You are viewing a potentially older version of this package. View all versions.
redos7-SharePermissions-2.9.2 icon

SharePermissions

Share host permissions among trusted players

Date uploaded 3 weeks ago
Version 2.9.2
Download link redos7-SharePermissions-2.9.2.zip
Downloads 190
Dependency string redos7-SharePermissions-2.9.2

This mod requires the following mods to function

BepInEx-BepInExPack-5.4.2100 icon
BepInEx-BepInExPack

BepInEx pack for Mono Unity games. Preconfigured and ready to use.

Preferred version: 5.4.2100
nickklmao-MenuLib-2.5.4 icon
nickklmao-MenuLib

A library for creating UI!

Preferred version: 2.5.4

README

Screenshot

SharePermissions

The mod provides functionality to manage and share permissions (kick, ban, start game, return to lobby) among players who you trust. That's usually for community hosts who want to delegate moderation tasks to trusted members of their group.

Quick Start

  1. Install the mod — that's it, it is active right away (no codes to configure)
  2. Tell your trusted friends to install it too
  3. In the lobby there's a new button "Mod" next to the menu title — it opens the Members / History / Access / Settings / + panel
  4. As the host, click a friend in the Members tab and promote them to moderator

Becoming a moderator

The host clicks a player in the Members tab and promotes them. That issues the player a private access token — their moderator credential. It is presented automatically when they rejoin, so a promotion persists across sessions until the host revokes it (demote them in Members, or revoke the token in the Access tab — that works even while they are offline).

There is no shared secret code anymore: earlier versions could grant moderator to anyone whose SecretCode matched the host's, which meant a leaked or guessed code silently handed out moderation rights. Now every grant is an explicit host decision.

A moderator does not have to hold every power. The host opens Members, clicks the moderator, and turns individual permissions off — kick, ban, persistent ban, Admin Menu, notes (add and delete only), and run control (start the run, cancel the countdown, return to the lobby). A newly promoted moderator holds all six, so promoting someone behaves exactly as it always has; the switches are there to take powers away. Changes apply immediately, are recorded in History, and survive the moderator reconnecting. The Access tab shows a grant's permissions next to the token when they are restricted; a moderator who is offline is adjusted by revoking their access and promoting them again.

A moderator running a version of the mod from before permissions existed still has every action checked by the host — the host is where the decision is made — but their own screen will still show buttons for things they may no longer do, and those buttons will simply do nothing. Their Settings > Diagnostics shows what they actually hold.

What's included

  • Members tab: every player with their role, live talk indicator, and (for the host) promote / demote, and per-moderator permissions — seven switches (kick, ban, persistent ban, Admin Menu, notes (add and delete only), run control, 1-on-1 voice) deciding what that one moderator may do
  • History tab: searchable, filterable log of every moderation event, kept across sessions and synced to moderators
  • Access tab: the host's issued moderator tokens (revoke one to demote its holder, online or not), the tokens you hold from hosts that promoted you, and a Banned players section showing the host's BanEnforcer list — with a Lift ban action for anyone holding persistent ban
  • Settings tab: everything configurable in-game — no config-file editing needed after setup, plus a Diagnostics readout of live state (your version, whether your moderator token was accepted, the private channel's health, everyone's mod version) and a one-click dump of it to the log for bug reports
  • Voice channel tab (the microphone icon): the private voice channel's live controls (on/off, 1-on-1 rows, volume) — and, for a moderator holding the 1-on-1 voice permission, the rows to ask for one and to answer an invitation
  • Kick/Ban buttons on the lobby player list and the in-game escape menu, for the host and moderators
  • Name colors: the host picks nickname colors for themself, moderators, and individual players (Members > a player > Set name color) — shown to everyone running the mod in the lobby list, on the floating name above each player's head in-game, and on the escape menu's volume rows (toggle your own display of them in Settings)
  • Run-start countdown on the Start button — everyone sees it, host and moderators cancel it with one click
  • On-screen notifications of moderation events for the host and moderators, with an optional sound (Mod sounds on the Settings tab) that also marks players joining and leaving the private voice channel
  • RPC-flood protection: auto-kicks players spamming network messages (lobby only, moderators exempt)
  • Role head markers in the lobby and truck: crown (host), gem (moderator), diamond (mod user)
  • Private voice channel: the host can put themself and their moderators — the whole team, or 1-on-1 with a single moderator — on a voice channel nobody else can hear, and a moderator given the 1-on-1 voice permission can ask for one too; see Private voice channel below
  • LoadingWidget companion mod (optional, separate install): the moderation panel during loading screens — load states, who's talking, per-player local volume, kick/ban, stuck-load rescue
  • Player notes: the host and moderators keep shared notes about players, tied to Steam IDs, carried between lobbies by the moderation team and shown when a noted player joins.

Private voice channel

The host turns this on from the microphone tab of the moderation panel — for the whole moderator team with one button, or 1-on-1 with a single moderator by clicking that moderator's 1 on 1 row (the rest of the team hears nothing and gets no notification; the shared History still records that a private channel opened and closed, but never with whom). Clicking another name switches the pair, clicking the current partner stops it, and a 1-on-1 ends by itself if that moderator leaves or is demoted.

A moderator can ask for one, too, if the host has given them the 1-on-1 voice permission on the Members tab. Their microphone tab lists the host first, then the other moderators; picking one sends an invitation, and nothing happens until that person accepts. The invited side gets an on-screen prompt and answers from their own microphone tab, so it works mid-run without a hotkey and without a popup stealing the screen — and an unanswered invitation expires by itself after thirty seconds. Either side can hang up. A moderator can only start one while no channel is running at all: the host's channel always wins, and opening one drops a pair that was already talking.

