Hi,

I've mentioned it already once here in this mailing list:

I've had trouble connecting (and authenticating) through Openfire's BOSH 
implementation, when I don't know Openfire's domain, but only its IP address or 
hostname (which might be different to the domain name).

It turned out, that Openfire did not send a "from" attribute in its initial 
BOSH session response, leaving me unknown about the domain name.

However the domain name is required by (at least) DIGEST-MD5 authentication.

Eventually I could only connect, if I know the domain name before connecting.

Therefore I think the "from" attribute must be included. It should be: "it MUST 
forward the identity to the client by including a 'from' attribute in a 
response" (instead of MAY).

Another reason: The core spec says:
"For response stream headers in both client-to-server and server-to-server 
communication, the receiving entity MUST include the 'from' attribute"
(http://xmpp.org/rfcs/rfc6120.html#streams-attr-from)

Christian

Am 27.01.2014 um 16:21 schrieb Winfried Tilanus:

> Hi,
> 
> These patches close the last open issues in XEP-0124 and XEP-0206. As far
> as I can see, these are the last changes to be made before they can be moved
> to final.
> 
> have fun!
> 
> Winfried
> 

Reply via email to