

Hello, I bring you an item that allows the player to recover an item that fails in an enchant. It shows the last 10 items of the player that have failed with the enchants.

 

 

I would like if someone is encouraged to add a filter because now it shows them to all types of item and I think it would be better if they are separated by armor weapon and jewels

 

 code

 sql

 

config

#==========================================================================
#   BLACK COUPON RECOVERY 1 ITEM ENCHANT FAILED
#==========================================================================

BlackCouponId = 6392

 

 

preview

  • Like 1
Link to comment
Share on other sites

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

Edited by melron
Link to comment
Share on other sites

40 minutes ago, melron said:

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

@tensador3 this is a big issue. You could send the obj_id first of the item on the bypass instead of itemid and enchant value and also save the char_id of the person that broke the item in the sql table. Then see if obj_id and char_id exists in sql. Then return the provided item_id and enchant value.

Also, rework your try catch, I recommend using try with resources. 

Link to comment
Share on other sites

42 minutes ago, melron said:

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

 

 

Excuse me, I'm not very good at this, would this be enough to prevent that from happening?

 

	private static void recoverSelectedItem(L2PcInstance player, int itemId, int enchantLevel)
	{
		// Comprueba si el jugador tiene suficientes items del ID 6392
		L2ItemInstance recoveryItem = player.getInventory().getItemByItemId(Config.BLACK_COUPON_ID);
		if (recoveryItem == null || recoveryItem.getCount() < 1)
		{
			player.sendMessage("No tienes suficientes items para recuperar este item.");
			return;
		}
		
		// Verifica el nivel de enchant del item recuperable en la base de datos
		if (!isValidEnchantLevel(itemId, enchantLevel, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item con ese nivel de enchant.");
			return;
		}
		
		// Verifica que el artículo que se está recuperando coincide con el artículo original
		if (!isValidRecoveryItem(itemId, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item.");
			return;
		}
		
		// Crea el item a recuperar con el ID y enchantLevel proporcionados
		L2ItemInstance recoveredItem = ItemTable.getInstance().createItem("RecoverItem", itemId, 1, player);
		recoveredItem.setEnchantLevel(enchantLevel);
		
		// Agrega el item recuperado al inventario del jugador
		player.getInventory().addItem("RecoverItem", recoveredItem, player, player);
		
		// Cobra 1 item del ID 6392
		player.getInventory().destroyItemByItemId("RecoveryCost", Config.BLACK_COUPON_ID, 1, player, player);
		
		// Elimina el item recuperado de la base de datos
		removeRecoverableItem(itemId, player.getObjectId());
		
		// Actualiza el inventario del jugador para que aparezca el item recuperado
		player.sendPacket(new ItemList(player, true));
		
		// Envía un mensaje al jugador con el nombre del item y su nivel de enchant
		String itemName = recoveredItem.getItemName();
		String message = "Has recuperado el item " + itemName;
		if (enchantLevel > 0)
		{
			message += " +" + enchantLevel;
		}
		player.sendMessage(message);
	}
	
	private static boolean isValidRecoveryItem(int itemId, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT item_id FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			return resultSet.next(); // Si hay un resultado, el artículo es válido
			
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el artículo recuperable de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false; // Si ocurre alguna excepción o no se encuentra el artículo, se considera inválido
	}
	
	private static boolean isValidEnchantLevel(int itemId, int enchantLevel, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT enchant_level FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			if (resultSet.next())
			{
				int validEnchantLevel = resultSet.getInt("enchant_level");
				return enchantLevel == validEnchantLevel;
			}
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el nivel de enchant válido de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false;
	}

 

Link to comment
Share on other sites

2 hours ago, tensador3 said:

 

 

Excuse me, I'm not very good at this, would this be enough to prevent that from happening?

 

	private static void recoverSelectedItem(L2PcInstance player, int itemId, int enchantLevel)
	{
		// Comprueba si el jugador tiene suficientes items del ID 6392
		L2ItemInstance recoveryItem = player.getInventory().getItemByItemId(Config.BLACK_COUPON_ID);
		if (recoveryItem == null || recoveryItem.getCount() < 1)
		{
			player.sendMessage("No tienes suficientes items para recuperar este item.");
			return;
		}
		
		// Verifica el nivel de enchant del item recuperable en la base de datos
		if (!isValidEnchantLevel(itemId, enchantLevel, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item con ese nivel de enchant.");
			return;
		}
		
		// Verifica que el artículo que se está recuperando coincide con el artículo original
		if (!isValidRecoveryItem(itemId, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item.");
			return;
		}
		
		// Crea el item a recuperar con el ID y enchantLevel proporcionados
		L2ItemInstance recoveredItem = ItemTable.getInstance().createItem("RecoverItem", itemId, 1, player);
		recoveredItem.setEnchantLevel(enchantLevel);
		