Two moderators talking to each other is the one case where the host is not in the room. So the host is told when it starts and when it ends, and the shared History records both names — the rest of the moderator team is told nothing, exactly as it isn't told about the host's own 1-on-1s. An existing moderator does not gain this permission when you upgrade; you hand it out per person.

Once the channel is on, its members hear each other and nobody else — at full volume, anywhere on the map, through walls, across a whole level, even if one of you is dead. Everyone outside the channel simply stops hearing you, including players running no mods at all, and you stop hearing them. Talking in the channel doesn't attract monsters, and ordinary players still attract them exactly as before. Your ordinary microphone goes silent the instant you turn the mode on, so you can never be caught talking on the wrong channel by accident; the private channel itself takes a moment to connect, and the panel shows you when it's live. Switching off holds your microphone quiet for a moment longer too, so the tail end of a private sentence can't slip out into public chat.

While the private channel is on, an always-visible list in the corner of the screen shows who is in it: every member has a live volume bar that moves while they talk, a muted member shows up in red, and a member who never actually reached the channel shows up in grey — so you can see at a glance who is speaking, how loud, who can't answer you right now, and who isn't really there at all. Pick the corner — or turn the list off — on the Settings tab.

A short sound marks someone arriving on the channel and another marks them leaving (or the channel closing under you), so you don't have to be watching the corner to notice, and a third plays when the mod shows you a notification. They are the game's own menu sounds rather than anything new, so your existing volume settings already apply to them. Turn all three off with Mod sounds on the Settings tab.

That last one is worth its own sentence: being put on the channel and arriving on it are different things, and they used to look identical. A moderator whose client is too old to know the channel exists, or whose connection just failed, sat on the list looking like someone being quiet. Now they read as absent, on the corner list and on the host's 1 on 1 rows alike.

There is deliberately no separate mute for the channel: the game's own mute is the one mute, and it applies to the private channel exactly as it applies to ordinary voice chat. Press the game's mute key (B by default) and you are muted everywhere at once — and everyone in the channel sees your row turn red. Push-to-talk works too: releasing the key silences you in the channel like anywhere else, it just shows as an idle (empty) bar rather than red, because resting push-to-talk isn't a mute. What you hear is yours to control with the + tab's Private volume slider (0–300%), which also goes all the way to silence. Above 100% the boost is limited rather than clipped, so it makes speech louder without making it harsher.

The channel is also tuned to sound better than ordinary voice chat: it sends at a higher bitrate (64 kbps against the game's 30), and it lifts a quiet microphone further before sending (up to 20 dB against the game's 9 — the Mic lift slider under Private volume on the microphone tab, or the PrivateChannelMicGain config entry, if you want it different).

It comes with some honest limits, worth knowing before you rely on it:

  • It's a moderation convenience, not a secure channel. The channel's name is the only thing keeping it private — anyone who learns it can listen in.
  • Revocation is by re-keying, and it costs a reconnect. The channel is re-keyed when a moderator is demoted and when a member leaves the lobby, which is what stops either of them listening in afterwards — but Photon offers no way to actually evict someone from a room, so the re-key is the only lever there is. Everyone still on the channel reconnects when it happens (a second or two of dead air), and several people leaving at once are handled as one re-key rather than one each.
  • Text chat isn't part of the private channel. Whatever you type is still visible to the whole lobby, and it's still read aloud to everyone by their own text-to-speech, exactly as if the mode were off. Only your microphone is made private.
  • While it's on, other mods' "force microphone on" features stop working for you. The mod deliberately holds your ordinary microphone silent while the channel is active — that's what keeps your voice out of the public room.
  • A moderator running an older version of the mod never joins the channel. They stay on ordinary public voice chat instead. The corner list and the host's 1 on 1 rows show them in grey as not on the channel, so at least the rest of the team can see it — but nothing tells them they're missing it.
  • An outsider who hasn't finished loading yet (or is stuck as a ghost) can still be heard through chat. The mod only silences the text-to-speech readout of players whose in-game character actually exists, so a still-loading or ghost outsider's typed messages stay audible to channel members.

How it works under the hood

Moderator clients send requests to the host's client; the host verifies the request arrives over the live connection of someone it actually promoted (an unforgeable connection identity, authorized by the access token — never a claimed Steam ID) and performs the action itself. Nothing runs on other players' machines.

Integrations

  • BanEnforcer (Omniscye-BanEnforcer v4+, optional): if the host has it installed, the Kick/Ban popups and the Members panel offer Ban (persistent) - the ban is written to BanEnforcer's on-disk list, so it keeps working after restarts. Moderators can use it too; only the host needs BanEnforcer installed. The Access tab's Banned players section shows that list too, with Lift ban for anyone holding persistent ban - it's the host's own list, so a lift only affects that host, and without BanEnforcer on the host the section says so rather than showing an empty list.
  • R.E.P.O. Admin Menu (proferabg-RepoAdminMenu, optional): moderators can open the Admin Menu when the host runs it and has Settings > Admin menu > Grant to moderators on (the default). Unlike BanEnforcer, this one needs the mod on both machines - it draws its own local menu, so there is nothing to unlock on a moderator who does not have it. A moderator's actions are carried out by the host and recorded in History as Admin Menu events. Covers the whole menu - settings, upgrades, kill/heal/revive/crown/truck, teleport and summon, spawning items/valuables/enemies, and the map controls. Things spawn where the moderator stands, and Kick/Ban inside it obey SharePermissions' own rules (the host is never kickable; a moderator only by the host). Note that this hands moderators cheat powers over everyone in the room, the host included - the grant switch is the control.

Misc

In folders with config files there's a sharepermissions.log file that contains all performed actions with timestamps and player names.

