Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6d74a56f88 |
@@ -1,27 +1,5 @@
|
|||||||
# Changelog
|
# Changelog
|
||||||
|
|
||||||
## Unreleased 2024-05-05
|
|
||||||
|
|
||||||
### Adjust config
|
|
||||||
|
|
||||||
* Replace deprecated legacy_ssl with c2s_direct_tls.
|
|
||||||
* Removed use_libevent = true. This means the default is now used which is epoll.
|
|
||||||
|
|
||||||
### Test
|
|
||||||
|
|
||||||
Added a test to check that no deprecated config settings are used.
|
|
||||||
|
|
||||||
## v 1.3.3
|
|
||||||
|
|
||||||
* Updated to LuaRocks 3.12.2
|
|
||||||
* Updated to Lua 5.4
|
|
||||||
* Updated to Prosody 0.12.5
|
|
||||||
* Removed unused luarocks
|
|
||||||
|
|
||||||
## v1.3.2
|
|
||||||
|
|
||||||
* Added Firewall module with optional custom blacklist
|
|
||||||
|
|
||||||
## v1.3.1
|
## v1.3.1
|
||||||
|
|
||||||
* Added optional Firewall module for testing
|
* Added optional Firewall module for testing
|
||||||
|
|||||||
+8
-9
@@ -4,11 +4,11 @@ ARG BUILD_DATE
|
|||||||
ARG VCS_REF
|
ARG VCS_REF
|
||||||
ARG VERSION
|
ARG VERSION
|
||||||
|
|
||||||
ARG LUAROCKS_VERSION=3.12.2
|
ARG LUAROCKS_VERSION=3.9.2
|
||||||
ARG PROSODY_VERSION=0.12.5
|
ARG PROSODY_VERSION=0.12.4
|
||||||
|
|
||||||
ARG LUAROCKS_SHA256="b0e0c85205841ddd7be485f53d6125766d18a81d226588d2366931e9a1484492"
|
ARG LUAROCKS_SHA256="bca6e4ecc02c203e070acdb5f586045d45c078896f6236eb46aa33ccd9b94edb"
|
||||||
ARG PROSODY_DOWNLOAD_SHA256="778fb7707a0f10399595ba7ab9c66dd2a2288c0ae3a7fe4ab78f97d462bd399f"
|
ARG PROSODY_DOWNLOAD_SHA256="47d712273c2f29558c412f6cdaec073260bbc26b7dda243db580330183d65856"
|
||||||
|
|
||||||
LABEL luarocks.version="${LUAROCKS_VERSION}"
|
LABEL luarocks.version="${LUAROCKS_VERSION}"
|
||||||
LABEL org.opencontainers.image.authors="Wproject Garapenak"
|
LABEL org.opencontainers.image.authors="Wproject Garapenak"
|
||||||
@@ -30,8 +30,7 @@ RUN apt-get update \
|
|||||||
libidn2-0 \
|
libidn2-0 \
|
||||||
libpq-dev \
|
libpq-dev \
|
||||||
libsqlite3-0 \
|
libsqlite3-0 \
|
||||||
lua5.4 \
|
lua5.2 \
|
||||||
liblua5.4-dev \
|
|
||||||
lua-bitop \
|
lua-bitop \
|
||||||
lua-dbi-mysql \
|
lua-dbi-mysql \
|
||||||
lua-dbi-postgresql \
|
lua-dbi-postgresql \
|
||||||
@@ -74,7 +73,7 @@ RUN buildDeps='gcc git libc6-dev libidn2-dev liblua5.2-dev libsqlite3-dev libssl
|
|||||||
&& make bootstrap \
|
&& make bootstrap \
|
||||||
&& cd / && rm -r /usr/src/luarocks \
|
&& cd / && rm -r /usr/src/luarocks \
|
||||||
\
|
\
|
||||||
# && luarocks install luaevent \
|
&& luarocks install luaevent \
|
||||||
&& luarocks install luadbi \
|
&& luarocks install luadbi \
|
||||||
`#&& luarocks install luadbi-mysql MYSQL_INCDIR=/usr/include/mariadb/` \
|
`#&& luarocks install luadbi-mysql MYSQL_INCDIR=/usr/include/mariadb/` \
|
||||||
&& luarocks install luadbi-sqlite3 \
|
&& luarocks install luadbi-sqlite3 \
|
||||||
@@ -91,7 +90,7 @@ RUN groupadd -r prosody \
|
|||||||
RUN mkdir -p /var/run/prosody/ \
|
RUN mkdir -p /var/run/prosody/ \
|
||||||
&& chown prosody:prosody /var/run/prosody/
|
&& chown prosody:prosody /var/run/prosody/
|
||||||
|
|
||||||
ENV __FLUSH_LOG=yes
|
ENV __FLUSH_LOG yes
|
||||||
|
|
||||||
VOLUME ["/usr/local/var/lib/prosody"]
|
VOLUME ["/usr/local/var/lib/prosody"]
|
||||||
|
|
||||||
@@ -112,7 +111,7 @@ RUN download-prosody-modules.bash \
|
