Opened 6 years ago

Closed 6 years ago

#5787 closed defect (fixed)

Gajim makes public the room bookmarks including the passwords

Reported by: naw <lambda512@…> Owned by:
Priority: normal Milestone: 0.14
Component: None Version: 0.13.4
Severity: major Keywords:
Cc: Blocked By:
Blocking: OS: All

Description

Bug description

When gajim is connected to an ejabberd server and you modify the room bookmarks, the bookmarks seems to be saved in private and in public. The information *includes the room passwords*.

I could replicate this in two ejabberd 2.1.x servers (jabberes.org and brauchen.info)

I couldn't replicate the problem with other server implementations (tigase, prosody, m-link)

Steps to reproduce

Connect to a ejabberd server Edit the MUC bookmarks Your contacts will get notified of the changes

Software versions

OS version: Archlinux
GTK version: 2.20.1
PyGTK version: 2.17.0

Change History (5)

comment:1 Changed 6 years ago by anonymous

I can't upload the traffic dumps as files (akismet thinks that its spam) so I upload it to pastebin.

XML dump from gajim http://pastebin.com/AXH4WByG XML seen by contacts http://pastebin.com/PhTJytit

comment:2 Changed 6 years ago by asterix

on which ejabberd installation did you try? I cannot reproduce that with ejabberd 2.1.3 (gajim.org). My contacts don't get my bookmarks.

comment:3 Changed 6 years ago by lambda512@…

I tested with jabberes.org and brauchen.info. Now I tested with gajim.org and could replicate the issue. I'll join the gajim room to discuss it.

comment:4 Changed 6 years ago by Yann Leboulanger <asterix@…>

(In [ec96e9f90375]) stop saving bookmarks in pubsub if server doesn't support #publish-options. see #5787

comment:5 Changed 6 years ago by Yann Leboulanger <asterix@…>

  • Milestone set to 0.14
  • Resolution set to fixed
  • Status changed from new to closed

(In [8d5f212ac020]) delete bookmarks from pubsub if server doesn't support publish-options. Fixes #5787

Note: See TracTickets for help on using tickets.