The mod's own interface — the moderation panels, its toasts and its popups — can be shown in Russian; English stays the default. The setting is a button at the top of the Settings tab that cycles the language and names the current one in that language: Language: English, click, Язык: Русский. On first run the mod guesses once, from the game's own selected language and then your system language, and records that it guessed so it never overrides a choice you make afterwards — delete the LanguageAutoDetected line from the config file to have it guess again. This translates the mod, not R.E.P.O.: the game's own text is unaffected.

A few things worth stating plainly:

  • The button relabels itself the instant you click it, but the rest of the panel only picks up the new language the next time you open it. MenuLib panels have caused enough in-game-only surprises in this mod before that rebuilding one while it's open was ruled out; reopening it is the safe way to pick up the change.
  • History's stored records — and everything moderators exchange to keep History in sync — stay English in every language, on purpose. That is what keeps an entry comparable across a mixed-language moderation team and useful pasted into a bug report, which is also why the History tab's own titles and filters are translated while the record text underneath is not.
  • Diagnostics, its log dump, sharepermissions.log and the config file's own descriptions are deliberately left in English too. They exist to be read by whoever is troubleshooting a bug report, not translated for the player who filed it.

CHANGELOG

Changelog

2.23.0

Added

  • Timed bans. When the host runs BanEnforcer, a persistent ban can last 1 day, 7 days or 30 days, or stay permanent. The host lifts a ban that has run out by itself - at startup, when it opens a lobby, and once a minute while hosting - and History records it as a lifted ban whose reason is "Ban ran out". The Access tab's banned-players list shows when each timed ban ends. Moderators are offered the lengths only by a host on this version. Lifting a ban by hand cancels its end date, and a permanent ban of the same player replaces a timed one.
  • Ban a griefer who already left, from History. The host's History entry for a player has a red Ban next to Copy that persistently bans that entry's Steam ID. It appears only for someone who can be banned - not the host, a moderator or a protected player, not already banned, and not still in the room (their row's Ban does that) - and the confirmation shows the Steam ID and warns that it is what the player's game reported.
  • A moderator hears why the host refused a kick or ban. The player already left, is still loading, is protected, is a moderator, or a persistent ban would land on a shared Steam ID or on the host's or a moderator's - the moderator now gets a toast saying which, instead of nothing at all. Needs the host on this version.
  • Kicked and banned players are told. A player running the mod who is kicked or banned sees on the main menu whether they were kicked, banned, or banned from all of that host's lobbies, and whether the host or a moderator did it. The moderator is never named. Best effort: the game may drop the connection before the message arrives.
  • Last seen, on the Access tab. Each moderator you promoted shows when they were last seen ("today", "yesterday", "N days ago"), so access nobody uses any more stands out. It is recorded privately on your computer, never in the grant; grants from earlier versions read "unknown" until their holder next joins.
  • A missed 1-on-1 call leaves a notice. An invitation that runs out before you answer now shows "Missed 1-on-1 call from NAME", even with notifications off.
  • Diagnostics names the folder holding your private files (tokens, notes, History, sharepermissions.log), or says it could not be made and those files are in the config folder a profile export shares.

Changed

  • The lobby-head picker is grouped the way the README lists the heads - hats and headgear, things worn on the face, whole faces, eyes, things over the head - under small labels, with Clear and Default first and your current head marked "(current)" as well as colored.
  • No more stall when the head picker first opens. Its rows appear at once and the previews fill in over about a second. A lobby that first shows several animated heads spreads their loading over a few frames, and with Animate lobby heads off animated heads no longer load their animation art at all (nor do heads in the spectate list).
  • In the moderator permission switches and on the Access tab, Kick and Ban are named as permissions (nouns) in every language instead of the button verbs; in English they read "Kicking" and "Banning".
  • Mod popups and lobby rows do a little less work every frame.

Fixed

  • Setting a name color or lobby head once 64 players already had one did nothing, silently. Manage Member now says the list is full in place of Set, and a pick that no longer fits says so.
  • If the notes file could not be read at launch (held by a backup tool or antivirus, say), the next note or sync could replace every saved note. Changes now wait in memory and are merged in once the file reads. A corrupt notes file is kept under a dated backup name (the last five are kept) instead of replacing the previous backup.
  • If a token file could not be read, the grants issued, permissions changed and tokens received that session were lost at the next launch. The file is now retried every few seconds and those changes are saved once it reads; Diagnostics shows a "Private files" line while one is unreadable. A token save cut short (a full disk, a scanner) could be read back as fewer grants, or a restricted grant as a full one; token files now end with a marker, and a cut-short one is recovered from its complete copy or left untouched.
  • When the host leaves and another player becomes host, the moderator list is always cleared and the handshake with the new host always restarts, even if another reset step fails, and a moderator no longer keeps the old host's permission limits.
  • The private channel's corner list says "+1 more" in the singular in French, Italian and Portuguese.
  • The host's 1-on-1 notices no longer drop an English "Unknown" into a translated sentence.
  • 1-on-1 keys bound to Caps Lock, Scroll Lock, Num Lock, Pause, Break, SysRq, Menu, AltGr or Clear show their key-cap name in your language, not Unity's internal names.
  • Deleting LanguageAutoDetected to have the mod guess your language again can now switch to English, as the README always said.
  • On a host left running for days, a History event identical to one from an earlier day at the same second could be left out of saved History.
  • The History and forensic-log settings' descriptions now say those files live in the private folder under %LOCALAPPDATA%\SharePermissions, not next to the config.

