view plugins/mod_auth_insecure.lua @ 14157:f881ed0ee8bd 0.12

moduleapi: Use multitable add/remove instead of set multitable:set() does not clear intermediate keys when setting the last one to nil. This meant that the event_handlers multitable for every module was not properly cleaning up the object and event name from the table when calling :unhook_object_event(). This combined badly with e.g. mod_bookmarks, which uses this extensively to add/remove hooks dynamically for mod_pep services. The multitable kept a reference to every mod_pep service object ever created, causing a memory leak. The multitable:remove() function clears intermediate keys when they are empty, so we've switched to using that now.
author Matthew Wild <mwild1@gmail.com>
date Fri, 17 Apr 2026 17:39:06 +0100
parents 0d7d71dee0a0
children 32881d0c359f
line wrap: on
line source

-- Prosody IM
-- Copyright (C) 2008-2010 Matthew Wild
-- Copyright (C) 2008-2010 Waqas Hussain
--
-- This project is MIT/X11 licensed. Please see the
-- COPYING file in the source package for more information.
--
-- luacheck: ignore 212

local datamanager = require "util.datamanager";
local new_sasl = require "util.sasl".new;
local saslprep = require "util.encodings".stringprep.saslprep;

local host = module.host;
local provider = { name = "insecure" };

assert(module:get_option_string("insecure_open_authentication") == "Yes please, I know what I'm doing!");

function provider.test_password(username, password)
	return true;
end

function provider.set_password(username, password)
	local account = datamanager.load(username, host, "accounts");
	password = saslprep(password);
	if not password then
		return nil, "Password fails SASLprep.";
	end
	if account then
		account.password = password;
		return datamanager.store(username, host, "accounts", account);
	end
	return nil, "Account not available.";
end

function provider.user_exists(username)
	return true;
end

function provider.create_user(username, password)
	return datamanager.store(username, host, "accounts", {password = password});
end

function provider.delete_user(username)
	return datamanager.store(username, host, "accounts", nil);
end

function provider.get_sasl_handler()
	local getpass_authentication_profile = {
		plain_test = function(sasl, username, password, realm)
			return true, true;
		end
	};
	return new_sasl(module.host, getpass_authentication_profile);
end

module:add_item("auth-provider", provider);