Merge 0.8->trunk
[prosody.git] / core / stanza_router.lua
index 3333354e5b5215fbd5118769c8e7b7afc2539274..97d328a1afbe3b2c51b2bff12a31fa139581bbda 100644 (file)
-
--- The code in this file should be self-explanatory, though the logic is horrible
--- for more info on that, see doc/stanza_routing.txt, which attempts to condense
--- the rules from the RFCs (mainly 3921)
-
-require "core.servermanager"
+-- Prosody IM
+-- Copyright (C) 2008-2010 Matthew Wild
+-- Copyright (C) 2008-2010 Waqas Hussain
+-- 
+-- This project is MIT/X11 licensed. Please see the
+-- COPYING file in the source package for more information.
+--
 
 local log = require "util.logger".init("stanzarouter")
 
+local hosts = _G.prosody.hosts;
+local tostring = tostring;
 local st = require "util.stanza";
 local send_s2s = require "core.s2smanager".send_to_host;
-local user_exists = require "core.usermanager".user_exists;
-
-local rostermanager = require "core.rostermanager";
-local sessionmanager = require "core.sessionmanager";
+local jid_split = require "util.jid".split;
+local jid_prepped_split = require "util.jid".prepped_split;
 
-local s2s_verify_dialback = require "core.s2smanager".verify_dialback;
-local s2s_make_authenticated = require "core.s2smanager".make_authenticated;
-local format = string.format;
-local tostring = tostring;
+local full_sessions = _G.prosody.full_sessions;
+local bare_sessions = _G.prosody.bare_sessions;
 
-local jid_split = require "util.jid".split;
-local print = print;
+local function handle_unhandled_stanza(host, origin, stanza)
+       local name, xmlns, origin_type = stanza.name, stanza.attr.xmlns or "jabber:client", origin.type;
+       if name == "iq" and xmlns == "jabber:client" then
+               if stanza.attr.type == "get" or stanza.attr.type == "set" then
+                       xmlns = stanza.tags[1].attr.xmlns or "jabber:client";
+                       log("debug", "Stanza of type %s from %s has xmlns: %s", name, origin_type, xmlns);
+               else
+                       log("debug", "Discarding %s from %s of type: %s", name, origin_type, stanza.attr.type);
+                       return true;
+               end
+       end
+       if stanza.attr.xmlns == nil then
+               log("debug", "Unhandled %s stanza: %s; xmlns=%s", origin.type, stanza.name, xmlns); -- we didn't handle it
+               if stanza.attr.type ~= "error" and stanza.attr.type ~= "result" then
+                       origin.send(st.error_reply(stanza, "cancel", "service-unavailable"));
+               end
+       elseif not((name == "features" or name == "error") and xmlns == "http://etherx.jabber.org/streams") then -- FIXME remove check once we handle S2S features
+               log("warn", "Unhandled %s stream element: %s; xmlns=%s: %s", origin.type, stanza.name, xmlns, tostring(stanza)); -- we didn't handle it
+               origin:close("unsupported-stanza-type");
+       end
+end
 
 function core_process_stanza(origin, stanza)
-       log("debug", "Received["..origin.type.."]: "..tostring(stanza))
+       (origin.log or log)("debug", "Received[%s]: %s", origin.type, stanza:top_tag())
+
        -- TODO verify validity of stanza (as well as JID validity)
-       if stanza.name == "iq" and not(#stanza.tags == 1 and stanza.tags[1].attr.xmlns) then
-               if stanza.attr.type == "set" or stanza.attr.type == "get" then
-                       error("Invalid IQ");
-               elseif #stanza.tags > 1 and not(stanza.attr.type == "error" or stanza.attr.type == "result") then
-                       error("Invalid IQ");
+       if stanza.attr.type == "error" and #stanza.tags == 0 then return; end -- TODO invalid stanza, log
+       if stanza.name == "iq" then
+               if not stanza.attr.id then stanza.attr.id = ""; end -- COMPAT Jabiru doesn't send the id attribute on roster requests
+               if (stanza.attr.type == "set" or stanza.attr.type == "get") and (#stanza.tags ~= 1) then
+                       origin.send(st.error_reply(stanza, "modify", "bad-request"));
+                       return;
                end
        end
 
-       if origin.type == "c2s" and not origin.full_jid
-               and not(stanza.name == "iq" and stanza.tags[1].name == "bind"
