Jump to content

Recommended Posts

Posted

Hello, I bring you an item that allows the player to recover an item that fails in an enchant. It shows the last 10 items of the player that have failed with the enchants.

 

 

I would like if someone is encouraged to add a filter because now it shows them to all types of item and I think it would be better if they are separated by armor weapon and jewels

 

 code

 sql

 

config

#==========================================================================
#   BLACK COUPON RECOVERY 1 ITEM ENCHANT FAILED
#==========================================================================

BlackCouponId = 6392

 

 

preview

Posted (edited)

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

Edited by melron
Posted
40 minutes ago, melron said:

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

@tensador3 this is a big issue. You could send the obj_id first of the item on the bypass instead of itemid and enchant value and also save the char_id of the person that broke the item in the sql table. Then see if obj_id and char_id exists in sql. Then return the provided item_id and enchant value.

Also, rework your try catch, I recommend using try with resources. 

Posted
42 minutes ago, melron said:

You should consider to fix this code. I won't mention that it's coding style is before java 8, but I will mention the security issue of your bypasses. You can easily get any item with your desired enchant value

 

 

Excuse me, I'm not very good at this, would this be enough to prevent that from happening?

 

	private static void recoverSelectedItem(L2PcInstance player, int itemId, int enchantLevel)
	{
		// Comprueba si el jugador tiene suficientes items del ID 6392
		L2ItemInstance recoveryItem = player.getInventory().getItemByItemId(Config.BLACK_COUPON_ID);
		if (recoveryItem == null || recoveryItem.getCount() < 1)
		{
			player.sendMessage("No tienes suficientes items para recuperar este item.");
			return;
		}
		
		// Verifica el nivel de enchant del item recuperable en la base de datos
		if (!isValidEnchantLevel(itemId, enchantLevel, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item con ese nivel de enchant.");
			return;
		}
		
		// Verifica que el artículo que se está recuperando coincide con el artículo original
		if (!isValidRecoveryItem(itemId, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item.");
			return;
		}
		
		// Crea el item a recuperar con el ID y enchantLevel proporcionados
		L2ItemInstance recoveredItem = ItemTable.getInstance().createItem("RecoverItem", itemId, 1, player);
		recoveredItem.setEnchantLevel(enchantLevel);
		
		// Agrega el item recuperado al inventario del jugador
		player.getInventory().addItem("RecoverItem", recoveredItem, player, player);
		
		// Cobra 1 item del ID 6392
		player.getInventory().destroyItemByItemId("RecoveryCost", Config.BLACK_COUPON_ID, 1, player, player);
		
		// Elimina el item recuperado de la base de datos
		removeRecoverableItem(itemId, player.getObjectId());
		
		// Actualiza el inventario del jugador para que aparezca el item recuperado
		player.sendPacket(new ItemList(player, true));
		
		// Envía un mensaje al jugador con el nombre del item y su nivel de enchant
		String itemName = recoveredItem.getItemName();
		String message = "Has recuperado el item " + itemName;
		if (enchantLevel > 0)
		{
			message += " +" + enchantLevel;
		}
		player.sendMessage(message);
	}
	
	private static boolean isValidRecoveryItem(int itemId, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT item_id FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			return resultSet.next(); // Si hay un resultado, el artículo es válido
			
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el artículo recuperable de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false; // Si ocurre alguna excepción o no se encuentra el artículo, se considera inválido
	}
	
	private static boolean isValidEnchantLevel(int itemId, int enchantLevel, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT enchant_level FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			if (resultSet.next())
			{
				int validEnchantLevel = resultSet.getInt("enchant_level");
				return enchantLevel == validEnchantLevel;
			}
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el nivel de enchant válido de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false;
	}

 

Posted
2 hours ago, tensador3 said:

 

 

Excuse me, I'm not very good at this, would this be enough to prevent that from happening?

 

	private static void recoverSelectedItem(L2PcInstance player, int itemId, int enchantLevel)
	{
		// Comprueba si el jugador tiene suficientes items del ID 6392
		L2ItemInstance recoveryItem = player.getInventory().getItemByItemId(Config.BLACK_COUPON_ID);
		if (recoveryItem == null || recoveryItem.getCount() < 1)
		{
			player.sendMessage("No tienes suficientes items para recuperar este item.");
			return;
		}
		
		// Verifica el nivel de enchant del item recuperable en la base de datos
		if (!isValidEnchantLevel(itemId, enchantLevel, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item con ese nivel de enchant.");
			return;
		}
		
		// Verifica que el artículo que se está recuperando coincide con el artículo original
		if (!isValidRecoveryItem(itemId, player.getObjectId()))
		{
			player.sendMessage("No puedes recuperar este item.");
			return;
		}
		
		// Crea el item a recuperar con el ID y enchantLevel proporcionados
		L2ItemInstance recoveredItem = ItemTable.getInstance().createItem("RecoverItem", itemId, 1, player);
		recoveredItem.setEnchantLevel(enchantLevel);
		
