aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorKim Alvefur <zash@zash.se>2016-01-19 21:31:02 +0100
committerKim Alvefur <zash@zash.se>2016-01-19 21:31:02 +0100
commitc03e941ccc5e429741ca485a582c6bf036cc57bf (patch)
tree06c1f55240e52a54e0dbc00293fdb833b80b7f66
parent6490acf700c4d8c197320dfe0602462ed0d4d212 (diff)
downloadprosody-c03e941ccc5e429741ca485a582c6bf036cc57bf.tar.gz
prosody-c03e941ccc5e429741ca485a582c6bf036cc57bf.zip
mod_dialback: Follow XEP-0185 and use HMAC
-rw-r--r--plugins/mod_dialback.lua3
1 files changed, 2 insertions, 1 deletions
diff --git a/plugins/mod_dialback.lua b/plugins/mod_dialback.lua
index 9dcb0ed5..dc3c3f10 100644
--- a/plugins/mod_dialback.lua
+++ b/plugins/mod_dialback.lua
@@ -12,6 +12,7 @@ local log = module._log;
local st = require "util.stanza";
local sha256_hash = require "util.hashes".sha256;
+local sha256_hmac = require "util.hashes".hmac_sha256;
local nameprep = require "util.encodings".stringprep.nameprep;
local xmlns_stream = "http://etherx.jabber.org/streams";
@@ -19,7 +20,7 @@ local xmlns_stream = "http://etherx.jabber.org/streams";
local dialback_requests = setmetatable({}, { __mode = 'v' });
function generate_dialback(id, to, from)
- return sha256_hash(id..to..from..hosts[from].dialback_secret, true);
+ return sha256_hmac(sha256_hash(hosts[from].dialback_secret), to .. ' ' .. from .. ' ' .. id, true);
end
function initiate_dialback(session)