Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | mod_saslauth: Use a defined SASL error | Kim Alvefur | 2021-03-18 | 1 | -1/+1 |
| | |||||
* | mod_saslauth: Improve code style | Kim Alvefur | 2021-03-18 | 1 | -1/+3 |
| | | | | | | This many returns deserve their own line. `session["sasl_handler"]` style isn't used anywhere else. | ||||
* | mod_saslauth: Don't throw errors in async code when connections are gone | tmolitor | 2021-03-18 | 1 | -0/+1 |
| | | | | Fixes #1515 | ||||
* | mod_saslauth: Only advertise channel binding if a finished message is available | Kim Alvefur | 2020-11-23 | 1 | -1/+1 |
| | | | | In some cases this method returns nothing, unclear why. | ||||
* | mod_saslauth: Disable 'tls-unique' channel binding with TLS 1.3 (closes #1542) | Kim Alvefur | 2020-11-23 | 1 | -1/+4 |
| | | | | | | | | The 'tls-unique' channel binding is undefined in TLS 1.3 according to a single sentence in parenthesis in Apendix C of RFC 8446 This may trigger downgrade protection in clients that were expecting channel binding to be available. | ||||
* | mod_saslauth: Ignore unused argument [luacheck] | Kim Alvefur | 2018-02-04 | 1 | -1/+1 |
| | |||||
* | mod_saslauth: Use renamed API for hooking non-stanzas | Kim Alvefur | 2018-02-04 | 1 | -1/+1 |
| | |||||
* | mod_saslauth: Pass SASL EXTERNAL failure reason on to be used in error bounces | Kim Alvefur | 2018-02-04 | 1 | -1/+2 |
| | |||||
* | mod_saslauth: Close connection if no fallback kicks in on SASL EXTERNAL failure | Kim Alvefur | 2018-02-04 | 1 | -1/+3 |
| | |||||
* | Backed out changeset 89c42aff8510: The problem in ejabberd has reportedly ↵ | Kim Alvefur | 2018-02-04 | 1 | -2/+4 |
| | | | | been resolved and this change causes more problems than it solves (fixes #1006) | ||||
* | mod_saslauth: Log which mechanisms are offered | Kim Alvefur | 2017-12-21 | 1 | -0/+1 |
| | |||||
* | mod_saslauth: Remove unused argument [luacheck] | Kim Alvefur | 2017-04-01 | 1 | -1/+1 |
| | |||||
* | mod_saslauth: Fix typoed variable name [luacheck] | Kim Alvefur | 2017-03-06 | 1 | -1/+1 |
| | |||||
* | mod_saslauth: Switch to hook_tag from hook_stanza which was renamed in ↵ | Kim Alvefur | 2017-03-06 | 1 | -3/+3 |
| | | | | 2087d42f1e77 | ||||
* | Merge 0.9->0.10 | Kim Alvefur | 2017-03-02 | 1 | -2/+13 |
|\ | |||||
| * | mod_saslauth: Log SASL failure reason | Kim Alvefur | 2017-03-02 | 1 | -2/+13 |
| | | |||||
* | | mod_saslauth: Ignore shadowing of logger [luacheck] | Kim Alvefur | 2017-02-15 | 1 | -1/+1 |
| | | |||||
* | | mod_saslauth: Improve logging as to why when SASL is not offered | Kim Alvefur | 2017-02-15 | 1 | -3/+11 |
| | | |||||
* | | mod_saslauth: Cache logger in local for less typing | Kim Alvefur | 2017-02-15 | 1 | -1/+2 |
| | | |||||
* | | core.sessionmanager, mod_saslauth: Introduce intermediate session type for ↵ | Kim Alvefur | 2016-12-13 | 1 | -1/+1 |
| | | | | | | | | authenticated but unbound sessions so that resource binding is not treated as a normal stanza | ||||
* | | mod_saslauth: Disable DIGEST-MD5 by default (closes #515) | Kim Alvefur | 2016-03-18 | 1 | -1/+1 |
| | | |||||
* | | mod_saslauth: Make it easier to support multiple channel binding methonds | Kim Alvefur | 2014-11-19 | 1 | -2/+4 |
| | | |||||
* | | mod_saslauth: Break out tls-unique channel binding callback so it is ↵ | Kim Alvefur | 2014-11-19 | 1 | -5/+10 |
| | | | | | | | | instantiated once | ||||
* | | mod_saslauth: Keep sasl_handler in a local variable | Kim Alvefur | 2014-11-19 | 1 | -5/+6 |
| | | |||||
* | | mod_saslauth: Better name for config option | Kim Alvefur | 2014-10-21 | 1 | -1/+1 |
| | | |||||