-                               and stanza.tags[1].attr.xmlns == "urn:ietf:params:xml:ns:xmpp-bind") then
-               error("Client MUST bind resource after auth");
-       end
+       if origin.type == "c2s" and not stanza.attr.xmlns then
+               if not origin.full_jid
+                       and not(stanza.name == "iq" and stanza.attr.type == "set" and stanza.tags[1] and stanza.tags[1].name == "bind"
+                                       and stanza.tags[1].attr.xmlns == "urn:ietf:params:xml:ns:xmpp-bind") then
+                       -- authenticated client isn't bound and current stanza is not a bind request
+                       if stanza.attr.type ~= "result" and stanza.attr.type ~= "error" then
+                               origin.send(st.error_reply(stanza, "auth", "not-authorized")); -- FIXME maybe allow stanzas to account or server
+                       end
+                       return;
+               end
 
-       local to = stanza.attr.to;
-       -- TODO also, stazas should be returned to their original state before the function ends
-       if origin.type == "c2s" then
-               stanza.attr.from = origin.full_jid; -- quick fix to prevent impersonation (FIXME this would be incorrect when the origin is not c2s)
+               -- TODO also, stanzas should be returned to their original state before the function ends
+               stanza.attr.from = origin.full_jid;
        end
-       
-       if not to then
-               core_handle_stanza(origin, stanza);
-       elseif origin.type == "c2s" and stanza.name == "presence" and stanza.attr.type ~= nil and stanza.attr.type ~= "unavailable" then
-               local node, host = jid_split(stanza.attr.to);
-               local to_bare = node and (node.."@"..host) or host; -- bare JID
-               local from_node, from_host = jid_split(stanza.attr.from);
-               local from_bare = from_node and (from_node.."@"..from_host) or from_host; -- bare JID
-               handle_outbound_presence_subscriptions_and_probes(origin, stanza, from_bare, to_bare);
-       elseif hosts[to] and hosts[to].type == "local" then
-               core_handle_stanza(origin, stanza);
-       elseif stanza.name == "iq" and not select(3, jid_split(to)) then
-               core_handle_stanza(origin, stanza);
-       elseif origin.type == "c2s" or origin.type == "s2sin" then
-               core_route_stanza(origin, stanza);
-       end
-end
-
--- This function handles stanzas which are not routed any further,
--- that is, they are handled by this server
-function core_handle_stanza(origin, stanza)
-       -- Handlers
-       if origin.type == "c2s" or origin.type == "c2s_unauthed" then
-               local session = origin;
-               
-               if stanza.name == "presence" and origin.roster then
-                       if stanza.attr.type == nil or stanza.attr.type == "unavailable" then
-                               for jid in pairs(origin.roster) do -- broadcast to all interested contacts
-                                       local subscription = origin.roster[jid].subscription;
-                                       if subscription == "both" or subscription == "from" then
-                                               stanza.attr.to = jid;
-                                               core_route_stanza(origin, stanza);
-                                       end
-                               end
-                               local node, host = jid_split(stanza.attr.from);
-                               for _, res in pairs(hosts[host].sessions[node].sessions) do -- broadcast to all resources
-                                       if res ~= origin and res.full_jid then -- to resource. FIXME is res.full_jid the correct check? Maybe it should be res.presence
-                                               stanza.attr.to = res.full_jid;
-                                               core_route_stanza(origin, stanza);
-                                       end
-                               end
-                               if not origin.presence then -- presence probes on initial presence -- FIXME does unavailable qualify as initial presence?
