# HG changeset patch # User Kim Alvefur # Date 1527275374 -7200 # Node ID 29c6d2681bad9f67d8bd548bb3a7973473bae91e # Parent 986c3e22ec3241ed5c9d355664a901dc4defbbd6 mod_c2s: Do not allow the stream 'to' to change across stream restarts (fixes #1147) diff -r 986c3e22ec32 -r 29c6d2681bad plugins/mod_c2s.lua --- a/plugins/mod_c2s.lua Wed Jan 10 15:15:25 2018 +0000 +++ b/plugins/mod_c2s.lua Fri May 25 21:09:34 2018 +0200 @@ -40,12 +40,19 @@ function stream_callbacks.streamopened(session, attr) local send = session.send; - session.host = nameprep(attr.to); - if not session.host then + local host = nameprep(attr.to); + if not host then session:close{ condition = "improper-addressing", text = "A valid 'to' attribute is required on stream headers" }; return; end + if not session.host then + session.host = host; + elseif session.host ~= host then + session:close{ condition = "not-authorized", + text = "The 'to' attribute must remain the same across stream restarts" }; + return; + end session.version = tonumber(attr.version) or 0; session.streamid = uuid_generate(); (session.log or session)("debug", "Client sent opening to %s", session.host);