-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 7/15/09 4:44 PM, Fabio Forno wrote:
> On Thu, Jul 16, 2009 at 12:38 AM, Peter Saint-Andre<[email protected]> wrote:
>> It's not clear how many server codebases follow RFC 3921 about blocking
>> jabber:iq:roster packets, but if we're going to remove that restriction
>> (it seems we have consensus) then start filing bug reports and feature
>> requests with your favorite server codebases and I would bet they will
>> fix this before draft-ietf-xmpp-3921bis becomes an RFC. :)
> 
> What about clients that don't check the from, which is legit since
> they trust the server?  For them we introduce a temporary security
> issue

Good point. Hmm. Maybe we need urn:xmpp:roster after all...

Peter

- --
Peter Saint-Andre
https://stpeter.im/


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkpeXXQACgkQNL8k5A2w/vxU+wCffUlMIYtV/qZdr6qD2XJUd1zH
1YkAnA33zwTUsmQIusi+tmqezRljp9qa
=zKB/
-----END PGP SIGNATURE-----

Reply via email to