-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 7/15/09 4:44 PM, Fabio Forno wrote: > On Thu, Jul 16, 2009 at 12:38 AM, Peter Saint-Andre<[email protected]> wrote: >> It's not clear how many server codebases follow RFC 3921 about blocking >> jabber:iq:roster packets, but if we're going to remove that restriction >> (it seems we have consensus) then start filing bug reports and feature >> requests with your favorite server codebases and I would bet they will >> fix this before draft-ietf-xmpp-3921bis becomes an RFC. :) > > What about clients that don't check the from, which is legit since > they trust the server? For them we introduce a temporary security > issue
Good point. Hmm. Maybe we need urn:xmpp:roster after all... Peter - -- Peter Saint-Andre https://stpeter.im/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.8 (Darwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAkpeXXQACgkQNL8k5A2w/vxU+wCffUlMIYtV/qZdr6qD2XJUd1zH 1YkAnA33zwTUsmQIusi+tmqezRljp9qa =zKB/ -----END PGP SIGNATURE-----