|||||||
smacks `# stream management (XEP-0198)` \
|
smacks `# stream management (XEP-0198)` \
|
||||||
throttle_presence `# presence throttling in CSI` \
|
throttle_presence `# presence throttling in CSI` \
|
||||||
vcard_muc `# XEP-0153: vCard-Based Avatar (MUC)` \
|
vcard_muc `# XEP-0153: vCard-Based Avatar (MUC)` \
|
||||||
#&& docker-prosody-module-pre-install.bash \
|
&& docker-prosody-module-pre-install.bash \
|
||||||
firewall `# anti-spam firewall` \
|
firewall `# anti-spam firewall` \
|
||||||
&& rm -rf "/usr/src/prosody-modules"
|
&& rm -rf "/usr/src/prosody-modules"
|
||||||
RUN echo "TLS_REQCERT allow" >> /etc/ldap/ldap.conf
|
RUN echo "TLS_REQCERT allow" >> /etc/ldap/ldap.conf
|
||||||
|
|||||||
@@ -1,8 +1,7 @@
|
|||||||
plugin_paths = { "/usr/local/lib/prosody/custom-modules/" };
|
plugin_paths = { "/usr/local/lib/prosody/custom-modules/" };
|
||||||
|
|
||||||
-- table of enabled modules
|
-- table of enabled modules
|
||||||
-- local mods_enabled = {
|
local mods_enabled = {
|
||||||
modules_enabled = {
|
|
||||||
-- Generally required
|
-- Generally required
|
||||||
"roster"; -- Allow users to have a roster. Recommended ;)
|
"roster"; -- Allow users to have a roster. Recommended ;)
|
||||||
"saslauth"; -- Authentication for clients and servers. Recommended if you want to log in.
|
"saslauth"; -- Authentication for clients and servers. Recommended if you want to log in.
|
||||||
@@ -49,7 +48,19 @@ modules_enabled = {
|
|||||||
"server_contact_info"; -- This module lets you advertise various contact addresses for your XMPP service via XEP-0157.
|
"server_contact_info"; -- This module lets you advertise various contact addresses for your XMPP service via XEP-0157.
|
||||||
};
|
};
|
||||||
|
|
||||||
-- modules_enabled = mods_enabled;
|
local enabled = os.getenv("ENABLE_FIREWALL") or "false"
|
||||||
|
local spam_blocklist = os.getenv("SPAM_BLOCKLIST") and "/usr/local/etc/prosody/firewall/" .. os.getenv("SPAM_BLOCKLIST") or "module:scripts/spam-blocklists.pfw"
|
||||||
|
|
||||||
|
if(enabled == "true")
|
||||||
|
then
|
||||||
|
table.insert(mods_enabled, "firewall");
|
||||||
|
|
||||||
|
firewall_scripts = {
|
||||||
|
spam_blocklist;
|
||||||
|
}
|
||||||
|
end
|
||||||
|
|
||||||
|
modules_enabled = mods_enabled;
|
||||||
|
|
||||||
-- These modules are auto-loaded, but should you want
|
-- These modules are auto-loaded, but should you want
|
||||||
-- to disable them then uncomment them here:
|
-- to disable them then uncomment them here:
|
||||||
@@ -58,3 +69,4 @@ modules_disabled = {
|
|||||||
-- "c2s"; -- Handle client connections
|
-- "c2s"; -- Handle client connections
|
||||||
-- "s2s"; -- Handle server-to-server connections
|
-- "s2s"; -- Handle server-to-server connections
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
default_storage = "sql"
|
default_storage = "sql"
|
||||||
|
|
||||||
sql = {
|
sql = {
|
||||||
driver = os.getenv("DB_DRIVER") or "SQLite3";
|
driver = os.getenv("DB_DRIVER");
|
||||||
database = os.getenv("DB_DATABASE") or "prosody.sqlite";
|
database = os.getenv("DB_DATABASE");
|
||||||
host = os.getenv("DB_HOST");
|
host = os.getenv("DB_HOST");
|
||||||
port = os.getenv("DB_PORT");
|
port = os.getenv("DB_PORT");
|
||||||
username = os.getenv("DB_USERNAME");
|
username = os.getenv("DB_USERNAME");
|
||||||
|
|||||||
