MLSAC b45: safer punishments
/mlsac punish no longer hits innocent players, punishments need evidence, forged responses are rejected.
Flag 13 on our test server: “Suppression (Flag 13, stage 1/1): cmd ban” and a ban with an animation.
AFK players getting kicked
Root cause found: /mlsac punish matched players by partial name, so if the cheater had logged off, the punishment landed on a random player with a similar name. The name must now match exactly.
Evidence check
If a player has no VL, no buffer and no detections, /mlsac punish refuses to run. For special cases there is /mlsac punish <name> confirm. Every call and every refusal is logged with the issuer's name.
Forged response protection
Model responses are validated: any probability outside 0–1 (NaN, Infinity and other garbage) is rejected. A forged response can no longer inflate the buffer into an instant kick.
Names with special characters
Names with spaces and special characters (Bedrock/Geyser) are no longer substituted into console commands — such a name could previously redirect a punishment to another player. These offenders are kicked directly through the API instead. In the Suspects menu, [console] and [player] actions are blocked for unsafe names.
File writes
CSV writes outside the plugin folder through a crafted name are closed off.
Punishment cooldown
The cooldown now also applies to raw commands (kick, ban, mute without a prefix) — no more kick storms on a burst of flags. These punishments are reported to the API too, so the dashboard history is fuller.
Minor
Cross-server alerts are sanitised, server-driven sequence updates are limited to a safe range, and the console warns if the backend is connected over http:// instead of https://.
