From 0915bd786b24bfbdcdb31919a6c6836e4c89a6f0 Mon Sep 17 00:00:00 2001 From: Matthew Wild Date: Wed, 15 Apr 2020 15:35:38 +0100 Subject: [PATCH] XEP-0333: Amend XEP-0359 security note per feedback from Florian --- xep-0333.xml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/xep-0333.xml b/xep-0333.xml index 16fee66f..35762045 100644 --- a/xep-0333.xml +++ b/xep-0333.xml @@ -253,10 +253,9 @@ the MUC-assigned id for Chat Markers. The id will be contained in a <stanza-id> element inserted into the stanza with a 'by' attribute matching the MUC's own JID.

-

As per XEP-0359 security considerations, clients MUST only trust a <stanza-id> - element with a 'by' attribute that matches the MUC's own JID, and MUST ignore any such - element in MUCs that do not announce XEP-0359 support.

- +

As per XEP-0359 security considerations, if XEP-0359 support is not announced then + <stanza-id/> elements with a 'by' attribute that match the MUC's own JID should + be considered spoofed and MUST be ignored.