@@ -1,11 +1,8 @@
|
|||||||
local stringy = require "stringy"
|
local stringy = require "stringy"
|
||||||
|
|
||||||
e2e_policy_chat = os.getenv("E2E_POLICY_CHAT") or "required"
|
e2e_policy_chat = os.getenv("E2E_POLICY_CHAT")
|
||||||
e2e_policy_muc = os.getenv("E2E_POLICY_MUC") or "required"
|
e2e_policy_muc = os.getenv("E2E_POLICY_MUC")
|
||||||
|
e2e_policy_whitelist = stringy.split(os.getenv("E2E_POLICY_WHITELIST"), ", ")
|
||||||
local whitelist = os.getenv("E2E_POLICY_WHITELIST") or ""
|
|
||||||
e2e_policy_whitelist = stringy.split(whitelist, ", ")
|
|
||||||
|
|
||||||
e2e_policy_message_optional_chat = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for conversations on this server."
|
e2e_policy_message_optional_chat = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for conversations on this server."
|
||||||
e2e_policy_message_required_chat = "For security reasons, OMEMO, OTR or PGP encryption is required for conversations on this server."
|
e2e_policy_message_required_chat = "For security reasons, OMEMO, OTR or PGP encryption is required for conversations on this server."
|
||||||
e2e_policy_message_optional_muc = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for MUC on this server."
|
e2e_policy_message_optional_muc = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for MUC on this server."
|
||||||
|
|||||||
@@ -1,29 +1,12 @@
|
|||||||
local stringy = require "stringy"
|
local stringy = require "stringy"
|
||||||
local function _split(s, sep)
|
|
||||||
if not s then return nil; end
|
|
||||||
sep = sep or ",";
|
|
||||||
local parts = {};
|
|
||||||
for part in s:gmatch("[^"..sep.."]+") do
|
|
||||||
parts[#parts+1] = part;
|
|
||||||
end
|
|
||||||
return parts;
|
|
||||||
end
|
|
||||||
|
|
||||||
local domain = os.getenv("DOMAIN")
|
|
||||||
local abuse = os.getenv("SERVER_CONTACT_INFO_ABUSE") or "xmpp:abuse@" .. domain
|
|
||||||
local admin = os.getenv("SERVER_CONTACT_INFO_ADMIN") or "xmpp:admin@" .. domain
|
|
||||||
local feedback = os.getenv("SERVER_CONTACT_INFO_FEEDBACK") or "xmpp:feedback@" .. domain
|
|
||||||
local sales = os.getenv("SERVER_CONTACT_INFO_SALES") or "xmpp:sales@" .. domain
|
|
||||||
local security = os.getenv("SERVER_CONTACT_INFO_SECURITY") or "xmpp:security@" .. domain
|
|
||||||
local support = os.getenv("SERVER_CONTACT_INFO_SUPPORT") or "xmpp:support@" .. domain
|
|
||||||
|
|
||||||
contact_info = {
|
contact_info = {
|
||||||
abuse = _split(abuse, ", ");
|
abuse = stringy.split(os.getenv("SERVER_CONTACT_INFO_ABUSE"), ", ");
|
||||||
admin = _split(admin, ", ");
|
admin = stringy.split(os.getenv("SERVER_CONTACT_INFO_ADMIN"), ", ");
|
||||||
feedback = _split(feedback, ", ");
|
feedback = stringy.split(os.getenv("SERVER_CONTACT_INFO_FEEDBACK"), ", ");
|
||||||
sales = _split(sales, ", ");
|
sales = stringy.split(os.getenv("SERVER_CONTACT_INFO_SALES"), ", ");
|
||||||
security = _split(security, ", ");
|
security = stringy.split(os.getenv("SERVER_CONTACT_INFO_SECURITY"), ", ");
|
||||||
support = _split(support, ", ");
|
support = stringy.split(os.getenv("SERVER_CONTACT_INFO_SUPPORT"), ", ");
|
||||||
}
|
}
|
||||||
|
|
||||||
welcome_message = "Kaixo $username, ongi etorri $host IM zerbitzura! Mesedez irakurri itzazu ondorengo <a href='https://lainoa.eus/terms/tos.html'>Erabilpen baldintzak</a>."
