#1254 Enforce from check on delay tags

Reporter lovetox
Owner Nobody
Stars ★★ (2)
  • Compliance
  • Type-Defect
  • Status-New
  • Priority-Medium
  1. lovetox on

    Please provide a snippet of the part of the specification which we violate if possible: .. Although the recipient's server SHOULD discard a delayed delivery notation whose 'from' attribute matches the server's JabberID (or return a <not-acceptable/> error to the originator).. Please provide a link to the specification: https://xmpp.org/extensions/xep-0203.html As a client developer i want to trust a server added delay and distrust a client added delay. If the "from" is not sanitized, it means i have to distrust all delays, which means i have to show offline messages received in the same way as when a user sends a delayed message.

New comment

Not published. Used for spam prevention and optional update notifications.