IMPORTANT: due to a drive failure, as of 13-Mar-2021, the Mercurial repository had to be re-mirrored, which changed every commit SHA. The old SHAs and trees are backed up in the vault branches. Please migrate to the new branches as soon as you can.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
prosody/plugins/mod_auth_anonymous.lua

78 lines
2.0 KiB

-- Prosody IM
-- Copyright (C) 2008-2010 Matthew Wild
-- Copyright (C) 2008-2010 Waqas Hussain
--
-- This project is MIT/X11 licensed. Please see the
-- COPYING file in the source package for more information.
--
-- luacheck: ignore 212
local new_sasl = require "prosody.util.sasl".new;
local datamanager = require "prosody.util.datamanager";
local hosts = prosody.hosts;
local allow_storage = module:get_option_boolean("allow_anonymous_storage", false);
-- define auth provider
local provider = {};
function provider.test_password(username, password)
return nil, "Password based auth not supported.";
end
function provider.get_password(username)
return nil, "Password not available.";
end
function provider.set_password(username, password)
return nil, "Password based auth not supported.";
end
function provider.user_exists(username)
return nil, "Only anonymous users are supported."; -- FIXME check if anonymous user is connected?
end
function provider.create_user(username, password)
return nil, "Account creation/modification not supported.";
end
function provider.get_sasl_handler()
local anonymous_authentication_profile = {
anonymous = function(sasl, username, realm)
return true; -- for normal usage you should always return true here
end
};
return new_sasl(module.host, anonymous_authentication_profile);
end
function provider.users()
return next, hosts[module.host].sessions, nil;
end
-- datamanager callback to disable writes
local function dm_callback(username, host, datastore, data)
if host == module.host then
return false;
end
return username, host, datastore, data;
end
if not module:get_option_boolean("allow_anonymous_s2s", false) then
module:hook("route/remote", function (event)
return false; -- Block outgoing s2s from anonymous users
end, 300);
end
function module.load()
if not allow_storage then
datamanager.add_callback(dm_callback);
end
end
function module.unload()
if not allow_storage then
datamanager.remove_callback(dm_callback);
end
end
module:provides("auth", provider);