|
welcome_message = "Kaixo $username, ongi etorri $host IM zerbitzura! Mesedez irakurri itzazu ondorengo <a href='https://lainoa.eus/terms/tos.html'>Erabilpen baldintzak</a>."
|
||||||
|
|||||||
@@ -1,15 +1,16 @@
|
|||||||
local domain = os.getenv("DOMAIN")
|
local domain = os.getenv("DOMAIN")
|
||||||
local domain_http_upload = os.getenv("DOMAIN_HTTP_UPLOAD") or "upload." .. domain
|
local domain_http_upload = os.getenv("DOMAIN_HTTP_UPLOAD")
|
||||||
local domain_muc = os.getenv("DOMAIN_MUC") or "conference." .. domain
|
local domain_muc = os.getenv("DOMAIN_MUC")
|
||||||
local domain_proxy = os.getenv("DOMAIN_PROXY") or "proxy." .. domain
|
local domain_proxy = os.getenv("DOMAIN_PROXY")
|
||||||
local domain_pubsub = os.getenv("DOMAIN_PUBSUB") or "pubsub." .. domain
|
local domain_pubsub = os.getenv("DOMAIN_PUBSUB")
|
||||||
|
|
||||||
-- XEP-0368: SRV records for XMPP over TLS
|
-- XEP-0368: SRV records for XMPP over TLS
|
||||||
-- https://compliance.conversations.im/test/xep0368/
|
-- https://compliance.conversations.im/test/xep0368/
|
||||||
c2s_direct_tls_ssl = {
|
legacy_ssl_ssl = {
|
||||||
certificate = "certs/" .. domain .. "/fullchain.pem";
|
certificate = "certs/" .. domain .. "/fullchain.pem";
|
||||||
key = "certs/" .. domain .. "/privkey.pem";
|
key = "certs/" .. domain .. "/privkey.pem";
|
||||||
}
|
}
|
||||||
c2s_direct_tls_ports = { 5223 }
|
legacy_ssl_ports = { 5223 }
|
||||||
|
|
||||||
-- https://prosody.im/doc/certificates#service_certificates
|
-- https://prosody.im/doc/certificates#service_certificates
|
||||||
-- https://prosody.im/doc/ports#ssl_configuration
|
-- https://prosody.im/doc/ports#ssl_configuration
|
||||||
|
|||||||
@@ -1,6 +1,28 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
|
export ALLOW_REGISTRATION=${ALLOW_REGISTRATION:-true}
|
||||||
|
export DOMAIN_HTTP_UPLOAD=${DOMAIN_HTTP_UPLOAD:-"upload.$DOMAIN"}
|
||||||
|
export DOMAIN_MUC=${DOMAIN_MUC:-"conference.$DOMAIN"}
|
||||||
|
export DOMAIN_PROXY=${DOMAIN_PROXY:-"proxy.$DOMAIN"}
|
||||||
|
export DOMAIN_PUBSUB=${DOMAIN_PUBSUB:-"pubsub.$DOMAIN"}
|
||||||
|
export DB_DRIVER=${DB_DRIVER:-"SQLite3"}
|
||||||
|
export DB_DATABASE=${DB_DATABASE:-"prosody.sqlite"}
|
||||||
|
export E2E_POLICY_CHAT=${E2E_POLICY_CHAT:-"required"}
|
||||||
|
export E2E_POLICY_MUC=${E2E_POLICY_MUC:-"required"}
|
||||||
|
export E2E_POLICY_WHITELIST=${E2E_POLICY_WHITELIST:-""}
|
||||||
|
export LOG_LEVEL=${LOG_LEVEL:-"info"}
|
||||||
|
export C2S_REQUIRE_ENCRYPTION=${C2S_REQUIRE_ENCRYPTION:-true}
|
||||||
|