		// Agrega el item recuperado al inventario del jugador
		player.getInventory().addItem("RecoverItem", recoveredItem, player, player);
		
		// Cobra 1 item del ID 6392
		player.getInventory().destroyItemByItemId("RecoveryCost", Config.BLACK_COUPON_ID, 1, player, player);
		
		// Elimina el item recuperado de la base de datos
		removeRecoverableItem(itemId, player.getObjectId());
		
		// Actualiza el inventario del jugador para que aparezca el item recuperado
		player.sendPacket(new ItemList(player, true));
		
		// Envía un mensaje al jugador con el nombre del item y su nivel de enchant
		String itemName = recoveredItem.getItemName();
		String message = "Has recuperado el item " + itemName;
		if (enchantLevel > 0)
		{
			message += " +" + enchantLevel;
		}
		player.sendMessage(message);
	}
	
	private static boolean isValidRecoveryItem(int itemId, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT item_id FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			return resultSet.next(); // Si hay un resultado, el artículo es válido
			
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el artículo recuperable de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false; // Si ocurre alguna excepción o no se encuentra el artículo, se considera inválido
	}
	
	private static boolean isValidEnchantLevel(int itemId, int enchantLevel, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT enchant_level FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			if (resultSet.next())
			{
				int validEnchantLevel = resultSet.getInt("enchant_level");
				return enchantLevel == validEnchantLevel;
			}
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el nivel de enchant válido de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false;
	}

 

 

From a security standpoint, I would say yes, it is a concern. However, from a broader perspective, it is not an ideal approach. The code you provided establishes three separate database connections for a single click, which is highly inefficient. It would be more advisable to implement a manager that can handle all the necessary tasks and hold the relevant data, rather than querying the database each time. This approach would greatly improve the efficiency and maintainability of the code.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • DISCORD : utchiha_market telegram : https://t.me/utchiha_market SELLIX STORE : https://utchihamkt.mysellix.io/ Join our server for more products : https://discord.gg/hood-services https://campsite.bio/utchihaamkt  
    • Server Rates: » Xp 500x. » Sp 500x. » Aden 500x. » Drop 1x. » PartyXp 2x. » PartySp 2x. » Starting character level -61. Enchant rates: » Safe enchant +4. » Blessed and simple scrolls max enchant (+16). » Crystal scrolls max enchant (+20). » Simple enchant scrolls chance – 65%. » Blessed enchant scrolls chance – 100%. » Crystal enchant scrolls chance – 50% Augmentations: » Mid life stone skill chance – 5%. » High life stone skill chance – 10%. » Top life stone skill chance – 20%. » Augments 1+1 Unique features: » Main town – Giran » Automatic-Manual Potions. » Working 2 castle sieges. (Giran-Aden) » SPS cancel lasts 10 seconds and than buffs come back. » Stackable scrolls, lifestones, book of giants. » Unique pvp zone » More then 11 active raid bosses. » Wedding system. » Unique farming areas. » Npc skill enchanter. » Full npc buffer with auto buff. » Max count of buffs – 55. » Max subclasses – 4. » Free and no quest class change. » Free and no quest sub class. » Raid boss drop nobless item. » No weight limit. » Unique protection anti-hwy armor for archers/daggers etc. » Ingame password change. » Top pvp/pk/online ranks NPC. » Unique monsters & NPC. » Interlude retail skills. » Server up-time [24/7] [99]%. » Perfect class balance (all class can kill all class depending on players skill and setup knowledge,gear,augmentations). » Announcements on double kills triple kills etc. » Announcements on Grand Boss death , with the name of the killer as well as clan name of the player. » Information Npc in game with all servers infromations. Custom server gear : 1). Titanium Armor Lv.1 2). Epic Armor Lv.2 3). Epic Weapons-Kamikaze-Black S grade (Same Stats) 4). Demonic-Angelic Wings-Baium Hair-Custom Accessories (SameStats) 5). Custom Fighter/Mage tattoo Lv1-Lv2-Lv3 6). Shirt (STR,CON,INT +1) 7). Custom Shields Server Commands: .tvtjoin .tvtleave – Join or leave tvt event. .ctfjoin .ctfleave – Join or leave ctf event. .dmjoin .dmleave – Join of leave dm event. .online – current online players count. .repair – repairs stuck character in world. .menu – opens online menu panel. .exit – PVP zone exit in case you are bullied. .changepassword - Opens online menu then u can change ur password in game. .farm - Enable/disable autofarm Event system: » TVT event » CTF event » DM event » Tournament Event » Party Zone » Unique event shop. Olympiad game: » Retail olympiad game. » Competition period [1] week. » Olympiad start time [18:00] end [00:00] GMT+2. » New Heroes every Sunday.
    • Tomorrow grand opening lests go 🙂 
  • Topics

×
×
  • Create New...