		// Agrega el item recuperado al inventario del jugador
		player.getInventory().addItem("RecoverItem", recoveredItem, player, player);
		
		// Cobra 1 item del ID 6392
		player.getInventory().destroyItemByItemId("RecoveryCost", Config.BLACK_COUPON_ID, 1, player, player);
		
		// Elimina el item recuperado de la base de datos
		removeRecoverableItem(itemId, player.getObjectId());
		
		// Actualiza el inventario del jugador para que aparezca el item recuperado
		player.sendPacket(new ItemList(player, true));
		
		// Envía un mensaje al jugador con el nombre del item y su nivel de enchant
		String itemName = recoveredItem.getItemName();
		String message = "Has recuperado el item " + itemName;
		if (enchantLevel > 0)
		{
			message += " +" + enchantLevel;
		}
		player.sendMessage(message);
	}
	
	private static boolean isValidRecoveryItem(int itemId, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT item_id FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			return resultSet.next(); // Si hay un resultado, el artículo es válido
			
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el artículo recuperable de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false; // Si ocurre alguna excepción o no se encuentra el artículo, se considera inválido
	}
	
	private static boolean isValidEnchantLevel(int itemId, int enchantLevel, int objectId)
	{
		Connection con = null;
		PreparedStatement statement = null;
		ResultSet resultSet = null;
		
		try
		{
			con = L2DatabaseFactory.getInstance().getConnection();
			String sql = "SELECT enchant_level FROM item_recover WHERE object_id = ? AND item_id = ?";
			statement = con.prepareStatement(sql);
			statement.setInt(1, objectId);
			statement.setInt(2, itemId);
			resultSet = statement.executeQuery();
			
			if (resultSet.next())
			{
				int validEnchantLevel = resultSet.getInt("enchant_level");
				return enchantLevel == validEnchantLevel;
			}
		}
		catch (SQLException e)
		{
			// Manejo de excepciones en caso de error al obtener el nivel de enchant válido de la base de datos
			e.printStackTrace();
		}
		finally
		{
			try
			{
				if (resultSet != null)
				{
					resultSet.close();
				}
				if (statement != null)
				{
					statement.close();
				}
				if (con != null)
				{
					con.close();
				}
			}
			catch (SQLException e)
			{
				// Manejo de excepciones en caso de error al cerrar la conexión a la base de datos
				e.printStackTrace();
			}
		}
		
		return false;
	}

 

 