export S2S_REQUIRE_ENCRYPTION=${S2S_REQUIRE_ENCRYPTION:-true}
|
||||||
|
export S2S_SECURE_AUTH=${S2S_SECURE_AUTH:-true}
|
||||||
|
export SERVER_CONTACT_INFO_ABUSE=${SERVER_CONTACT_INFO_ABUSE:-"xmpp:abuse@$DOMAIN"}
|
||||||
|
export SERVER_CONTACT_INFO_ADMIN=${SERVER_CONTACT_INFO_ADMIN:-"xmpp:admin@$DOMAIN"}
|
||||||
|
export SERVER_CONTACT_INFO_FEEDBACK=${SERVER_CONTACT_INFO_FEEDBACK:-"xmpp:feedback@$DOMAIN"}
|
||||||
|
export SERVER_CONTACT_INFO_SALES=${SERVER_CONTACT_INFO_SALES:-"xmpp:sales@$DOMAIN"}
|
||||||
|
export SERVER_CONTACT_INFO_SECURITY=${SERVER_CONTACT_INFO_SECURITY:-"xmpp:security@$DOMAIN"}
|
||||||
|
export SERVER_CONTACT_INFO_SUPPORT=${SERVER_CONTACT_INFO_SUPPORT:-"xmpp:support@$DOMAIN"}
|
||||||
|
export PROSODY_ADMINS=${PROSODY_ADMINS:-""}
|
||||||
|
|
||||||
if [[ "$1" != "prosody" ]]; then
|
if [[ "$1" != "prosody" ]]; then
|
||||||
exec prosodyctl $*
|
exec prosodyctl $*
|
||||||
exit 0;
|
exit 0;
|
||||||
|
|||||||
@@ -43,13 +43,7 @@ for ext in $exts; do
|
|||||||
# Skip this if the modules should not be added to modules_enabled.
|
# Skip this if the modules should not be added to modules_enabled.
|
||||||
if [ "$ext" != "http_upload" ] && [ "$ext" != "vcard_muc" ] ; then
|
if [ "$ext" != "http_upload" ] && [ "$ext" != "vcard_muc" ] ; then
|
||||||
echo " - enabling within ${config}"
|
echo " - enabling within ${config}"
|
||||||
new_config=$(cat "${config}" | module="${ext}" perl -0pe 's/(modules_enabled[ ]*=[ ]*{[^}]*)};/$1\n\t"$ENV{module}";\n};/')
|
new_config=$(cat "${config}" | module="${ext}" perl -0pe 's/(mods_enabled[ ]*=[ ]*{[^}]*)};/$1\n\t"$ENV{module}";\n};/')
|
||||||
echo "${new_config}" > "${config}"
|
echo "${new_config}" > "${config}"
|
||||||
fi
|
fi
|
||||||
# firewall module configuration
|
|
||||||
if [ "$ext" == "firewall" ] ; then
|
|
||||||
echo " - setting up mod_${ext}"
|
|
||||||
new_config=$(cat "${config}" | echo -e "\nlocal spam_blocklist = os.getenv(\"SPAM_BLOCKLIST\") and \"/usr/local/etc/prosody/firewall/\" .. os.getenv(\"SPAM_BLOCKLIST\") or \"module:scripts/spam-blocklists.pfw\"\n\nfirewall_scripts = {\n\t\"module:scripts/spam-blocking.pfw\";\n\tspam_blocklist;\n};")
|
|
||||||
echo "${new_config}" >> "${config}"
|
|
||||||
fi
|
|
||||||
done
|
done
|
||||||
|
|||||||
Executable
+42
@@ -0,0 +1,42 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
source="/usr/src/prosody-modules"
|
||||||
|
target="/usr/local/lib/prosody/custom-modules"
|
||||||
|
|
||||||
|
cd ${source}
|
||||||
|
|
||||||
|
usage() {
|
||||||
|
echo "usage: $0 ext-name [ext-name ...]"