-                                       local probe = st.presence({from = origin.full_jid, type = "probe"});
-                                       for jid in pairs(origin.roster) do -- probe all contacts we are subscribed to
-                                               local subscription = origin.roster[jid].subscription;
-                                               if subscription == "both" or subscription == "to" then
-                                                       probe.attr.to = jid;
-                                                       core_route_stanza(origin, probe);
-                                               end
-                                       end
-                                       for _, res in pairs(hosts[host].sessions[node].sessions) do -- broadcast from all resources
-                                               if res ~= origin and stanza.attr.type ~= "unavailable" and res.presence then -- FIXME does unavailable qualify as initial presence?
-                                                       res.presence.attr.to = origin.full_jid;
-                                                       core_route_stanza(res, res.presence);
-                                                       res.presence.attr.to = nil;
-                                               end
-                                       end
-                                       -- TODO resend subscription requests
-                               end
-                               origin.presence = stanza;
-                               stanza.attr.to = nil; -- reset it
-                       else
-                               -- TODO error, bad type
-                       end
+       local to, xmlns = stanza.attr.to, stanza.attr.xmlns;
+       local from = stanza.attr.from;
+       local node, host, resource;
+       local from_node, from_host, from_resource;
+       local to_bare, from_bare;
+       if to then
+               if full_sessions[to] or bare_sessions[to] or hosts[to] then
+                       node, host = jid_split(to); -- TODO only the host is needed, optimize
                else
-                       log("debug", "Routing stanza to local");
-                       handle_stanza(session, stanza);
-               end
-       elseif origin.type == "s2sin_unauthed" or origin.type == "s2sin" then
-               if stanza.attr.xmlns == "jabber:server:dialback" then
-                       if stanza.name == "verify" then
-                               -- We are being asked to verify the key, to ensure it was generated by us
-                               log("debug", "verifying dialback key...");
-                               local attr = stanza.attr;
-                               print(tostring(attr.to), tostring(attr.from))
-                               print(tostring(origin.to_host), tostring(origin.from_host))
-                               -- FIXME: Grr, ejabberd breaks this one too?? it is black and white in XEP-220 example 34
-                               --if attr.from ~= origin.to_host then error("invalid-from"); end
-                               local type;
-                               if s2s_verify_dialback(attr.id, attr.from, attr.to, stanza[1]) then
-                                       type = "valid"
-                               else
-                                       type = "invalid"
-                                       log("warn", "Asked to verify a dialback key that was incorrect. An imposter is claiming to be %s?", attr.to);
+                       node, host, resource = jid_prepped_split(to);
+                       if not host then
+                               log("warn", "Received stanza with invalid destination JID: %s", to);
+                               if stanza.attr.type ~= "error" and stanza.attr.type ~= "result" then
+                                       origin.send(st.error_reply(stanza, "modify", "jid-malformed", "The destination address is invalid: "..to));
                                end
-                               origin.sends2s(format("<db:verify from='%s' to='%s' id='%s' type='%s'>%s</db:verify>", attr.to, attr.from, attr.id, type, stanza[1]));
-                       elseif stanza.name == "result" and origin.type == "s2sin_unauthed" then
-                               -- he wants to be identified through dialback
-                               -- We need to check the key with the Authoritative server
-                               local attr = stanza.attr;
-                               origin.from_host = attr.from;
-                               origin.to_host = attr.to;
-                               origin.dialback_key = stanza[1];
-                               log("debug", "asking %s if key %s belongs to them", origin.from_host, origin.dialback_key);
