mod_saslauth: Requiring c2s encryption means requiring c2s encryption... thanks Flo

Mon, 21 Dec 2009 22:00:49 +0000

author
Matthew Wild <mwild1@gmail.com>
date
Mon, 21 Dec 2009 22:00:49 +0000
changeset 2388
4768879d3591
parent 2387
92264ee3a0e4
child 2389
8f6526da4757

mod_saslauth: Requiring c2s encryption means requiring c2s encryption... thanks Flo

plugins/mod_saslauth.lua file | annotate | diff | comparison | revisions
--- a/plugins/mod_saslauth.lua	Mon Dec 21 17:03:47 2009 +0000
+++ b/plugins/mod_saslauth.lua	Mon Dec 21 22:00:49 2009 +0000
@@ -104,6 +104,9 @@
 		if not valid_mechanism then
 			return session.send(build_reply("failure", "invalid-mechanism"));
 		end
+		if secure_auth_only and not session.secure then
+			return session.send(build_reply("failure", "encryption-required"));
+		end
 	elseif not session.sasl_handler then
 		return; -- FIXME ignoring out of order stanzas because ejabberd does
 	end

mercurial