Security

  • Promoting a player who claims the Steam ID of an offline moderator no longer deletes that moderator's access. A Steam ID is only what a player's game reports. When the player has not proved the saved grant, the host is warned first; if they go ahead, the saved grant is kept beside the new one, and demoting that player or revoking their access removes only their own.
  • A host pretending to be another host can no longer wipe out the token you hold for the real one by sending you a new token. The earlier token is kept as a fallback and proven automatically when the newest is not accepted; when the real host promotes you again, its new token wins.
  • The host limits how fast a moderator can drive the Admin Menu. Clicking at normal speed is never affected; a money or level slider dragged quickly, or settings toggled quickly, land on the last value a moment later instead of flooding the host.
  • Flood protection in the lobby now covers SharePermissions' own messages too. A player spamming them has them dropped above 100 a second and is removed at the same rate as an RPC flooder; normal traffic is far below either limit, and the host and moderators are exempt as before.
  • A private voice member can no longer make the host re-send the channel to everyone by flipping its connected state rapidly: at most once a second per member, always ending on the latest state.
  • Player names and the text a moderator sends are cleaned and shortened before they reach the host's log, so a name can no longer forge log lines or make the log grow by kilobytes, and a moderator repeating a refused kick or ban is logged once every few seconds with a count.

2.22.0

Added

  • Fifty-nine more lobby heads move: faces blink, and things fly. Confetti bursts out of the party hat, a butterfly flutters in and settles on the flower crown, a nut bonks off the hard hat, and a snowflake lands on the earmuffs just before they shiver. The cyclops, the alien, the zombie's good eye and the winking head's open eye blink now and then, the boxy head's eyes shut like shutters, the three-eyed head blinks one eye after another, the sleepy head dozes off, the panda blinks behind its patches and the angry head's eye twitches. A candle flickers inside the jack-o'-lantern, the monster's neck bolts spark, the pig snorts, the blush flushes, the arrow quivers, the 3D glasses glitch and the vampire's fang gleams. The propeller spins, rain falls from the rain cloud, the music notes rock to a beat, the witch hat and the shark fin sway, the sombrero dances, the cowboy hat tips, the jester's bells jingle, the traffic cone wobbles, the mushroom boings, the beanie's pom-pom bounces, the ushanka flaps its ear flaps, the mohawk bristles, the graduation cap's tassel swings and the bird on its nest pecks. The cat flicks an ear, a bunny ear flops over, the bear's ears flick, the owl blinks, a tear drips, the bandage throbs, the bandit mask's tails flap, the mustache wiggles, the unibrow goes up at one end and the alert flashes. Heart eyes beat, star eyes spin, pixel eyes blink, X eyes twirl, dollar eyes flip like coins, sparkly eyes flash and target eyes lock on, and the glasses, the goggles, the captain's badge, the viking's helmet, the knight's helm, the pharaoh's cobra and the astronaut's bubble catch the light now and then. As before, most heads hold still while their player talks, the list of dead players stays still, and Animate lobby heads in Settings > Interface turns it all off for you. Nothing new is sent over the network: wherever the host shows lobby heads, everyone running this version sees them move.

2.21.0

Security

  • Your moderator tokens no longer travel with a shared mod profile. They used to sit in the BepInEx config file, and exporting or sharing a profile (r2modman's or Gale's "Export profile", a modpack code) copies that whole folder - so anyone you shared a profile with got working moderator access to your lobbies, and a moderator's export shared the access they held. The tokens, your player notes, History and sharepermissions.log now live in their own folder, %LOCALAPPDATA%\SharePermissions\<profile>, which no export touches. Everything moves there by itself the first time you start this version; nobody has to be promoted again. If you shared a profile code while hosting before this update, revoke those grants on the Access tab and promote your moderators again.
  • Your notes only go where you go. A host you moderate for now receives only the notes you wrote yourself, not the notes other hosts' teams shared with you - and a modified host that merely claims you are its moderator can learn no more than that.
  • Notes can't be flooded away. A single moderator could once upload thousands of made-up notes that pushed every real note out of everyone's store. Now each moderator's uploads can add at most 500 new notes per lobby, notes arriving from others can't be dated more than a few minutes ahead, and nothing arriving from others ever pushes out a note you wrote.
  • History can't be made to lie about who did something. A very long nickname could push the real "by …" off the end of a History line, so a kick or ban read as someone else's - another moderator's, or the host's. Every name in History is now cleaned and shortened before the line is written, so the real attribution always survives. The persistent-ban reason stored in BanEnforcer's list gets the same cleaning.
  • Moderators can't persistently ban the host or another moderator by the back door. Every Steam ID a client reports is its own claim, so a moderator with a second copy of the game could have it pose as an absent player and persistently ban that player's Steam ID. A moderator's persistent ban is now refused for the host's own Steam ID and for anyone the host has made a moderator, online or not. The host's own bans are unchanged.

2.20.0

Added

  • Moderators can pick their own lobby head. A moderator picks it once on their Settings tab (Lobby heads > Your head), and it is saved on their computer and worn in every lobby they moderate. A head the host sets for that player on the Members tab still wins, and a moderator who is demoted stops wearing it. The host's Manage Member page shows a moderator's own pick. Needs the moderator and the host on this version.
  • The Mod button for every player running the mod. Every player running the mod now gets the Mod button in multiplayer lobbies and the escape menu. For a player who is not a moderator it opens Settings (language, display switches, notifications) and, when the host runs this version, the microphone tab for 1-on-1 calls.
  • 1-on-1 calls with players who are not moderators. From the microphone tab they can call the host or a moderator, who answers on the usual prompt. The host can turn this off in Settings > 1-on-1 calls > Players may call the team (on by default); a call already running carries on. The host puts a player on a 1-on-1 straight from the microphone tab, as with a moderator, and a moderator with the 1-on-1 voice permission invites one. Two players cannot call each other. Needs the host and the player on this version; players on older versions are never offered.
  • The host and moderator name colors can be reset to their defaults from their picker. (#59)
  • When the host has set a head for a moderator, their Settings tab says so under Your head, since that head is shown instead of their own pick. (#57)
  • Some lobby heads move. The halo floats and now and then catches the light, the antenna and the sprout sway, the question mark rocks, the dizzy stars wobble, the flames flicker, the light bulb buzzes and the clown nose gets a honk. The visor scans while nobody is talking, googly eyes wobble when they look around, and spiral eyes spin. The unicorn horn, the wizard's star and the sunglasses twinkle now and then. Most heads hold still while their player talks (googly eyes still wobble), the list of dead players stays still, and the head picker shows every head still. Turn it off for yourself with Animate lobby heads in Settings > Interface. Nothing is sent over the network, so it works whatever version of the mod the host runs: wherever the host shows lobby heads, everyone running this version sees them move.

