xmlhandlers: Don't restrict CDATA
[prosody.git] / core / stanza_router.lua
index 6fa41232f00d837f6e115220b110647dd4c78818..d6dd53062d655ae59768b097a0c9b71d7c6d1a5e 100644 (file)
@@ -1,72 +1,50 @@
--- Prosody IM v0.4
--- Copyright (C) 2008-2009 Matthew Wild
--- Copyright (C) 2008-2009 Waqas Hussain
+-- Prosody IM
+-- Copyright (C) 2008-2010 Matthew Wild
+-- Copyright (C) 2008-2010 Waqas Hussain
 -- 
 -- This project is MIT/X11 licensed. Please see the
 -- COPYING file in the source package for more information.
 --
 
-
-
 local log = require "util.logger".init("stanzarouter")
 
-local hosts = _G.hosts;
-
+local hosts = _G.prosody.hosts;
+local tostring = tostring;
 local st = require "util.stanza";
 local send_s2s = require "core.s2smanager".send_to_host;
-local user_exists = require "core.usermanager".user_exists;
-
-local rostermanager = require "core.rostermanager";
-local sessionmanager = require "core.sessionmanager";
-local offlinemanager = require "core.offlinemanager";
-
-local s2s_verify_dialback = require "core.s2smanager".verify_dialback;
-local s2s_make_authenticated = require "core.s2smanager".make_authenticated;
-
 local modules_handle_stanza = require "core.modulemanager".handle_stanza;
 local component_handle_stanza = require "core.componentmanager".handle_stanza;
-
-local handle_outbound_presence_subscriptions_and_probes = function()end;--require "core.presencemanager".handle_outbound_presence_subscriptions_and_probes;
-local handle_inbound_presence_subscriptions_and_probes = function()end;--require "core.presencemanager".handle_inbound_presence_subscriptions_and_probes;
-local handle_normal_presence = function()end;--require "core.presencemanager".handle_normal_presence;
-
-local format = string.format;
-local tostring = tostring;
-local t_concat = table.concat;
-local t_insert = table.insert;
-local tonumber = tonumber;
-local s_find = string.find;
-local pairs = pairs;
-local ipairs = ipairs;
-
 local jid_split = require "util.jid".split;
 local jid_prepped_split = require "util.jid".prepped_split;
-local print = print;
-local fire_event = require "core.eventmanager2".fire_event;
+
+local full_sessions = _G.prosody.full_sessions;
+local bare_sessions = _G.prosody.bare_sessions;
 
 function core_process_stanza(origin, stanza)
        (origin.log or log)("debug", "Received[%s]: %s", origin.type, stanza:top_tag())
 
-       -- Currently we guarantee every stanza to have an xmlns, should we keep this rule?
-       if not stanza.attr.xmlns then stanza.attr.xmlns = "jabber:client"; end
-       
        -- TODO verify validity of stanza (as well as JID validity)
        if stanza.attr.type == "error" and #stanza.tags == 0 then return; end -- TODO invalid stanza, log
        if stanza.name == "iq" then
-               if (stanza.attr.type == "set" or stanza.attr.type == "get") and #stanza.tags ~= 1 then
+               if not stanza.attr.id then stanza.attr.id = ""; end -- COMPAT Jabiru doesn't send the id attribute on roster requests
+               if (stanza.attr.type == "set" or stanza.attr.type == "get") and (#stanza.tags ~= 1) then
                        origin.send(st.error_reply(stanza, "modify", "bad-request"));
                        return;
                end
        end
 
-       if origin.type == "c2s" and not origin.full_jid
-               and not(stanza.name == "iq" and stanza.tags[1].name == "bind"
-                               and stanza.tags[1].attr.xmlns == "urn:ietf:params:xml:ns:xmpp-bind") then
-               error("Client MUST bind resource after auth");
-       end
+       if origin.type == "c2s" and not stanza.attr.xmlns then
+               if not origin.full_jid
+                       and not(stanza.name == "iq" and stanza.attr.type == "set" and stanza.tags[1] and stanza.tags[1].name == "bind"
+                                       and stanza.tags[1].attr.xmlns == "urn:ietf:params:xml:ns:xmpp-bind") then
+                       -- authenticated client isn't bound and current stanza is not a bind request
+                       if stanza.attr.type ~= "result" and stanza.attr.type ~= "error" then
+                               origin.send(st.error_reply(stanza, "auth", "not-authorized")); -- FIXME maybe allow stanzas to account or server
+                       end
+                       return;
+               end
 