-                               send_s2s(origin.to_host, origin.from_host, format("<db:verify from='%s' to='%s' id='%s'>%s</db:verify>", origin.to_host, origin.from_host, origin.streamid, origin.dialback_key));
-                               hosts[origin.from_host].dialback_verifying = origin;
+                               return;
                        end
+                       to_bare = node and (node.."@"..host) or host; -- bare JID
+                       if resource then to = to_bare.."/"..resource; else to = to_bare; end
+                       stanza.attr.to = to;
                end
-       elseif origin.type == "s2sout_unauthed" or origin.type == "s2sout" then
-               if stanza.attr.xmlns == "jabber:server:dialback" then
-                       if stanza.name == "result" then
-                               if stanza.attr.type == "valid" then
-                                       s2s_make_authenticated(origin);
-                               else
-                                       -- FIXME
-                                       error("dialback failed!");
-                               end
-                       elseif stanza.name == "verify" and origin.dialback_verifying then
-                               local valid;
-                               local attr = stanza.attr;
-                               if attr.type == "valid" then
-                                       s2s_make_authenticated(origin.dialback_verifying);
-                                       valid = "valid";
-                               else
-                                       -- Warn the original connection that is was not verified successfully
-                                       log("warn", "dialback for "..(origin.dialback_verifying.from_host or "(unknown)").." failed");
-                                       valid = "invalid";
-                               end
-                               origin.dialback_verifying.sends2s(format("<db:result from='%s' to='%s' id='%s' type='%s'>%s</db:result>", attr.from, attr.to, attr.id, valid, origin.dialback_verifying.dialback_key));
+       end
+       if from and not origin.full_jid then
+               -- We only stamp the 'from' on c2s stanzas, so we still need to check validity
+               from_node, from_host, from_resource = jid_prepped_split(from);
+               if not from_host then
+                       log("warn", "Received stanza with invalid source JID: %s", from);
+                       if stanza.attr.type ~= "error" and stanza.attr.type ~= "result" then
+                               origin.send(st.error_reply(stanza, "modify", "jid-malformed", "The source address is invalid: "..from));
                        end
+                       return;
                end
-       else
-               log("warn", "Unhandled origin: %s", origin.type);
+               from_bare = from_node and (from_node.."@"..from_host) or from_host; -- bare JID
+               if from_resource then from = from_bare.."/"..from_resource; else from = from_bare; end
+               stanza.attr.from = from;
        end
-end
 
-function send_presence_of_available_resources(user, host, jid, recipient_session)
-       local h = hosts[host];
-       local count = 0;
-       if h and h.type == "local" then
-               local u = h.sessions[user];
-               if u then
-                       for k, session in pairs(u.sessions) do
-                               local pres = session.presence;
-                               if pres then
-                                       pres.attr.to = jid;
-                                       pres.attr.from = session.full_jid;
-                                       recipient_session.send(pres);
-                                       pres.attr.to = nil;
-                                       pres.attr.from = nil;
-                                       count = count + 1;
+       --[[if to and not(hosts[to]) and not(hosts[to_bare]) and (hosts[host] and hosts[host].type ~= "local") then -- not for us?
+               log("warn", "stanza recieved for a non-local server");
+               return; -- FIXME what should we do here?
+       end]] -- FIXME
+
+       if (origin.type == "s2sin" or origin.type == "c2s" or origin.type == "component") and xmlns == nil then
+               if origin.type == "s2sin" and not origin.dummy then
+                       local host_status = origin.hosts[from_host];
+                       if not host_status or not host_status.authed then -- remote server trying to impersonate some other server?
+                               log("warn", "Received a stanza claiming to be from %s, over a stream authed for %s!", from_host, origin.from_host);
+                               return; -- FIXME what should we do here? does this work with subdomains?