Changed

  • The Access tab shows what each moderator may do. Every moderator you have promoted is listed with all seven permissions under their name, the ones they lack dimmed and struck through, in your language. Click one to open their page: change their permissions there even while they are offline (the change reaches them when they next join), or revoke their access. Revoking now goes through their page instead of opening straight from the row.
  • Players who are still joining show as [LOADING], not [GHOST]. A row in the lobby list turns into a gold [GHOST] only when the player has not arrived after 60 seconds, has an avatar without a valid Steam ID for 10 seconds, or loses their avatar. The Members tab says "loading" or "ghost" the same way (it used to say "connecting"), both tags are now translated, and the Settings toggle that hides these rows is now called Loading and ghost rows.
  • Only the host can kick a player who is still loading. Once a moderator's own game has loaded, they no longer get a Kick for a player who is still joining or loading in the lobby list or the escape menu, and the Admin Menu's Kick does nothing for that player. While the moderator's own game is loading during a level change, the Kick on the loading screen (LoadingWidget) stays available, as before. The host refuses a moderator's kick of a player it still sees loading, older moderator clients included, unless the host's own level is changing at that moment. Once the player turns into a ghost, moderators can kick them again. This also keeps a protected player safe from moderators while they are still joining, and in the second after they arrive, before the host has matched them to their Steam ID. After a level change the host allows for a moderator whose game finished loading first: once a player who never arrived turns into a ghost for that moderator, the host takes their kick even if its own game finished loading up to 30 seconds later. A moderator's automatic flood report waits the same way: it is sent once the flooding player has finished loading or turned into a ghost, and if the host still turns it down, it is sent again every 10 seconds while the flood goes on.
  • Ban (persistent) is refused when two players claim the same Steam ID. When more than one player in the room reports the same Steam ID, a persistent ban could land on the wrong person, so it is refused for the host and for moderators, and the host sees a message saying why. Kick and plain Ban still work; kick the other player first if you want the persistent ban.
  • The host now accepts at most one start or back-to-lobby command per second from each moderator, so a moderator (or a leaked token) repeating them can no longer flood History and everyone's toasts. Cancelling a countdown is never held back, so a moderator can always stop a start they just made, even with a one-second countdown, and a start the host turned down (for example while a player was joining) does not make the next try wait.
  • The ON/OFF switches and the units on the Settings and voice-tab sliders (s, min, /s, KB, dB) now follow the chosen language.
  • The voice tab's microphone icon is redrawn with smooth edges and now looks like a microphone. It also shrinks along with the tab names when a language's names are too long for the row.
  • An invitation nobody answers, or that the caller withdraws, now counts as a decline: for 30 seconds the same caller cannot invite the same person again, and is told that person did not answer.
  • A moderator demoted during a 1-on-1 stays in the call when they run this version: a call now ends on a demotion only when neither side is the host or a moderator any more. The host can still end it.
  • When a 1-on-1 ends, the other person is now told why (hung up, left, ended by the host, or the host left), and the host is told when the person it was talking to leaves. When an invitation is withdrawn, the person invited is told; "Request cancelled" now means only that you cancelled, and a request to someone who left says so.
  • The time limits in Settings > 1-on-1 calls now also cover calls a player starts.
  • The host's microphone tab lists up to 20 people for a 1-on-1 (it was 8), names the two people in a 1-on-1 it is not in, and ends its own 1-on-1 with Hang up: NAME. Its Start private channel: all moderators is greyed out while no moderator is in the lobby, and a team channel left with only the host says so. A moderator on the all-moderators channel is told that only the host can close it. The microphone tab colours a caller as the on-screen prompt does, and shows "muted" in red.
  • The corner list is titled "Private channel", like the tab. A muted member's meter turns into a crossed-out microphone and a member who never reached the channel shows a grey name in italics, so the states differ by shape as well as colour; "+N more" appears when the channel has more members than the list has rows; and its title, countdown and hang-up line get the same dark backing as its rows.
  • Ban (persistent) asks first. Choosing it in the Player Actions popup now opens a Yes/No confirmation that names the player, for every player. On a moderator, that one confirmation also says they are a moderator. (#44)
  • Very dark name colors stay readable. A name color darker than the lobby name color's floor is lightened where names are shown (the lobby and spectate lists, the name above a player's head, the escape menu), the same way as the lobby name color. The Settings rows and the color picker draw the value in the color players will see. The host's pick itself is kept. (#21)
  • The Name colors hint on the Settings tab now says the colors apply to names only: role labels on the Members tab and the head markers keep their own colors. (#23)
  • One crown at a time. The host's crown head marker hides while the host wears the game's Arena Crown, and comes back when the crown moves on. (#24)
  • Re-promoting a moderator who still has a saved grant keeps the permissions you had switched off. Revoke their access first to start again with all seven. (#56)
  • Turning Show notifications off no longer hides answers to your own actions. A declined or unanswered 1-on-1, a kick, ban or note that could not go through, and the 30-second warning and end of a 1-on-1 you are in still show. The moderation feed, the notes reminder and your role changes stay off. (#31)
  • With the corner list (the private channel's member list) set to the Bottom left corner, it now sits just above the notifications and the 1-on-1 invite prompt instead of underneath them. (#30)
  • History rows now say what happened in Admin Menu and 1-on-1 entries. An Admin Menu row names the action (for example "Admin Menu: Kill - by NAME"), and a 1-on-1 row names both players, with Caller and With lines in its details. (#33)
  • History's filter skips "Mute" unless your History holds a record from the old global mute, and kick/ban protection changes are listed under "Kicks & bans" instead of "Info". (#60)
  • Moderators no longer get a "private voice channel key rotated" notification and sound each time someone leaves the team channel or is demoted; History still records it. (#46)
  • The notes page says how to delete a note, and a moderator without the Notes permission is told why they cannot add one. Add note now always says whether the note was added, shortened or refused. (#11)
  • On the Access tab, a moderator who cannot lift bans sees the Banned players rows dimmed, and the note about the persistent-ban permission shows only to them. (#43)
  • A moderator's Settings tab no longer lists flood-protection numbers. They were the moderator's own settings, not the host's, which are not shared. (#41)
  • The 1-on-1 answer and hang-up keys moved to Settings > 1-on-1 calls. While a key row waits for a key, Backspace switches that key off, and a key that another row or the game already uses is refused with a message on the row, instead of nothing happening. (#28)
  • The Settings switches that hide name colors, lobby heads and notifications on your own screen are now called Show name colors, Show lobby heads and Show notifications. A line under Interface says these switches change only what you see. (#37)
  • Keys are named the way the key caps read, in your language: 1 instead of Alpha1, Num 1 for the number pad, and End, Home, Del, Ins, PgUp/PgDn, Enter, the Shift, Ctrl, Alt and Windows keys, and the arrows. (#38)
  • The buttons on the Manage Member page and in the Player Actions popup use the same text size as the rest of the page. (#14)