* | | mod_saslauth: Make it possible to disable certain mechanisms | Kim Alvefur | 2014-10-21 | 1 | -1/+5 |
| | | |||||
* | | mod_saslauth: Add LOGIN to mechanisms not allowed over unencrypted ↵ | Kim Alvefur | 2014-10-21 | 1 | -1/+1 |
| | | | | | | | | connections as it may be offered by 3rd party authentication plugins | ||||
* | | mod_saslauth: Use a configurable set of mechanisms to not allow over ↵ | Kim Alvefur | 2014-10-21 | 1 | -2/+3 |
| | | | | | | | | unencrypted connections | ||||
* | | mod_saslauth: Log warning if no SASL mechanisms were offered | Kim Alvefur | 2014-10-21 | 1 | -1/+5 |
| | | |||||
* | | mod_saslauth: Use type-specific config option getters | Kim Alvefur | 2014-10-21 | 1 | -2/+2 |
| | | |||||
* | | mod_legacyauth, mod_saslauth, mod_tls: Pass require_encryption as default ↵ | Kim Alvefur | 2014-10-21 | 1 | -1/+1 |
| | | | | | | | | option to s2s_require_encryption so the later overrides the former | ||||
* | | mod_saslauth: Fix encoding of missing vs empty SASL reply messages | Kim Alvefur | 2014-09-23 | 1 | -7/+7 |
| | | |||||
* | | mod_saslauth: Stricter SASL EXTERNAL handling more in line with XEP-0178 | Kim Alvefur | 2014-09-23 | 1 | -51/+30 |
| | | |||||
* | | mod_dialback, mod_saslauth: Remove broken fallback to dialback on SASL ↵ | Kim Alvefur | 2014-09-23 | 1 | -4/+2 |
| | | | | | | | | EXTERNAL failure | ||||
* | | mod_lastactivity, mod_legacyauth, mod_presence, mod_saslauth, mod_tls: Use ↵ | Kim Alvefur | 2014-07-04 | 1 | -1/+1 |
| | | | | | | | | the newer stanza:get_child APIs and optimize away some table lookups | ||||
* | | Merge 0.9->0.10 | Kim Alvefur | 2014-03-25 | 1 | -1/+1 |
|\| | |||||
| * | mod_saslauth: Only do c2s SASL on normal VirtualHosts | Kim Alvefur | 2014-03-22 | 1 | -1/+1 |
| | | |||||
* | | mod_saslauth: Make sure sasl handler has add_cb_handler (fixes #392) | Kim Alvefur | 2014-02-12 | 1 | -1/+1 |
| | | |||||
* | | mod_saslauth: Collect data for channel binding only if we know for sure that ↵ | Kim Alvefur | 2013-10-07 | 1 | -1/+1 |
| | | | | | | | | the stream is encrypted | ||||
* | | Merge Tobias SCRAM-PLUS work | Kim Alvefur | 2013-09-22 | 1 | -0/+10 |
|\ \ | |||||
| * | | mod_saslauth: Check whether LuaSec supports getpeerfinished() binding. | Tobias Markmann | 2011-01-17 | 1 | -4/+8 |
| | | | |||||
| * | | mod_saslauth: Add channel binding handler for tls-unique channel binding. | Tobias Markmann | 2011-01-17 | 1 | -1/+3 |
| | | | |||||
| * | | mod_saslauth: Set secure socket as SASL object user data for secure sessions. | Tobias Markmann | 2011-01-17 | 1 | -0/+4 |
| | | | |||||
* | | | Remove all trailing whitespace | Florian Zeitz | 2013-08-09 | 1 | -1/+1 |
| |/ |/| | |||||
* | | mod_saslauth, mod_compression: Fix some cases where open_stream() was not ↵ | Matthew Wild | 2013-04-29 | 1 | -1/+1 |
| | | | | | | | | being passed to/from (see df3c78221f26 and issue #338) | ||||
* | | s2smanager, mod_s2s, mod_dialback, mod_saslauth: Move ↵ | Matthew Wild | 2013-03-22 | 1 | -3/+2 |
| | | | | | | | | s2smanager.make_authenticated() to mod_s2s, and plugins now signal authentication via the s2s-authenticated event | ||||
* | | mod_s2s, mod_saslauth, mod_compression: Refactor to have common code for ↵ | Kim Alvefur | 2013-03-16 | 1 | -5/+1 |
| | | | | | | | | opening streams | ||||
* | | mod_saslauth: Pass session to usermanager.get_sasl_handler() | Matthew Wild | 2012-07-04 | 1 | -2/+2 |
| | | |||||
* | | mod_saslauth: Remove unused declaration of xmlns_stanzas | Matthew Wild | 2012-04-28 | 1 | -1/+0 |
| | | |||||
* | | mod_saslauth: Remove useless import of, and call to nodeprep. | Kim Alvefur | 2012-02-12 | 1 | -3/+0 |
| | |