|
||||||
|
echo " ie: $0 carbons e2e_policy proxy65"
|
||||||
|
echo
|
||||||
|
echo 'Possible values for ext-name:'
|
||||||
|
find . -mindepth 1 -maxdepth 1 -type d | sort | sed s/\.\\/mod_//g | xargs
|
||||||
|
}
|
||||||
|
|
||||||
|
exts=
|
||||||
|
for ext; do
|
||||||
|
if [ -z "mod_$ext" ]; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
if [ ! -d "mod_$ext" ]; then
|
||||||
|
echo >&2 "error: $PWD/mod_$ext does not exist"
|
||||||
|
echo >&2
|
||||||
|
usage >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
exts="$exts $ext"
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ -z "$exts" ]; then
|
||||||
|
usage >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
for ext in $exts; do
|
||||||
|
echo "Installing mod_${ext}"
|
||||||
|
|
||||||
|
echo " - copying to ${target}"
|
||||||
|
cp -r "${source}/mod_${ext}" "${target}/"
|
||||||
|
|
||||||
|
done
|
||||||
@@ -4,7 +4,6 @@ set -e
|
|||||||
dir="/usr/src/prosody-modules"
|
dir="/usr/src/prosody-modules"
|
||||||
|
|
||||||
mkdir -p "${dir}"
|
mkdir -p "${dir}"
|
||||||
wget https://hg.prosody.im/prosody-modules/archive/233691533318.tar.gz -O tip.tar.gz
|
wget https://hg.prosody.im/prosody-modules/archive/tip.tar.gz
|
||||||
#wget https://hg.prosody.im/prosody-modules/archive/tip.tar.gz
|
|
||||||
tar -xzf tip.tar.gz -C "${dir}" --strip-components=1
|
tar -xzf tip.tar.gz -C "${dir}" --strip-components=1
|
||||||
rm tip.tar.gz
|
rm tip.tar.gz
|
||||||
|
|||||||
@@ -2,21 +2,17 @@ bashtel.ru
|
|||||||
creep.im
|
creep.im
|
||||||
darkengine.biz
|
darkengine.biz
|
||||||
default.rs
|
default.rs
|
||||||
exploit.im
|
|
||||||
hiddenlizard.org
|
hiddenlizard.org
|
||||||
jabber.bitactive.com
|
jabber.bitactive.com
|
||||||
jabber.cd
|
jabber.cd
|
||||||
jabber.cz
|
|
||||||
jabber.freenet.de
|
jabber.freenet.de
|
||||||
jabber.ipredator.se
|
jabber.ipredator.se
|
||||||
jabber.npw.net
|
jabber.npw.net
|
||||||
jabber.sampo.ru
|
jabber.sampo.ru
|
||||||
jabbim.pl
|
|
||||||
labas.biz
|
labas.biz
|
||||||
otr.chat
|
otr.chat
|
||||||
paranoid.scarab.name
|
paranoid.scarab.name
|
||||||
rassnet.org
|
rassnet.org
|
||||||
safetyjabber.com
|
safetyjabber.com
|
||||||
sj.ms
|
sj.ms
|
||||||
trashserver.net
|
|
||||||
xmpp.bytesund.biz
|
xmpp.bytesund.biz
|
||||||
|
|||||||
+8
-7
@@ -3,16 +3,17 @@
|
|||||||
|
|
||||||
local stringy = require "stringy"
|
local stringy = require "stringy"
|
||||||
|
|
||||||
local prosody_admins = os.getenv("PROSODY_ADMINS") or "";
|
admins = stringy.split(os.getenv("PROSODY_ADMINS"), ", ");
|
||||||
admins = stringy.split(prosody_admins, ", ");
|
|
||||||
|
|
||||||
pidfile = "/var/run/prosody/prosody.pid"
|
pidfile = "/var/run/prosody/prosody.pid"
|
||||||
|
|
||||||
allow_registration = os.getenv("ALLOW_REGISTRATION") or "true";
|
use_libevent = true; -- improves performance
|
||||||
|
|
||||||
c2s_require_encryption = os.getenv("C2S_REQUIRE_ENCRYPTION") or "true";
|
allow_registration = os.getenv("ALLOW_REGISTRATION");
|
||||||
s2s_require_encryption = os.getenv("S2S_REQUIRE_ENCRYPTION") or "true";
|
|
||||||
s2s_secure_auth = os.getenv("S2S_SECURE_AUTH") or "true";
|
c2s_require_encryption = os.getenv("C2S_REQUIRE_ENCRYPTION");
|
||||||
|
s2s_require_encryption = os.getenv("S2S_REQUIRE_ENCRYPTION");
|
||||||
|
s2s_secure_auth = os.getenv("S2S_SECURE_AUTH");
|
||||||
|
|
||||||
authentication = os.getenv("AUTHENTICATION") or "internal_hashed";
|
authentication = os.getenv("AUTHENTICATION") or "internal_hashed";
|
||||||
|
|
||||||
@@ -27,7 +28,7 @@ ldap_mode = os.getenv("LDAP_MODE") or "bind";
|
|||||||
ldap_admin_filter = os.getenv("LDAP_ADMIN_FILTER") or "";
|
ldap_admin_filter = os.getenv("LDAP_ADMIN_FILTER") or "";
|
||||||
|
|
||||||
log = {
|
log = {
|
||||||
{levels = {min = os.getenv("LOG_LEVEL") or "info"}, to = "console"};
|
{levels = {min = os.getenv("LOG_LEVEL")}, to = "console"};
|
||||||
};
|
};
|
||||||
|
|
||||||
Include "conf.d/*.cfg.lua";
|
Include "conf.d/*.cfg.lua";
|
||||||
|
|||||||
@@ -158,9 +158,11 @@ docker build -t prosody/xmpp .