Fixed

  • A moderator's plain Ban no longer becomes a permanent ban. With BanEnforcer on the host, a moderator's Ban on a player who had a character was also saved to the host's permanent ban list, under a Steam ID BanEnforcer picked for itself, even for a moderator who was not allowed persistent bans. Now only Ban (persistent) writes to that list, from the host or a moderator.
  • A moderator's Kick or Ban hits the player they clicked. A player who copied someone else's Steam ID could get the real owner kicked or banned instead. If that owner was a moderator or protected, the copier could not be kicked by moderators at all. The Admin Menu's kill, heal, revive, crown, truck, teleport and summon could land on the same wrong player. Needs the moderator and the host on this version.
  • Kicking someone who already left no longer writes History. If the player left while the host's Kick/Ban popup was open, History still recorded a kick or ban that never happened. The host now gets a short message instead.
  • A protected player written with leading zeros is now protected. A Steam ID typed into the ProtectedPlayers setting as "0076..." was kept but never matched the player. It is now read as the ID it spells.
  • The host can demote a moderator who claims the host's own Steam ID. Demote used to do nothing on such a player.
  • The moderators' ban list no longer mixes two syncs. When the end of a ban-list sync was lost, the next sync was added on top of it, and the Access tab showed a mixed list with duplicates. When a sync stalls for more than two seconds partway, the Access tab now says the list couldn't be shown in full, instead of presenting what arrived as the full list or as the most recent bans; reopen the tab to fetch it again.
  • A joining player can no longer set their identity before they have loaded. The mod read a Steam ID from a player property that neither the game nor the mod ever writes, so only a modified client could fill it in, and it counted before the player had even arrived. It is no longer read.
  • Moderators can no longer delete other people's notes through the notes sync. A deletion that a moderator's game sent along with its notes was applied, and passed to every other moderator, without checking who wrote the note, so a modified client could wipe the team's notes. A flood of made-up deletions could also make notes that had really been deleted come back. The host now accepts such a deletion only from the note's author, and limits how many deletions one moderator can send this way in each lobby, even if they leave and rejoin. A host can still delete any note in their own lobby. That deletion reaches their own moderators, but it no longer spreads to other lobbies whose host has the note.
  • Notes stay with moderators. A player who is not a moderator in the current lobby no longer accepts notes or deletions from the host, and no longer sends their own notes. This holds even if a modified host asks, and even if they were a moderator somewhere else before.
  • Your notes file is saved safely. A crash or a full disk while notes were being saved could leave a damaged file, and all your notes were lost on the next start. Saves now replace the file only once the new copy is complete. If a save fails, for example because another program has the file open, it is tried again, and the finished copy is kept for the next start instead of being thrown away. Notes arriving from the host are also saved once the sync finishes, instead of rewriting the file hundreds of times during one sync.
  • A full notes list no longer loses newer notes to older ones. With the list at its 2000-note limit, a very old note arriving from someone else pushed out a newer one. It is now skipped instead. Notes about an invalid player, which could never be shown or deleted, are now ignored.
  • A moderator's full notes upload is no longer cut short. A moderator with a lot of notes had the end of their upload, which is where their deletions are, dropped by the host every session.
  • History keeps a lobby's events after you leave it. Leaving a lobby used to hide its events from History until you restarted the game. In a long session, anything past the 100 most recent events also disappeared. Both now stay listed, dated like past sessions. With Keep history across sessions off, History still shows only the current lobby.
  • Trimming the saved History when the game starts can no longer delete the whole file if another program has it open at that moment.
  • A key change during a level load no longer splits the private channel. If a member left while the host's level was loading, the host moved to a new private room but nobody else was told. The channel stayed split, and the others still listed the player who had left, until someone joined or the host turned the channel off and on. Everyone now follows the host as soon as its level has loaded.
  • A 1-on-1 that ends during a level load now ends for both people. If the call ended while the host's level was loading, because the other person left or it was hung up, the person still in it was left in an empty call, unable to talk to or hear anyone else. They are now let out as soon as the host's level has loaded, and pressing Hang up also gets them out.
  • 1-on-1 answers are no longer lost during a level load. Some messages the host owed you while its level was loading used to vanish: "declined", "no answer", "request cancelled" when the other person left, or an invite being withdrawn. That left a "Waiting for..." line or an invite prompt that could no longer do anything. These messages now arrive once the host's level has loaded, and an invite delivered that way shows only the time it has left.
  • The private channel's corner list keeps up after a level load. A member who joined or dropped out of the private room while their game was loading could keep showing the wrong state (connected when they were not, or the other way round) until it changed again.
  • The corner list no longer shows names from your last lobby. The first private channel in a new lobby could label its members with the names of players from the previous lobby.
  • Fewer reconnects in the private channel. When a member left within a couple of seconds of another key change, such as a demotion, everyone in the channel had to reconnect twice. They now reconnect once.
  • Typing in a menu text field no longer answers an invite or ends your call. Typing a Y or an N into the Members tab's note, the History search or a color's hex code with an invite on screen answered the invite, and typing your hang-up key into one of them ended your 1-on-1. The 1-on-1 keys now do nothing while you are typing in a menu text field, just as they already did in the game's chat.
  • If the host's private voice channel hits an internal error, the members are now told it closed. Before, they stayed muted to everyone else and deaf to the room, and removing a moderator afterwards did not cut them off.
  • On the Settings tab's 1-on-1 key rows, pressing Esc to cancel a binding no longer closes the whole Moderation panel as well, and clicking a second row while another was waiting for a key no longer leaves the first one stuck on "Press a key...".