-       -- TODO also, stanzas should be returned to their original state before the function ends
-       if origin.type == "c2s" then
+               -- TODO also, stanzas should be returned to their original state before the function ends
                stanza.attr.from = origin.full_jid;
        end
        local to, xmlns = stanza.attr.to, stanza.attr.xmlns;
@@ -75,22 +53,30 @@ function core_process_stanza(origin, stanza)
        local from_node, from_host, from_resource;
        local to_bare, from_bare;
        if to then
-               node, host, resource = jid_prepped_split(to);
-               if not host then
-                       log("warn", "Received stanza with invalid destination JID: %s", to);
-                       origin.send(st.error_reply(stanza, "modify", "jid-malformed", "The destination address is invalid: "..to));
-                       return;
+               if full_sessions[to] or bare_sessions[to] or hosts[to] then
+                       node, host = jid_split(to); -- TODO only the host is needed, optimize
+               else
+                       node, host, resource = jid_prepped_split(to);
+                       if not host then
+                               log("warn", "Received stanza with invalid destination JID: %s", to);
+                               if stanza.attr.type ~= "error" and stanza.attr.type ~= "result" then
+                                       origin.send(st.error_reply(stanza, "modify", "jid-malformed", "The destination address is invalid: "..to));
+                               end
+                               return;
+                       end
+                       to_bare = node and (node.."@"..host) or host; -- bare JID
+                       if resource then to = to_bare.."/"..resource; else to = to_bare; end
+                       stanza.attr.to = to;
                end
-               to_bare = node and (node.."@"..host) or host; -- bare JID
-               if resource then to = to_bare.."/"..resource; else to = to_bare; end
-               stanza.attr.to = to;
        end
-       if from then
+       if from and not origin.full_jid then
                -- We only stamp the 'from' on c2s stanzas, so we still need to check validity
                from_node, from_host, from_resource = jid_prepped_split(from);
                if not from_host then
                        log("warn", "Received stanza with invalid source JID: %s", from);
-                       origin.send(st.error_reply(stanza, "modify", "jid-malformed", "The source address is invalid: "..from));
+                       if stanza.attr.type ~= "error" and stanza.attr.type ~= "result" then
+                               origin.send(st.error_reply(stanza, "modify", "jid-malformed", "The source address is invalid: "..from));
+                       end
                        return;
                end
                from_bare = from_node and (from_node.."@"..from_host) or from_host; -- bare JID
@@ -103,7 +89,7 @@ function core_process_stanza(origin, stanza)
                return; -- FIXME what should we do here?
        end]] -- FIXME
 
-       if (origin.type == "s2sin" or origin.type == "c2s" or origin.type == "component") and xmlns == "jabber:client" then
+       if (origin.type == "s2sin" or origin.type == "c2s" or origin.type == "component") and xmlns == nil then
                if origin.type == "s2sin" and not origin.dummy then
                        local host_status = origin.hosts[from_host];
                        if not host_status or not host_status.authed then -- remote server trying to impersonate some other server?
@@ -111,172 +97,102 @@ function core_process_stanza(origin, stanza)
                                return; -- FIXME what should we do here? does this work with subdomains?
                        end
                end
-               core_post_stanza(origin, stanza);
+               core_post_stanza(origin, stanza, origin.full_jid);
        else
+               local h = hosts[stanza.attr.to or origin.host or origin.to_host];
+               if h then
+                       local event;
+                       if xmlns == nil then
+                               if stanza.name == "iq" and (stanza.attr.type == "set" or stanza.attr.type == "get") then
+                                       event = "stanza/iq/"..stanza.tags[1].attr.xmlns..":"..stanza.tags[1].name;
+                               else
+                                       event = "stanza/"..stanza.name;
+                               end
+                       else
+                               event = "stanza/"..xmlns..":"..stanza.name;
+                       end
+                       if h.events.fire_event(event, {origin = origin, stanza = stanza}) then return; end
+               end
+               if host and not hosts[host] then host = nil; end -- COMPAT: workaround for a Pidgin bug which sets 'to' to the SRV result
                modules_handle_stanza(host or origin.host or origin.to_host, origin, stanza);
        end
 end
 
-function core_post_stanza(origin, stanza)
+function core_post_stanza(origin, stanza, preevents)
        local to = stanza.attr.to;
        local node, host, resource = jid_split(to);
        local to_bare = node and (node.."@"..host) or host; -- bare JID
 
