From 157aad019add1e986676611d024f416c6975e7c3 Mon Sep 17 00:00:00 2001 From: Georg Lukas Date: Tue, 12 Dec 2017 17:45:38 +0100 Subject: [PATCH] =?UTF-8?q?XEP-0379:=20fix=20=C2=A75.4=20anchor?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- xep-0379.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/xep-0379.xml b/xep-0379.xml index be50d7db..b2f77dcc 100644 --- a/xep-0379.xml +++ b/xep-0379.xml @@ -322,7 +322,7 @@ https://juicyxmpp.example/i/#romeo@montague.net?preauth=1tMFqYDdKhfe2pwp;name=Ro and provide an easy mechanism to remove them and cancel their subscription.

- +

An attacker can lure the user by providing an invitation link with a 'name' parameter that does not match the JID. Therefore, a client SHOULD always display both the JID and the proposed display name when adding a