  • A player whose name is made entirely of invisible characters is now listed, and can be kicked, once they become a ghost; before, they never got a row at all.
  • When a host deletes a moderator token from the config while the game is running, a moderator still using it now loses moderator access at once, as if it had been revoked from the Access tab, instead of keeping it until they leave.
  • The in-game config editor REPOConfig no longer shows your moderator tokens (PromotedTokens and MyModeratorTokens), so they can't leak on a stream or screenshot.
  • Turning the host's "Grant to moderators" (Admin Menu) on or off now reaches moderators who are already in the lobby straight away, instead of only after the next player joins.
  • A moderator pressing Start while a player is joining, outside the lobby or during a running countdown, or Back to Lobby from a menu, no longer adds a History entry and a toast for something the host never did.
  • When a moderator cancels the run-start countdown, History now records their Steam ID and files the entry under that moderator, so a moderator named "host" can no longer look like the host. Entries written by older versions still show as before.
  • Toasts still waiting to appear when you switch language now show in the new language, and the toast shown when the host revokes an unnamed moderator token is now translated like the other moderation toasts.
  • Long names in the Members tab no longer break an emoji in half when they are shortened.
  • The arrow buttons on the mod's sliders now stop at the ends of their range instead of wrapping around. "<" on a 0% private volume no longer jumps to 300%, and the host's flood limits can no longer jump from one end of their range to the other in a single click.
  • The Diagnostics button now says the lines went to the BepInEx log, which is where they are written. It used to name sharepermissions.log.
  • Editing your own name colors or lobby heads outside the panel (with a config manager or a config reload) while in someone else's lobby no longer replaces that host's colors and heads with yours for the rest of the session. Your edit takes effect when you leave or become the host.
  • Opening the lobby-head picker for the first time no longer creates a large burst of throwaway memory, so the stutter is shorter. The hats' heights now ship with the mod instead of being measured from each picture as it loads; the heads look exactly the same.
  • After a 1-on-1 you asked for connects, the microphone tab no longer keeps showing "Waiting for NAME" and Cancel, and you can call again as soon as it ends; a host who answers a request by clicking the caller's row no longer leaves the caller told "No answer" in the middle of the call.
  • A 1-on-1 request no longer waits in silence: a click too soon after the last one, or during a level load, says to try again; a request the host never answers says so; and accepting a call that can no longer start says the channel is busy. Accept, Decline, Cancel and the hang-up key pressed during a level load say to try again instead of doing nothing.
  • Hang up and the hang-up key end your 1-on-1 even while an invitation you sent someone else is still waiting; they used to withdraw that invitation and leave the call running. Cancel still withdraws it.
  • Russian microphone-tab captions, and long names with "(not on the channel)", no longer run past the row; a long name is shortened and the mark always shows whole.
  • The host's Admin Menu Ban is no longer permanent. With BanEnforcer installed, the host's Ban Player in the Admin Menu was saved to the permanent ban list, and neither its Kick nor its Ban showed in History. Both now work like Kick and Ban in the player popup: they are recorded in History, and a Ban lasts for the session. Only Ban (persistent) writes the permanent list. (#5)
  • History now updates while the panel is open. Protecting a player, promoting or demoting, revoking access, and events synced from the host show up in History and in its tab count straight away, instead of after closing and reopening the panel. (#4)
  • The notes reminder ("NAME joined - notes (N)") now appears when a player you have notes on joins the room after you, once. It never showed before, because the player's Steam ID was not known yet when it checked. (#6)
  • The Access tab's "Show all N bans" works on a moderator's first look in a room: it used to do nothing and then claim ten rows while eight showed. The collapsed list always shows the last ten. (#7)
  • A player whose name shows no visible characters is now listed on the Members tab once they have arrived, as "Player_N", so they can be managed. (#8)
  • Long Chinese, Japanese and Korean names no longer push the role, loading, ghost or protected badge off the Members and Access rows. (#13)
  • History rows are cut to fit the row in every language, ending in "…" instead of being sliced at the edge in Russian, and English rows keep more of the player's name. (#16)
  • The Members tab says how many players it could not list when there are more than 20. (#32)
  • The Manage Member page of a player who is still loading no longer says "No mod"; it shows "loading" or "ghost" and asks you to reopen it once they arrive. The Members tab's "loading" badge now matches the lobby's [LOADING] color. (#42, #61)
  • The Manage Member page notices when its player leaves: it says so, and a Promote or permission change made after that is refused with a message instead of silently doing nothing. (#55)
  • Bans made through the mod now show who made them (by Host, or by the moderator's name) on the Access tab's Banned players rows, instead of a cut-off "SharePermission…". (#47)
  • The mod no longer switches to your system's language on its first run, or after an update that adds languages, when you switched R.E.P.O. itself to English in its own language menu. (#19)
  • The Settings hint and the README no longer say everyone sees the start countdown. Only players running the mod see it, the host and moderators with Run control can cancel it, and it starts after the game's own start prompt. (#20)
  • Arena winners keep their name color. A winning host or moderator, or a player with their own name color, was drawn in a dark shade on the arena winner display, where the game shows other winners in white. The name now shows at full strength. (#22)
  • In Russian, Japanese and Spanish, the History search box's note that search terms are in English is no longer cut off. (#39)
  • A moderator whose Admin Menu permission the host switched off is now told so on the Settings tab, instead of being told they may open it. The line also says the Admin Menu opens in-game only. (#40)
  • Settings > Diagnostics on the host now shows what the host offers its moderators, and that the host may do everything. (#45)
  • A color typed in a color picker's hex field that is not a #RRGGBB value now says so on the page. (#59)
  • Translation fixes: the confirmation for kicking or banning a moderator is one whole question in every language; the Settings tab's Admin Menu section is headed "Admin Menu" in every language, English included; and neither the 1-on-1 key hint nor the voice tab's channel switch has a stray space in Japanese any more. (#48, #49, #50)

