Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | doap: Update XEP-0359 version, no protocol changes | Kim Alvefur | 2023-11-11 | 1 | -1/+1 |
| | | | | Security considerations added, no protocol changes. | ||||
* | doap: Update XEP-0353 version, no change affecting server handling | Kim Alvefur | 2023-11-11 | 1 | -1/+1 |
| | |||||
* | doap: Update XEP-0313 version, only change align with current mod_mam behavior | Kim Alvefur | 2023-11-11 | 1 | -1/+1 |
| | |||||
* | doap: Update XEP-0045 version, only minor changes | Kim Alvefur | 2023-11-11 | 1 | -1/+1 |
| | |||||
* | util.startup: Attempt to bring some order to startup/shutdown with util.fsm | Matthew Wild | 2023-11-07 | 1 | -10/+41 |
| | |||||
* | .luacheckrc: Add module:could() | Matthew Wild | 2023-11-07 | 1 | -0/+1 |
| | |||||
* | moduleapi: may(): Support explicit actor_jid in context object | Matthew Wild | 2023-11-07 | 1 | -18/+24 |
| | |||||
* | mod_muc: Switch to module:could() for some implicit access control checks | Matthew Wild | 2023-11-07 | 1 | -2/+2 |
| | |||||
* | mod_muc: Allow guest users to list rooms by default | Matthew Wild | 2023-11-07 | 1 | -0/+3 |
| | |||||
* | mod_muc: Add :list-rooms permission | Matthew Wild | 2023-11-07 | 1 | -1/+5 |
| | |||||
* | mod_tokenauth: Fix saving grants after clearing expired tokens | Kim Alvefur | 2023-11-05 | 1 | -4/+4 |
| | | | | | Previously the whole grant was deleted if it found one expired toke, which was not indented. | ||||
* | mod_s2s_auth_certs: Remove LuaSec compat that moved to net.server | Kim Alvefur | 2023-11-04 | 1 | -6/+1 |
| | |||||
* | core.certmanager: Handle dane context setting same way on reload as on ↵ | Kim Alvefur | 2023-11-04 | 1 | -1/+7 |
| | | | | initialization | ||||
* | util.prosodyctl.check: Print DANE TLSA records for certificates | Kim Alvefur | 2023-11-03 | 1 | -0/+10 |
| | | | | Not the prosodyctl check dane I wanted to make but a start. | ||||
* | util.prosodyctl.check: Wrap each check in a function | Kim Alvefur | 2023-11-03 | 1 | -13/+29 |
| | | | | | | | One small refactor but one huge step in the right direction Mostly because adding another check would make the line checking for a valid check exceed the column limit. | ||||
* | muc.register: Clarify what's going on when enforcing nicknames | Kim Alvefur | 2023-11-03 | 1 | -0/+2 |
| | | | | Does this make it clearer what is going on? | ||||
* | util.datamanager: Clean up list index files on purge (i.e. user deletion) | Kim Alvefur | 2023-11-02 | 1 | -0/+2 |
| | |||||
* | mod_s2s: Automagically enable DANE for s2sin if 'use_dane' is enabled | Kim Alvefur | 2023-11-02 | 1 | -0/+6 |
| | | | | Simplifies configuration, only one already existing boolean to flip. | ||||
* | mod_s2s_auth_dane_in: DANE support for s2sin | Kim Alvefur | 2023-11-01 | 2 | -0/+115 |
| | | | | | Complements the DANE support for outgoing connections included in net.connect | ||||
* | migrator: Add mod_http_file_share example to config template | Kim Alvefur | 2023-11-01 | 1 | -0/+6 |
| | |||||
* | migrator: Update default config template with new stores | Kim Alvefur | 2023-11-01 | 1 | -0/+4 |
| | | | | | | * mod_authz_internal adds account_roles * mod_cron has its state * mod_smacks also has some non-critical state | ||||
* | core.certmanager: Tweak log level of message about SNI being required | Kim Alvefur | 2023-10-29 | 1 | -1/+1 |
| | | | | Everything supports SNI today, so this is not useful information. | ||||
* | mod_bosh: Include stream attributes in stream-features event | Matthew Wild | 2023-10-28 | 1 | -1/+1 |
| | | | | | This matches what mod_c2s does, and fixes a traceback in mod_sasl2_fast when used with BOSH (that module tries to use event.stream.from). | ||||
* | Merge 0.12->trunk | Kim Alvefur | 2023-10-27 | 1 | -1/+4 |
|\ | |||||
| * | core.certmanager: Validate that 'tls_profile' is one of the valid values | Kim Alvefur | 2023-10-27 | 1 | -1/+4 |
| | | | | | | | | A typo should not result in ending up with "legacy" | ||||
* | | mod_saslauth: Clear 'auto' from endpoint hash var, it's not a real hash ↵ | Matthew Wild | 2023-10-26 | 1 | -0/+1 |
| | | | | | | | | (thanks tmolitor) | ||||
* | | mod_saslauth, mod_c2s: Disable tls-server-end-point channel binding by default | Matthew Wild | 2023-10-26 | 2 | -14/+23 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This channel binding method is now enabled when a hash is manually set in the config, or it attempts to discover the hash automatically if the value is the special string "auto". A related change to mod_c2s prevents complicated certificate lookups in the client connection hot path - this work now happens only when this channel binding method is used. I'm not aware of anything else that uses ssl_cfg (vs ssl_ctx). Rationale for disabling by default: - Minor performance impact in automatic cert detection - This method is weak against a leaked/stolen private key (other methods such as 'tls-exporter' would not be compromised in such a case) Rationale for keeping the implementation: - For some deployments, this may be the only method available (e.g. due to TLS offloading in another process/server). | ||||