+       local to_type, to_self;
+       if node then
+               if resource then
+                       to_type = '/full';
+               else
+                       to_type = '/bare';
+                       if node == origin.username and host == origin.host then
+                               stanza.attr.to = nil;
+                               to_self = true;
+                       end
+               end
+       else
+               if host then
+                       to_type = '/host';
+               else
+                       to_type = '/bare';
+                       to_self = true;
+               end
+       end
+
        local event_data = {origin=origin, stanza=stanza};
-       if host and fire_event(host.."/"..stanza.name, event_data) then
-               -- event handled
-       elseif stanza.name == "presence" and origin.host and fire_event(origin.host.."/"..stanza.name, event_data) then
-               -- event handled
-       elseif not to then
-               modules_handle_stanza(host or origin.host or origin.to_host, origin, stanza);
-       elseif hosts[to] and hosts[to].type == "local" then -- directed at a local server
-               modules_handle_stanza(host or origin.host or origin.to_host, origin, stanza);
-       elseif hosts[to_bare] and hosts[to_bare].type == "component" then -- hack to allow components to handle node@server
-               component_handle_stanza(origin, stanza);
-       elseif hosts[host] and hosts[host].type == "component" then -- directed at a component
-               component_handle_stanza(origin, stanza);
-       elseif hosts[host] and hosts[host].type == "local" and stanza.name == "iq" and not resource then -- directed at bare JID
-               modules_handle_stanza(host or origin.host or origin.to_host, origin, stanza);
+       if preevents then -- c2s connection
+               if hosts[origin.host].events.fire_event('pre-'..stanza.name..to_type, event_data) then return; end -- do preprocessing
+       end
+       local h = hosts[to_bare] or hosts[host or origin.host];
+       if h then
+               if h.events.fire_event(stanza.name..to_type, event_data) then return; end -- do processing
+               if to_self and h.events.fire_event(stanza.name..'/self', event_data) then return; end -- do processing
+
+               if h.type == "component" then
+                       component_handle_stanza(origin, stanza);
+                       return;
+               end
+               modules_handle_stanza(h.host, origin, stanza);
        else
                core_route_stanza(origin, stanza);
        end
 end
 
 function core_route_stanza(origin, stanza)
-       -- Hooks
-       --- ...later
-
-       -- Deliver
-       local to = stanza.attr.to;
-       local node, host, resource = jid_split(to);
-       local to_bare = node and (node.."@"..host) or host; -- bare JID
-       local from = stanza.attr.from;
-       local from_node, from_host, from_resource = jid_split(from);
-       local from_bare = from_node and (from_node.."@"..from_host) or from_host; -- bare JID
+       local node, host, resource = jid_split(stanza.attr.to);
+       local from_node, from_host, from_resource = jid_split(stanza.attr.from);
 
        -- Auto-detect origin if not specified
        origin = origin or hosts[from_host];
        if not origin then return false; end
        
