Closed shred closed 5 years ago
LGTM! Set EJABBERD_REGISTER_ADMIN_ONLY
to true
is fine for me and a good time to start with a changelog to communicate the breaking downward compatibility. Maybe in another PR?
I will prepare another PR for EJABBERD_REGISTER_ADMIN_ONLY
then.
This PR essentially only contains a bugfix. Can you merge it?
Thanks for your contribution!
EJABBERD_REGISTER_TRUSTED_NETWORK_ONLY
totrue
by default, as it is claimed in the documentation.EJABBERD_MUC_CREATE_ADMIN_ONLY
andEJABBERD_REGISTER_ADMIN_ONLY
as further options to secure the server.This pull request addresses issue #192. I explicitly do not claim that this PR fixes the open relay issue, or hardens the server against attacks. Please review this PR.
@rroemhild: I would prefer to set
EJABBERD_REGISTER_ADMIN_ONLY
totrue
by default, so the default configuration is most restrictive. However this would break downward compatibility. What do you think?