+                       end
+               end
+               core_post_stanza(origin, stanza, origin.full_jid);
+       else
+               local h = hosts[stanza.attr.to or origin.host or origin.to_host];
+               if h then
+                       local event;
+                       if xmlns == nil then
+                               if stanza.name == "iq" and (stanza.attr.type == "set" or stanza.attr.type == "get") then
+                                       event = "stanza/iq/"..stanza.tags[1].attr.xmlns..":"..stanza.tags[1].name;
+                               else
+                                       event = "stanza/"..stanza.name;
                                end
+                       else
+                               event = "stanza/"..xmlns..":"..stanza.name;
                        end
+                       if h.events.fire_event(event, {origin = origin, stanza = stanza}) then return; end
                end
+               if host and not hosts[host] then host = nil; end -- COMPAT: workaround for a Pidgin bug which sets 'to' to the SRV result
+               handle_unhandled_stanza(host or origin.host or origin.to_host, origin, stanza);
        end
-       return count;
 end
 
-function handle_outbound_presence_subscriptions_and_probes(origin, stanza, from_bare, to_bare)
-       local node, host = jid_split(from_bare);
-       local st_from, st_to = stanza.attr.from, stanza.attr.to;
-       stanza.attr.from, stanza.attr.to = from_bare, to_bare;
-       if stanza.attr.type == "subscribe" then
-               log("debug", "outbound subscribe from "..from_bare.." for "..to_bare);
-               -- 1. route stanza
-               -- 2. roster push (subscription = none, ask = subscribe)
-               if rostermanager.set_contact_pending_out(node, host, to_bare) then
-                       rostermanager.roster_push(node, host, to_bare);
-               end -- else file error
-               core_route_stanza(origin, stanza);
-       elseif stanza.attr.type == "unsubscribe" then
-               log("debug", "outbound unsubscribe from "..from_bare.." for "..to_bare);
-               -- 1. route stanza
-               -- 2. roster push (subscription = none or from)
-               if rostermanager.unsubscribe(node, host, to_bare) then
-                       rostermanager.roster_push(node, host, to_bare); -- FIXME do roster push when roster has in fact not changed?
-               end -- else file error
-               core_route_stanza(origin, stanza);
-       elseif stanza.attr.type == "subscribed" then
-               log("debug", "outbound subscribed from "..from_bare.." for "..to_bare);
-               -- 1. route stanza
-               -- 2. roster_push ()
-               -- 3. send_presence_of_available_resources
-               if rostermanager.subscribed(node, host, to_bare) then
-                       rostermanager.roster_push(node, host, to_bare);
-                       core_route_stanza(origin, stanza);
-                       send_presence_of_available_resources(node, host, to_bare, origin);
-               end
-       elseif stanza.attr.type == "unsubscribed" then
-               log("debug", "outbound unsubscribed from "..from_bare.." for "..to_bare);
-               -- 1. route stanza
-               -- 2. roster push (subscription = none or to)
-               if rostermanager.unsubscribed(node, host, to_bare) then
-                       rostermanager.roster_push(node, host, to_bare);
-                       core_route_stanza(origin, stanza);
-               end
-       end
-       stanza.attr.from, stanza.attr.to = st_from, st_to;
-end
+function core_post_stanza(origin, stanza, preevents)
+       local to = stanza.attr.to;
+       local node, host, resource = jid_split(to);
+       local to_bare = node and (node.."@"..host) or host; -- bare JID
 
-function handle_inbound_presence_subscriptions_and_probes(origin, stanza, from_bare, to_bare)
-       local node, host = jid_split(to_bare);
-       local st_from, st_to = stanza.attr.from, stanza.attr.to;
-       stanza.attr.from, stanza.attr.to = from_bare, to_bare;
-       if stanza.attr.type == "probe" then
-               if rostermanager.is_contact_subscribed(node, host, from_bare) then
-                       if 0 == send_presence_of_available_resources(node, host, from_bare, origin) then
-                               -- TODO send last recieved unavailable presence (or we MAY do nothing, which is fine too)
-                       end
-               else
-                       core_route_stanza(origin, st.presence({from=to_bare, to=from_bare, type="unsubscribed"}));
-               end
-       elseif stanza.attr.type == "subscribe" then
-               log("debug", "inbound subscribe from "..from_bare.." for "..to_bare);