From a security standpoint, I would say yes, it is a concern. However, from a broader perspective, it is not an ideal approach. The code you provided establishes three separate database connections for a single click, which is highly inefficient. It would be more advisable to implement a manager that can handle all the necessary tasks and hold the relevant data, rather than querying the database each time. This approach would greatly improve the efficiency and maintainability of the code.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Very nice and passionate effort. Good luck.
    • SX.ORG is a global proxy platform offering residential, mobile and datacenter IPs for SEO, web scraping, ad verification and multi-account management. It provides flexible IP rotation, precise geo-targeting, HTTP(S)/SOCKS5 support, API access and pay-as-you-go pricing based only on the traffic you use.
    • L2-IMBA — SEASON 2  Custom PvP / PvE Interlude · Every Class Playable BETA — LIVE NOW GRAND START — 11 September 2026, 20:00 GMT+2 https://l2-imba.com · https://discord.com/invite/jmhVpj8ySv ═══════════════════════════════════════ RATES & CORE SETTINGS ═══════════════════════════════════════ Chronicle — Interlude XP / SP — x45, level-adjusted curve Adena — x1 Max level — 90 Subclass — 1, to level 80 Starting hub — Giran Skills — Auto-learn, post-80 via custom trainers Loot — Auto-loot with low-value filtering Buffs — Extended duration, expanded slots, saved schemes Client limit — NO DUAL-BOXING, one client per player Automation — Built-in auto-farm with daily time limit Offline — Trading and crafting enabled Current beta configuration. Final values confirmed at launch sign-off. ═══════════════════════════════════════ All 31 third classes are developed to level 90 through five specialized trainers — there are no dead classes here. Tanks, daggers, archers, warriors, summoners, healers, buffers and crafters all have real post-80 progression and a role worth playing. Full PvE progression through ten farm zones, thirty-five themed encounters and eighteen tracked raids, feeding into gear-equalized Team vs Team and open-world PvP. This isn't a stat patch with a new name. L2-IMBA keeps the combat, classes and world of Interlude and builds a new endgame on top of it — new equipment branches, custom class development past level 80, purpose-built farm ecosystems, boss progression, crafting, and augmentation, all connected into one progression loop. Level and develop your class → choose an armor identity → clear themed farm content → collect materials and boss resources → craft and upgrade without abandoning your build → compete in equalized and open-world PvP → reach God's equipment. ═══════════════════════════════════════ ROLE MASTERY ARMOR ═══════════════════════════════════════ Starting at Dynasty, armor becomes a real build choice instead of a mandatory set everyone wears. Each armor type offers three role masteries plus a flexible Universal path — twelve paths per tier, sixty full-set configurations across the progression. The chest piece selects your mastery; a matching five-piece set activates it. HEAVY   Juggernaut — frontline wall, shield synergy, reflection   Spellbreaker — anti-magic fortress, spell disruption   Slayer — heavy armor turned offensive, vampiric sustain LIGHT   Bowmaster — ranged pressure, kiting, accuracy   Assassin — positional burst, blow reliability, dagger lethals   Berserker — high-risk carry, power rises as HP falls ROBE   Arcanist — rapid-fire critical casting   Invoker — high-impact nuking and debuffs   Oracle — dedicated healing and support Upgrade recipes preserve your chosen path through every tier: Dynasty → Zariche → Valakas → Cursed → God's The system is gear-driven, not class-locked. Build creatively. ═══════════════════════════════════════ LEVEL 90 CLASS DEVELOPMENT ═══════════════════════════════════════ Max level extended to 90. Five specialized trainers — Archer, Tank, Rogue, Warrior, Mystic — cover all 31 third classes in post-80 progression, with 470+ learning entries. Every race gets a custom passive from level one. Tanks get distinct Human/Elf/Dark Elf identities. Duelist gains a two-handed greatsword path. Fortune Seeker becomes a real fighter without losing its spoil identity. Maestro gets a durable frontline route. Summoners, cubics and servitors get deeper combat logic rather than stat scaling. This is backed by server-side combat work — dedicated handling for debuff proficiency, PvE skill damage, blows, lethals, bow reuse, vampirism and reflection. ═══════════════════════════════════════ THE FARMING WORLD ═══════════════════════════════════════ Ten dedicated farm destinations via Global Gatekeeper: Farm Coins 1 & 2, Holy, Fire/Water, Wind, Earth, Unholy, Golden, Chaotic and Night zones. Seven themed enemy families — Undead, Demon, Angel, Beast, Bug, Water, Fire — each with four stages and a mini-boss. Thirty-five distinct encounters, each with its own resource identity feeding crafting. Eighteen tracked raids — twelve Farm Raid Bosses and six Custom Epic Raid Bosses. Plus a scheduled group-based Party Zone with dynamically managed normal and rare spawns. ═══════════════════════════════════════ CRAFTING & ENDGAME ═══════════════════════════════════════ SOUL FORGE — recycle old weapons into tier resources, convert boss and farm materials, craft Legendary components. Old gear becomes input, not warehouse clutter. CURATED AUGMENTATION — data-driven Top-Grade and Legendary profiles with meaningful stat, active and passive pools. Active effects are categorized so the same effect can't be stacked through equipment swapping. EXTENDED ENCHANT — Custom Crystal and Legendary stages. On the Legendary route, a failed enchant does not destroy the item or reduce its enchant level. Long-term progression, not an all-or-nothing gamble. TREASURE CHESTS — Rare, Immortal, Epic and Legendary tiers feeding gear growth, crafting and augmentation. ═══════════════════════════════════════ PvP ═══════════════════════════════════════ Gear-equalized Team vs Team on a recurring schedule — your equipment is snapshotted and restored, so the fight is about play, not who farmed longest. Open-world PvP with rewards and ranks alongside it. ═══════════════════════════════════════ QUALITY OF LIFE ═══════════════════════════════════════ - No dual-boxing — one client per player, enforced - Built-in auto-farm with a daily time limit — no third-party software needed, and third-party automation is bannable - Auto-learn skills, auto-loot with low-value drop filtering - Extended-duration buffs, expanded slots, saved schemes - Offline trading and crafting - Global Gatekeeper, global class change - Offline combat automation disabled ═══════════════════════════════════════ BY THE NUMBERS ═══════════════════════════════════════ 380+ custom item definitions · 110+ weapons and shields · 210+ armor and wearables · 250+ custom skill definitions · 2,700+ custom monster placements · 90+ shop and exchange catalogs · 1,100+ offers ═══════════════════════════════════════ BETA ═══════════════════════════════════════ Core systems, progression identities and content routes are in place. Exact item bonuses, mastery values, skill strength, reuse times, augment pools, enchant chances, drop rates and crafting costs remain subject to testing. Beta changes will refine balance without removing the defining role of each mastery or the overall progression structure. All beta characters are wiped at full launch. Beta testers keep their rewards. ═══════════════════════════════════════ OPEN BETA — 4 SEPTEMBER 2026 · 18:00 GMT+2 Website: https://l2-imba.com Wiki: https://l2-imba.com/wiki Register: https://l2-imba.com/account Download: https://l2-imba.com/start-playing Discord:  https://discord.com/invite/jmhVpj8ySv
    • 🛡️ 100% Safe on your personal Gmail. Zero VPN required and works globally. Grab yours directly on klouditem.com!
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..