When user A requests subscription to user B, it enters roster of user B

2 replies [Last post]
Anonymous

How to replicate:
- User A create account
- User B create account
- User A logins
- User B logins
- User A binds resource
- User B binds resource
- User A send presence available
- User B send presence available
- User A sends subscription request to User B
- User B requests its roster : user A is in roster with subscription "none", ask "none".

I believe that User A should not enter the roster at all.

as per RFC6121
3.1.3. Server Processing of Inbound Subscription Request

Security Warning: Until and unless the contact approves the
subscription request as described under Section 3.1.4, the
contact's server MUST NOT add an item for the user to the
contact's roster.

Regards,
Luca.

wojtek's picture
Offline
Joined: 2010-11-24
Points: 1167

This is a known issue however I've added it to our project tracking system: https://projects.tigase.org/issues/663 .

For the future reports please use our bug tracking system - https://projects.tigase.org/ .

Luca (not verified)

Thanks Woitek,
I'm really sorry, I did not know that there was a bug tracker,
I should've searched better....

Luca.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.