mojira.dev
MCPE-161129

/tellraw command can be run without cheats

The bug

You can use the /tellraw command without cheats. Although you can't evaluate selectors either in the command itself or the raw text object, you can still send messages to any user that look they they come from the game itself.

How to reproduce

Create and join a world without cheats enabled

Type

/tellraw <someone> {"rawtext":[{"text":"Β§eHerobrine joined the game"}]}

To be even more sneaky, use a translation key to send localized system messages like this:

/tellraw <someone> {"rawtext":[{"text":"Β§c"},{"translate":"storageSpaceWarningScreen.fullduringgameplay"}]}

Your victim will see this false message, without any indication that it's a complete fabrication sent by you:

[media]

Attachments

Comments 7

I have noticed Opped players can use the command in a world without cheats, but Members and Visitors can't. I honestly think this is good to have. However due to the trolling that can be done with it, it should be a toggle in player permissions.

Operators are always able to /tellraw without cheats enabled, it's been a thing for years.

I consider every restriction of Operator power to be a bug. For me the whole point is unrestricted power without having to resort to the server console.

Β 

I also don't see how cheats would have entered this conversation, it should be a discussion of where to draw the line of power for humans sending server messages, why would cheats enabled/disabled move that line?

operators being able to /tellraw is intentional, if members can't tellraw, that is also intended

Unable to reproduce in the latest version

I did reproduce through in Latest preview in Android.

Thank you for your report!
After consideration, the issue is being closed as Won't Fix.

Please note that this is not the same as Working as Intended, as this bug report correctly describes behavior in the game that might not be the intended or desirable behavior, but it will not be fixed right now. Sometimes, this is because the issue reported is minor and/or impossible to change without large architectural changes to the code base.

Quick Links:
πŸ““ Bug Tracker Guidelines – πŸ’¬ Community Support – πŸ“§ Mojang Support (Technical Issues) – πŸ“§ Microsoft Support (Account Issues)
πŸ““ Project Summary – ✍️ Feedback and Suggestions – πŸ“– Game Wiki

tryashtar

(Unassigned)

897696

Confirmed

Multiple

security

1.19.30.22 Preview, 1.19.20, 1.21.30.22 Preview

Retrieved