Mercurial > prosody-hg
annotate net/httpserver.lua @ 14159:4bbb17445ed9 0.12 0.12.6
mod_proxy65: Consistently apply authorization checks
The module checked for authorization when a client asked for the address:port
of the proxy service. It did not check for authorization when processing a
request to activate a bytestream. This meant that any unauthenticated party
able to guess the IP/port and XMPP domain of a proxy65 service (generally low
difficulty) would be able to use the proxy to relay traffic between two
connections.
This factors out the permission check, and applies it to every request type.
| author | Matthew Wild <mwild1@gmail.com> |
|---|---|
| date | Wed, 29 Apr 2026 11:40:43 +0100 |
| parents | adc17a2bd6fd |
| children | ba409c67353b |
| rev | line source |
|---|---|
|
4784
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
1 -- COMPAT w/pre-0.9 |
|
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
2 local log = require "util.logger".init("net.httpserver"); |
|
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
3 local traceback = debug.traceback; |
|
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
4 |
|
6780
647adfd8f738
net.*: Remove use of module() function
Kim Alvefur <zash@zash.se>
parents:
4797
diff
changeset
|
5 local _ENV = nil; |
|
8555
4f0f5b49bb03
vairious: Add annotation when an empty environment is set [luacheck]
Kim Alvefur <zash@zash.se>
parents:
7359
diff
changeset
|
6 -- luacheck: std none |
|
4784
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
7 |
|
8679
adc17a2bd6fd
net.httpserver: Make function local, fixes loading since there is no environment [luacheck]
Kim Alvefur <zash@zash.se>
parents:
8555
diff
changeset
|
8 local function fail() |
|
7359
a5a080c12c96
Update every link to the documentation to use HTTPS
Emmanuel Gil Peyrot <linkmauve@linkmauve.fr>
parents:
6780
diff
changeset
|
9 log("error", "Attempt to use legacy HTTP API. For more info see https://prosody.im/doc/developers/legacy_http"); |
|
4784
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
10 log("error", "Legacy HTTP API usage, %s", traceback("", 2)); |
|
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
11 end |
|
e10b623ccecb
net.httpserver: Add compatibility stub
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
12 |
|
6780
647adfd8f738
net.*: Remove use of module() function
Kim Alvefur <zash@zash.se>
parents:
4797
diff
changeset
|
13 return { |
|
647adfd8f738
net.*: Remove use of module() function
Kim Alvefur <zash@zash.se>
parents:
4797
diff
changeset
|
14 new = fail; |
|
647adfd8f738
net.*: Remove use of module() function
Kim Alvefur <zash@zash.se>
parents:
4797
diff
changeset
|
15 new_from_config = fail; |
|
647adfd8f738
net.*: Remove use of module() function
Kim Alvefur <zash@zash.se>
parents:
4797
diff
changeset
|
16 set_default_handler = fail; |
|
647adfd8f738
net.*: Remove use of module() function
Kim Alvefur <zash@zash.se>
parents:
4797
diff
changeset
|
17 }; |
