projects
/
prosody.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
mod_welcome: Use module:hook instead of module:add_event_hook
[prosody.git]
/
plugins
/
mod_legacyauth.lua
diff --git
a/plugins/mod_legacyauth.lua
b/plugins/mod_legacyauth.lua
index 3e3924704d1cd35aef4b1554c193fef4f86a31df..8bff51fef7be460b2dd21a69e2e17ead81b47d71 100644
(file)
--- a/
plugins/mod_legacyauth.lua
+++ b/
plugins/mod_legacyauth.lua
@@
-1,4
+1,4
@@
--- Prosody IM v0.
3
+-- Prosody IM v0.
4
-- Copyright (C) 2008-2009 Matthew Wild
-- Copyright (C) 2008-2009 Waqas Hussain
--
-- Copyright (C) 2008-2009 Matthew Wild
-- Copyright (C) 2008-2009 Waqas Hussain
--
@@
-11,13
+11,29
@@
local st = require "util.stanza";
local t_concat = table.concat;
local st = require "util.stanza";
local t_concat = table.concat;
+local config = require "core.configmanager";
+local secure_auth_only = config.get(module:get_host(), "core", "require_encryption");
+
+local sessionmanager = require "core.sessionmanager";
+local usermanager = require "core.usermanager";
+
module:add_feature("jabber:iq:auth");
module:add_event_hook("stream-features", function (session, features)
module:add_feature("jabber:iq:auth");
module:add_event_hook("stream-features", function (session, features)
- if not session.username then features:tag("auth", {xmlns='http://jabber.org/features/iq-auth'}):up(); end
+ if secure_auth_only and not session.secure then
+ -- Sorry, not offering to insecure streams!
+ return;
+ elseif not session.username then
+ features:tag("auth", {xmlns='http://jabber.org/features/iq-auth'}):up();
+ end
end);
module:add_iq_handler("c2s_unauthed", "jabber:iq:auth",
function (session, stanza)
end);
module:add_iq_handler("c2s_unauthed", "jabber:iq:auth",
function (session, stanza)
+ if secure_auth_only and not session.secure then
+ session.send(st.error_reply(stanza, "modify", "not-acceptable", "Encryption (SSL or TLS) is required to connect to this server"));
+ return true;
+ end
+
local username = stanza.tags[1]:child_with_name("username");
local password = stanza.tags[1]:child_with_name("password");
local resource = stanza.tags[1]:child_with_name("resource");
local username = stanza.tags[1]:child_with_name("username");
local password = stanza.tags[1]:child_with_name("password");
local resource = stanza.tags[1]:child_with_name("resource");