-               if rostermanager.is_contact_subscribed(node, host, from_bare) then
-                       core_route_stanza(origin, st.presence({from=to_bare, to=from_bare, type="subscribed"})); -- already subscribed
+       local to_type, to_self;
+       if node then
+               if resource then
+                       to_type = '/full';
                else
-                       if not rostermanager.is_contact_pending_in(node, host, from_bare) then
-                               if rostermanager.set_contact_pending_in(node, host, from_bare) then
-                                       sessionmanager.send_to_available_resources(node, host, stanza);
-                               end -- TODO else return error, unable to save
+                       to_type = '/bare';
+                       if node == origin.username and host == origin.host then
+                               stanza.attr.to = nil;
+                               to_self = true;
                        end
                end
-       elseif stanza.attr.type == "unsubscribe" then
-               log("debug", "inbound unsubscribe from "..from_bare.." for "..to_bare);
-               if rostermanager.process_inbound_unsubscribe(node, host, from_bare) then
-                       rostermanager.roster_push(node, host, from_bare);
-               end
-       elseif stanza.attr.type == "subscribed" then
-               log("debug", "inbound subscribed from "..from_bare.." for "..to_bare);
-               if rostermanager.process_inbound_subscription_approval(node, host, from_bare) then
-                       rostermanager.roster_push(node, host, from_bare);
-               end
-       elseif stanza.attr.type == "unsubscribed" then
-               log("debug", "inbound unsubscribed from "..from_bare.." for "..to_bare);
-               if rostermanager.process_inbound_subscription_approval(node, host, from_bare) then
-                       rostermanager.roster_push(node, host, from_bare);
+       else
+               if host then
+                       to_type = '/host';
+               else
+                       to_type = '/bare';
+                       to_self = true;
                end
-       end -- discard any other type
-       stanza.attr.from, stanza.attr.to = st_from, st_to;
+       end
+
+       local event_data = {origin=origin, stanza=stanza};
+       if preevents then -- c2s connection
+               if hosts[origin.host].events.fire_event('pre-'..stanza.name..to_type, event_data) then return; end -- do preprocessing
+       end
+       local h = hosts[to_bare] or hosts[host or origin.host];
+       if h then
+               if h.events.fire_event(stanza.name..to_type, event_data) then return; end -- do processing
+               if to_self and h.events.fire_event(stanza.name..'/self', event_data) then return; end -- do processing
+               handle_unhandled_stanza(h.host, origin, stanza);
+       else
+               core_route_stanza(origin, stanza);
+       end
 end
 
 function core_route_stanza(origin, stanza)
-       -- Hooks
-       --- ...later
-       
-       -- Deliver
-       local to = stanza.attr.to;
-       local node, host, resource = jid_split(to);
-       local to_bare = node and (node.."@"..host) or host; -- bare JID
-       local from = stanza.attr.from;
-       local from_node, from_host, from_resource = jid_split(from);
-       local from_bare = from_node and (from_node.."@"..from_host) or from_host; -- bare JID
-
-       if stanza.name == "presence" and (stanza.attr.type ~= nil and stanza.attr.type ~= "unavailable") then resource = nil; end
+       local node, host, resource = jid_split(stanza.attr.to);
+       local from_node, from_host, from_resource = jid_split(stanza.attr.from);
 
-       local host_session = hosts[host]
-       if host_session and host_session.type == "local" then
-               -- Local host
-               local user = host_session.sessions[node];
-               if user then
-                       local res = user.sessions[resource];
-                       if not res then
-                               -- if we get here, resource was not specified or was unavailable
-                               if stanza.name == "presence" then
-                                       if stanza.attr.type ~= nil and stanza.attr.type ~= "unavailable" then
-                                               handle_inbound_presence_subscriptions_and_probes(origin, stanza, from_bare, to_bare);
-                                       else -- sender is available or unavailable
-                                               for k in pairs(user.sessions) do -- presence broadcast to all user resources. FIXME should this be just for available resources? Do we need to check subscription?