2.19.0

Added

  • Six more languages. The mod's own panels, toasts and popups now come in Spanish, Italian, Portuguese (Brazil), Japanese, German and French, next to English and Russian. On first run the mod picks the language your game or system uses. If you already had the mod and it is showing English because your language did not exist yet, it switches to your language once; pick English again and it stays English.

Changed

  • A proper language picker. The Language setting at the top of the Settings tab opens a list of every language, each written in its own language, instead of cycling through them one click at a time.
  • Russian, reread. Lines about another player no longer assume the player is male, the shortened ban-list line agrees with every count, a few stiff phrases read naturally, and a History row that cut the requesting player's name down to a few letters now shows it.

Fixed

  • The hang-up key could stop working until you restarted the game. If you clicked one of the Settings tab's 1-on-1 key rows and the panel closed before you pressed a key - through its Close button, a language change or a level change - that row kept waiting for a key out of sight, and while it waited the hang-up key did nothing. A key row now stops waiting as soon as the panel closes or another page opens over it, so a key typed on that page, such as a color's hex code, no longer becomes one of your 1-on-1 keys either.
  • Binding a 1-on-1 key can no longer end your call or answer an invite. A key you press on one of the Settings tab's key rows now only ever becomes that key: binding the hang-up key during a 1-on-1 can no longer also end the call, and binding the accept or decline key while an invite is on screen can no longer also answer it. While a row is waiting for a key, the invite's accept and decline keys wait too, as the hang-up key already did.
  • The invite prompt shows your new key. If you rebound the accept or decline key on the Settings tab while an invite was on screen, the prompt went on showing the old key, though only the new one answered it. It now shows the new key as soon as you bind it.
  • The corner list and the invite prompt change language with the rest of the mod. Picking a language on the Settings tab left the corner list's title, and its hang-up line during a 1-on-1, in the old language until you restarted the game, and an invite on screen in the old language until the next one. The title also stayed English for the session in which the mod first picked your language for you. Both now switch the moment the language does.

2.18.0

Changed

  • Lobby heads now show while you spectate too. Once you die, the list of dead players you see while spectating wears the same heads as the lobby. The game packs that list tighter than the lobby, so a tall hat overlaps the head above it there; the list's title moves up to make room for the top player's hat. The Settings toggle for lobby heads covers this list as well.

Fixed

  • Lobby heads look the same on every row. The list turns every other head to face the other way, and until now that flipped each hat and accessory but never the face under it: on half the rows the pirate's eye patch covered its only open eye, the question mark and the music notes read backwards and the 3D glasses swapped lenses. Now only the headset turns, so its microphone stays on the side the mouth opens.
  • A crowned player keeps glasses, the pirate's eye patch, a bandana and anything else worn on the head rather than on top of it under the arena crown, which now sits over them; hats still make way for it.
  • Art fixes to 42 lobby heads. The headset's red microphone tip was hidden behind the jaw; the sleepy lids stuck out past the head; the dollar signs were drawn wrong; the googly eyes notched the head's outline; the pig's ears floated above the head; pupils peeked out around the angry brows, the shades, the 3D glasses and the hockey mask, and vanished behind the knight's visor (which now has cross-shaped eye holes). Parts that disappeared on dark lobbies or on a player of the same color now have an edge or a lighter shade (the clown nose, the panda's ears, the monster's hair, the bandit mask's tails, the graduation cap's tassel, the dizzy star, the chef's hat band, the round glasses' frames), the fez tassel now hangs over the hat, the antlers are a little smaller, and slivers, gaps and overhangs are tidied on many more.
  • The head picker's previews look toward the head's name, as heads in the lobby always look somewhere, instead of staring straight ahead.

Older versions: see the full changelog at https://github.com/redos7/SharePermissions/blob/master/CHANGELOG.md