|
|||||||
Next I recommend using a ```docker-compose.yml``` file:
|
Next I recommend using a ```docker-compose.yml``` file:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
|
version: '3.7'
|
||||||
|
|
||||||
services:
|
services:
|
||||||
server:
|
server:
|
||||||
image: prosody/xmpp:latest
|
image: sarasmiseth/prosody:latest
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
ports:
|
||||||
- "5000:5000"
|
- "5000:5000"
|
||||||
@@ -175,9 +177,9 @@ services:
|
|||||||
- ./data:/usr/local/var/lib/prosody
|
- ./data:/usr/local/var/lib/prosody
|
||||||
```
|
```
|
||||||
|
|
||||||
Boot it via: ```docker compose up -d```.
|
Boot it via: ```docker-compose up -d```.
|
||||||
|
|
||||||
Inspect logs: ```docker compose logs -f```.
|
Inspect logs: ```docker-compose logs -f```.
|
||||||
|
|
||||||
### Volumes permissions
|
### Volumes permissions
|
||||||
|
|
||||||
@@ -270,6 +272,11 @@ There is also ```docker-prosody-module-pre-install.bash``` which downloads the s
|
|||||||
|
|
||||||
If you need additional configuration just overwrite the respective _cfg.lua_ file or add new ones.
|
If you need additional configuration just overwrite the respective _cfg.lua_ file or add new ones.
|
||||||
|
|
||||||
|
#### Firewall module
|
||||||
|
Optionally, the Firewall module can be enabled through the ```ENABLE_FIREWALL``` environment variable. By default, the module obtains the list of spamming used known domains through the CDN service provided by [cdn.jsdelivr.net](https://cdn.jsdelivr.net/) at https://cdn.jsdelivr.net/gh/jabberspam/blacklist/blacklist.txt , but additionally a custom blacklist can be used through the ```SPAM_BLOCKLIST``` environment variable.
|
||||||
|
|
||||||
|
If you need more sophisticated rules, please refer to the module [documentation](https://modules.prosody.im/mod_firewall).
|
||||||
|
|
||||||
### Upgrade
|
### Upgrade
|
||||||
|
|
||||||
When migrating from prosody 0.10, you need to update the database once:
|
When migrating from prosody 0.10, you need to update the database once:
|
||||||
|
|||||||
Submodule tests/bats/bats-assert deleted from e2d855bc78
Submodule tests/bats/bats-core deleted from a751f3d3da
Submodule tests/bats/bats-support deleted from 9bf10e876d
@@ -1,3 +1,5 @@
|
|||||||
|
version: "3.9"
|
||||||
|
|
||||||
services:
|
services:
|
||||||
prosody:
|
prosody:
|
||||||
image: prosody
|
image: prosody
|
||||||
|
|||||||
+13
-22
@@ -19,7 +19,7 @@ registerTestUser() {
|
|||||||
local userName="$1"
|
local userName="$1"
|
||||||
local containerName="$2"
|
local containerName="$2"
|
||||||
echo "Registering TestUser '$userName' in container '$containerName'"
|
echo "Registering TestUser '$userName' in container '$containerName'"
|
||||||
sudo docker compose exec "$containerName" /bin/bash -c "prosodyctl register $userName example.com 12345678"
|
sudo docker compose exec "$containerName" /bin/bash -c "/entrypoint.bash register $userName example.com 12345678"
|
||||||
}
|
}
|
||||||
|
|
||||||
registerTestUsers() {
|
registerTestUsers() {
|
||||||
@@ -32,7 +32,8 @@ registerTestUsers() {
|
|||||||
|
|
||||||
runTests() {
|
runTests() {
|
||||||
local containerName="$1"
|
local containerName="$1"
|
||||||
python3 --version \
|
python --version \
|
||||||
|
&& python3 --version \
|
||||||
&& python3 -m venv venv \
|
&& python3 -m venv venv \
|
||||||
&& source venv/bin/activate \
|
&& source venv/bin/activate \
|
||||||
&& python --version \
|