* | | mod_saslauth: Fix traceback in tls-server-end-point channel binding | Matthew Wild | 2023-10-26 | 1 | -3/+8 |
| | | |||||
* | | mod_admin_shell: Make 'Role' column dynamically sized | Kim Alvefur | 2023-10-26 | 1 | -1/+1 |
| | | | | | | | | | | | | | | Some of the new roles don't quite fit nicely into 4 characters (excluding ellipsis). Given the ability to dynamically add additional roles from the config and possibly from modules, it seems better to just make it a relative size since we can't know how long they will be. | ||||
* | | mod_saslauth: Actively close cert file after reading | Matthew Wild | 2023-10-24 | 1 | -0/+1 |
| | | | | | | | | Explicit > implicit | ||||
* | | mod_saslauth: Fix read format string (thanks tmolitor) | Matthew Wild | 2023-10-24 | 1 | -1/+1 |
| | | |||||
* | | mod_cron: Make task frequencies configurable in overly generic manner | Kim Alvefur | 2023-10-22 | 3 | -10/+10 |
| | | | | | | | | Requested feature for many modules, notably MAM and file sharing. | ||||
* | | mod_cron: Fix missing restore method in Teal record definition | Kim Alvefur | 2023-10-22 | 1 | -0/+1 |
| | | |||||
* | | CHANGES: Mention 'tls-server-end-point' | Kim Alvefur | 2023-10-22 | 1 | -0/+1 |
| | | |||||
* | | mod_saslauth: Get correct 'tls-server-end-point' with new LuaSec API | Kim Alvefur | 2022-10-23 | 1 | -12/+15 |
| | | | | | | | | | | | | MattJ contributed new APIs for retrieving the actually used certificate and chain to LuaSec, which are not in a release at the time of this commit. | ||||
* | | mod_c2s: Add session.ssl_cfg/ssl_ctx for direct TLS connections | Matthew Wild | 2022-09-07 | 1 | -0/+8 |
| | | |||||
* | | portmanager: Expose API to get at SSL/TLS config for a given interface/port | Matthew Wild | 2022-09-07 | 1 | -0/+8 |
| | | |||||
* | | mod_saslauth: Derive hash from certificate per tls-server-end-point | Kim Alvefur | 2021-06-29 | 1 | -0/+34 |
| | | | | | | | | | | | | | | | | | | | | | | This originally used a WIP implementation of cert:sigalg(), a method to retrieve certificate signature algorithm, but it was never submitted upstream. https://github.com/Zash/luasec/tree/zash/sigalg cert:getsignaturename() was merged in https://github.com/brunoos/luasec/commit/de393417b7c7566caf1e0a0ad54132942ac4f049 XEP-0440 v0.3.0 made implementing tls-server-end-point a MUST | ||||
* | | mod_saslauth: Support tls-server-end-point via manually specified hash | Kim Alvefur | 2020-12-07 | 1 | -0/+13 |
| | | | | | | | | | | | | | | | | Since this channel binding method is said to enable TLS offloading then you need tell Prosody the hash (or the full cert), so this seems like a good start. Support is RECOMMENDED in XEP-0440 version 0.2 | ||||
* | | mod_tokenauth: Set name/description on cleanup job | Kim Alvefur | 2023-10-21 | 1 | -1/+1 |
| | | |||||
* | | mod_tokenauth: Save grant after removing expired tokens | Kim Alvefur | 2023-10-21 | 1 | -0/+5 |
| | | | | | | | | Ensures the periodic cleanup really does remove expired tokens. | ||||
* | | mod_tokenauth: Periodically clear out expired tokens and grants | Kim Alvefur | 2023-10-09 | 1 | -0/+6 |
| | | | | | | | | This should ensure expired grants eventually disappear. | ||||
* | | mod_tokenauth: Delete grants without tokens after period | Kim Alvefur | 2023-10-16 | 1 | -0/+8 |
| | | | | | | | | | | | | | | | | | | | | Generally it is expected that a grant would have at least one token as long as the grant is in active use. Refresh tokens issued by mod_http_oauth2 have a lifetime of one week by default, so the idea here is that if that refresh token expired and another week goes by without the grant being used, then the whole grant can be removed. | ||||
* | | mod_tokenauth: Clear expired tokens on grant retrieval | Kim Alvefur | 2023-10-09 | 1 | -1/+8 |
| | | |||||
* | | mod_tokenauth: Delete grants in the wrong formats on retrieval | Kim Alvefur | 2023-10-09 | 1 | -0/+5 |
| | | |||||
* | | lint: Teach luacheck about module:once | Kim Alvefur | 2023-10-15 | 1 | -0/+1 |
| | | | | | | | | Silence warning for using this introduced in 9c62ffbdf2ae | ||||
* | | mod_cron: Remove unused import [luacheck] | Kim Alvefur | 2023-10-15 | 2 | -2/+0 |
| | | | | | | | | Use of datetime was removed in 6ac5ad578565 | ||||
* | | Merge 0.12->trunk | Kim Alvefur | 2023-10-15 | 1 | -1/+1 |
|\| | |||||
| * | mod_muc_mam: Improve wording of enable setting | Kim Alvefur | 2023-10-15 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | | Suggested by jstein in the chat This option label is used by XMPP clients to explain what the option does. a) The user should know where the data is archived. b) The user needs a statement that can be enabled/disabled by the variable. A question would have the wrong logic here. | ||||
| * | Added tag 0.12.4 for changeset a2ba3f06dcf4 | Kim Alvefur | 2023-09-05 | 0 | -0/+0 |
| | |