-                                                       if user.sessions[k].full_jid then
-                                                               stanza.attr.to = user.sessions[k].full_jid; -- reset at the end of function
-                                                               user.sessions[k].send(stanza);
-                                                       end
-                                               end
-                                       end
-                               elseif stanza.name == "message" then -- select a resource to recieve message
-                                       for k in pairs(user.sessions) do
-                                               if user.sessions[k].full_jid then
-                                                       res = user.sessions[k];
-                                                       break;
-                                               end
-                                       end
-                                       -- TODO find resource with greatest priority
-                                       res.send(stanza);
-                               else
-                                       -- TODO send IQ error
-                               end
-                       else
-                               -- User + resource is online...
-                               stanza.attr.to = res.full_jid; -- reset at the end of function
-                               res.send(stanza); -- Yay \o/
-                       end
-               else
-                       -- user not online
-                       if user_exists(node, host) then
-                               if stanza.name == "presence" then
-                                       if stanza.attr.type ~= nil and stanza.attr.type ~= "unavailable" then
-                                               handle_inbound_presence_subscriptions_and_probes(origin, stanza, from_bare, to_bare);
-                                       else
-                                               -- TODO send unavailable presence or unsubscribed
-                                       end
-                               elseif stanza.name == "message" then
-                                       -- TODO send message error, or store offline messages
-                               elseif stanza.name == "iq" then
-                                       -- TODO send IQ error
-                               end
-                       else -- user does not exist
-                               -- TODO we would get here for nodeless JIDs too. Do something fun maybe? Echo service? Let plugins use xmpp:server/resource addresses?
-                               if stanza.name == "presence" then
-                                       if stanza.attr.type == "probe" then
-                                               origin.send(st.presence({from = to_bare, to = from_bare, type = "unsubscribed"}));
-                                       end
-                                       -- else ignore
-                               else
-                                       origin.send(st.error_reply(stanza, "cancel", "service-unavailable"));
-                               end
-                       end
-               end
+       -- Auto-detect origin if not specified
+       origin = origin or hosts[from_host];
+       if not origin then return false; end
+       
+       if hosts[host] then
+               -- old stanza routing code removed
+               core_post_stanza(origin, stanza);
        elseif origin.type == "c2s" then
                -- Remote host
-               local xmlns = stanza.attr.xmlns;
-               --stanza.attr.xmlns = "jabber:server";
-               stanza.attr.xmlns = nil;
-               log("debug", "sending s2s stanza: %s", tostring(stanza));
-               send_s2s(origin.host, host, stanza); -- TODO handle remote routing errors
-               stanza.attr.xmlns = xmlns; -- reset
+               if not hosts[from_host] then
+                       log("error", "No hosts[from_host] (please report): %s", tostring(stanza));
+               end
+               if (not hosts[from_host]) or (not hosts[from_host].disallow_s2s) then
+                       local xmlns = stanza.attr.xmlns;
+                       --stanza.attr.xmlns = "jabber:server";
+                       stanza.attr.xmlns = nil;
+                       log("debug", "sending s2s stanza: %s", tostring(stanza.top_tag and stanza:top_tag()) or stanza);
+                       send_s2s(origin.host, host, stanza); -- TODO handle remote routing errors
+                       stanza.attr.xmlns = xmlns; -- reset
+               else
+                       core_route_stanza(hosts[from_host], st.error_reply(stanza, "cancel", "not-allowed", "Communication with remote servers is not allowed"));
+               end
+       elseif origin.type == "component" or origin.type == "local" then
+               -- Route via s2s for components and modules
+               log("debug", "Routing outgoing stanza for %s to %s", from_host, host);
+               send_s2s(from_host, host, stanza);
        else
-               log("warn", "received stanza from unhandled connection type: %s", origin.type);
+               log("warn", "received %s stanza from unhandled connection type: %s", tostring(stanza.name), tostring(origin.type));
        end
-       stanza.attr.to = to; -- reset
-end
-
-function handle_stanza_toremote(stanza)
-       log("error", "Stanza bound for remote host, but s2s is not implemented");
 end