-       if hosts[to_bare] and hosts[to_bare].type == "component" then -- hack to allow components to handle node@server
-               return component_handle_stanza(origin, stanza);
-       elseif hosts[host] and hosts[host].type == "component" then -- directed at a component
-               return component_handle_stanza(origin, stanza);
-       end
-
-       if stanza.name == "presence" and (stanza.attr.type ~= nil and stanza.attr.type ~= "unavailable" and stanza.attr.type ~= "error") then resource = nil; end
-
-       local host_session = hosts[host]
-       if host_session and host_session.type == "local" then
-               -- Local host
-               local user = host_session.sessions[node];
-               if user then
-                       local res = user.sessions[resource];
-                       if res then -- resource is online...
-                               res.send(stanza); -- Yay \o/
-                       else
-                               -- if we get here, resource was not specified or was unavailable
-                               if stanza.name == "presence" then
-                                       if stanza.attr.type ~= nil and stanza.attr.type ~= "unavailable" and stanza.attr.type ~= "error" then
-                                               handle_inbound_presence_subscriptions_and_probes(origin, stanza, from_bare, to_bare, core_route_stanza);
-                                       elseif not resource then -- sender is available or unavailable or error
-                                               for _, session in pairs(user.sessions) do -- presence broadcast to all user resources.
-                                                       if session.full_jid then -- FIXME should this be just for available resources? Do we need to check subscription?
-                                                               stanza.attr.to = session.full_jid; -- reset at the end of function
-                                                               session.send(stanza);
-                                                       end
-                                               end
-                                       end
-                               elseif stanza.name == "message" then -- select a resource to recieve message
-                                       stanza.attr.to = to_bare;
-                                       if stanza.attr.type == 'headline' then
-                                               for _, session in pairs(user.sessions) do -- find resource with greatest priority
-                                                       if session.presence and session.priority >= 0 then
-                                                               session.send(stanza);
-                                                       end
-                                               end
-                                       elseif resource and stanza.attr.type == 'groupchat' then
-                                               -- Groupchat message sent to offline resource
-                                               origin.send(st.error_reply(stanza, "cancel", "service-unavailable"));
-                                       else
-                                               local priority = 0;
-                                               local recipients = {};
-                                               for _, session in pairs(user.sessions) do -- find resource with greatest priority
-                                                       if session.presence then
-                                                               local p = session.priority;
-                                                               if p > priority then
-                                                                       priority = p;
-                                                                       recipients = {session};
-                                                               elseif p == priority then
-                                                                       t_insert(recipients, session);
-                                                               end
-                                                       end
-                                               end
-                                               local count = 0;
-                                               for _, session in ipairs(recipients) do
-                                                       session.send(stanza);
-                                                       count = count + 1;
-                                               end
-                                               if count == 0 and (stanza.attr.type == "chat" or stanza.attr.type == "normal" or not stanza.attr.type) then
-                                                       offlinemanager.store(node, host, stanza);
-                                                       -- TODO deal with storage errors
-                                               end
-                                       end
-                               elseif stanza.attr.type == "get" or stanza.attr.type == "set" then
-                                       origin.send(st.error_reply(stanza, "cancel", "service-unavailable"));
-                               end
-                       end
-               else
-                       -- user not online
-                       if user_exists(node, host) then
-                               if stanza.name == "presence" then
-                                       if stanza.attr.type ~= nil and stanza.attr.type ~= "unavailable" and stanza.attr.type ~= "error" then
-                                               handle_inbound_presence_subscriptions_and_probes(origin, stanza, from_bare, to_bare, core_route_stanza);
-                                       else
-                                               -- TODO send unavailable presence or unsubscribed
-                                       end
-                               elseif stanza.name == "message" then -- FIXME if full jid, then send out to resources with highest priority
-                                       stanza.attr.to = to_bare; -- TODO not in RFC, but seems obvious. Should discuss on the mailing list.
-                                       if stanza.attr.type == "chat" or stanza.attr.type == "normal" or not stanza.attr.type then
-                                               offlinemanager.store(node, host, stanza);
-                                               -- FIXME don't store messages with only chat state notifications
-                                       elseif stanza.attr.type == "groupchat" then
-                                               local reply = st.error_reply(stanza, "cancel", "service-unavailable");
-                                               reply.attr.from = to;
-                                               origin.send(reply);
-                                       end
-                                       -- TODO allow configuration of offline storage
-                                       -- TODO send error if not storing offline
-                               elseif stanza.name == "iq" and (stanza.attr.type == "get" or stanza.attr.type == "set") then
-                                       origin.send(st.error_reply(stanza, "cancel", "service-unavailable"));
-                               end
-                       else -- user does not exist
-                               -- TODO we would get here for nodeless JIDs too. Do something fun maybe? Echo service? Let plugins use xmpp:server/resource addresses?
-                               if stanza.name == "presence" then
-                                       local t = stanza.attr.type;
-                                       if t == "subscribe" or t == "probe" then
-                                               origin.send(st.presence({from = to_bare, to = from_bare, type = "unsubscribed"}));
-                                       end
-                                       -- else ignore
-                               elseif stanza.attr.type ~= "error" and (stanza.name ~= "iq" or stanza.attr.type ~= "result") then
-                                       origin.send(st.error_reply(stanza, "cancel", "service-unavailable"));
-                               end
-                       end
-               end
+       if hosts[host] then
+               -- old stanza routing code removed
+               core_post_stanza(origin, stanza);
        elseif origin.type == "c2s" then
                -- Remote host
-               local xmlns = stanza.attr.xmlns;
-               --stanza.attr.xmlns = "jabber:server";
-               stanza.attr.xmlns = nil;
-               log("debug", "sending s2s stanza: %s", tostring(stanza));
-               send_s2s(origin.host, host, stanza); -- TODO handle remote routing errors
-               stanza.attr.xmlns = xmlns; -- reset
+               if not hosts[from_host] then
+                       log("error", "No hosts[from_host] (please report): %s", tostring(stanza));
+               end
+               if (not hosts[from_host]) or (not hosts[from_host].disallow_s2s) then
+                       local xmlns = stanza.attr.xmlns;
+                       --stanza.attr.xmlns = "jabber:server";
+                       stanza.attr.xmlns = nil;
+                       log("debug", "sending s2s stanza: %s", tostring(stanza.top_tag and stanza:top_tag()) or stanza);
+                       send_s2s(origin.host, host, stanza); -- TODO handle remote routing errors
+                       stanza.attr.xmlns = xmlns; -- reset
+               else
+                       core_route_stanza(hosts[from_host], st.error_reply(stanza, "cancel", "not-allowed", "Communication with remote servers is not allowed"));
+               end
        elseif origin.type == "component" or origin.type == "local" then
                -- Route via s2s for components and modules
-               log("debug", "Routing outgoing stanza for %s to %s", origin.host, host);
-               send_s2s(origin.host, host, stanza);
+               log("debug", "Routing outgoing stanza for %s to %s", from_host, host);
+               send_s2s(from_host, host, stanza);
        else
-               log("warn", "received stanza from unhandled connection type: %s", origin.type);
+               log("warn", "received %s stanza from unhandled connection type: %s", tostring(stanza.name), tostring(origin.type));
        end
-       stanza.attr.to = to; -- reset
 end