view plugins/mod_auth_insecure.lua @ 14181:6fb6e383123f 13.0

util.signal: Fix signalfd closure on non-Linux systems The loop was incorrect for 0-indexed arrays. It started at signalfd_num, which is the total number of signalfds, and decremented to 1 (condition was >0). So if 1 signalfd was registered, it would check only signalfds[1]. At capacity (32 signalfds) it would read past the end of the array. In every case, it would always skip the entry at position [0], leading to a leak. The swap-with-tail removal of the matched item used the post-decrement operator, leading to accessing the array slot just beyond the tail. Finally, it didn't break after finding a match. Probably harmless, but there isn't expected to be more than a single entry per fd, as far as I can tell.
author Matthew Wild <mwild1@gmail.com>
date Mon, 25 May 2026 16:02:39 +0100
parents 74b9e05af71e
children
line wrap: on
line source

-- Prosody IM
-- Copyright (C) 2008-2010 Matthew Wild
-- Copyright (C) 2008-2010 Waqas Hussain
--
-- This project is MIT/X11 licensed. Please see the
-- COPYING file in the source package for more information.
--
-- luacheck: ignore 212

local datamanager = require "prosody.util.datamanager";
local new_sasl = require "prosody.util.sasl".new;
local saslprep = require "prosody.util.encodings".stringprep.saslprep;

local host = module.host;
local provider = { name = "insecure" };

assert(module:get_option_string("insecure_open_authentication") == "Yes please, I know what I'm doing!");

function provider.test_password(username, password)
	return true;
end

function provider.set_password(username, password)
	local account = datamanager.load(username, host, "accounts");
	password = saslprep(password);
	if not password then
		return nil, "Password fails SASLprep.";
	end
	if account then
		account.updated = os.time();
		account.password = password;
		return datamanager.store(username, host, "accounts", account);
	end
	return nil, "Account not available.";
end

function provider.user_exists(username)
	return true;
end

function provider.create_user(username, password)
	local now = os.time();
	return datamanager.store(username, host, "accounts", { created = now; updated = now; password = password });
end

function provider.delete_user(username)
	return datamanager.store(username, host, "accounts", nil);
end

function provider.get_sasl_handler()
	local getpass_authentication_profile = {
		plain_test = function(sasl, username, password, realm)
			return true, true;
		end
	};
	return new_sasl(module.host, getpass_authentication_profile);
end

module:add_item("auth-provider", provider);