alexeycv / pako

Automatically exported from code.google.com/p/pako
3 stars 1 forks source link

"dict add" stores JID instead of nickname #1

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
It may be unsafe to open user's private info

Original issue reported on code.google.com by justda...@gmail.com on 15 Jul 2009 at 11:41

GoogleCodeExporter commented 9 years ago
Dict is a JID-specofoc global dictionary. That's why dict add stores JID 
instead of nick.

Original comment by alexey...@gmail.com on 16 Nov 2009 at 12:32

GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
Don't you think it's a bad design?

Original comment by justda...@gmail.com on 16 Nov 2009 at 3:22

GoogleCodeExporter commented 9 years ago
I'll read dict code and modify it, if I found security problems. May be it will 
be in
output, but it's right thing for a data saving and nothing unsecure.

Thanks for your feedback.

Original comment by alexey...@gmail.com on 16 Nov 2009 at 8:19

GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
I think, if an user has access to "dict add" and knows its destination - he'll 
be
aware of the fact, that dict is a global dictionary, shared all over the 
conference
and everywhere.
Nickname cannot identify the person all over the jabber, however JID can.

Original comment by klich...@gmail.com on 7 Dec 2009 at 11:06

GoogleCodeExporter commented 9 years ago
Ok, it seems I don't know what this dictionary for.
But look how same things are made in other bots.

Original comment by justda...@gmail.com on 7 Dec 2009 at 11:17

GoogleCodeExporter commented 9 years ago

Original comment by alexey...@gmail.com on 3 Mar 2010 at 9:50