&& python --version \
|
||||||
@@ -41,19 +42,12 @@ runTests() {
|
|||||||
&& pytest \
|
&& pytest \
|
||||||
&& deactivate \
|
&& deactivate \
|
||||||
&& sleep 5 \
|
&& sleep 5 \
|
||||||
&& sudo docker compose logs "$containerName" \
|
&& sudo docker-compose logs "$containerName" \
|
||||||
&& export batsContainerName="$containerName" \
|
&& export batsContainerName="$containerName" \
|
||||||
&& ./bats/bats-core/bin/bats tests.bats \
|
&& ./bats/bats-core/bin/bats tests.bats \
|
||||||
&& ./bats/bats-core/bin/bats tests-"$containerName".bats
|
&& ./bats/bats-core/bin/bats tests-"$containerName".bats
|
||||||
}
|
}
|
||||||
|
|
||||||
checkConfig() {
|
|
||||||
local containerName="$1"
|
|
||||||
sudo docker compose up -d "$containerName"
|
|
||||||
sudo docker compose exec -T "$containerName" prosodyctl check config || true
|
|
||||||
sudo docker compose down
|
|
||||||
}
|
|
||||||
|
|
||||||
generateCert "example.com"
|
generateCert "example.com"
|
||||||
generateCert "conference.example.com"
|
generateCert "conference.example.com"
|
||||||
generateCert "proxy.example.com"
|
generateCert "proxy.example.com"
|
||||||
@@ -62,25 +56,22 @@ generateCert "upload.example.com"
|
|||||||
|
|
||||||
# Run tests for first container with postgres
|
# Run tests for first container with postgres
|
||||||
# Start postgres first and wait for 10 seconds before starting prosody.
|
# Start postgres first and wait for 10 seconds before starting prosody.
|
||||||
sudo docker compose down
|
sudo docker-compose down
|
||||||
sudo docker compose up -d postgres
|
sudo docker-compose up -d postgres
|
||||||
sleep 10
|
sleep 10
|
||||||
sudo docker compose up -d prosody_postgres
|
sudo docker-compose up -d prosody_postgres
|
||||||
|
|
||||||
registerTestUsers prosody_postgres
|
registerTestUsers prosody_postgres
|
||||||
runTests prosody_postgres
|
runTests prosody_postgres
|
||||||
sudo docker compose down
|
sudo docker-compose down
|
||||||
|
|
||||||
# Run tests for second container with SQLite
|
# Run tests for second container with SQLite
|
||||||
sudo docker compose up -d prosody
|
sudo docker-compose up -d prosody
|
||||||
sleep 5
|
|
||||||
registerTestUsers prosody
|
registerTestUsers prosody
|
||||||
runTests prosody
|
runTests prosody
|
||||||
sudo docker compose down
|
sudo docker-compose down
|
||||||
|
|
||||||
# Run tests for prosody with ldap
|
# Run tests for prosody with ldap
|
||||||
sudo docker compose up -d prosody_ldap
|
sudo docker-compose up -d prosody_ldap
|
||||||
runTests prosody_ldap
|
runTests prosody_ldap
|
||||||
sudo docker compose down
|
sudo docker-compose down
|
||||||
|
|
||||||
# Check server config
|
|
||||||
checkConfig prosody
|
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ load 'bats/bats-support/load'
|
|||||||
load 'bats/bats-assert/load'
|
load 'bats/bats-assert/load'
|
||||||
|
|
||||||
@test "Should use sqlite" {
|
@test "Should use sqlite" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,13 +4,13 @@ load 'bats/bats-support/load'
|
|||||||
load 'bats/bats-assert/load'
|
load 'bats/bats-assert/load'
|
||||||
|
|
||||||
@test "Should use sqlite" {
|
@test "Should use sqlite" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should use ldap" {
|
@test "Should use ldap" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Host 'example.com' now set to use user provider 'ldap'\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Host 'example.com' now set to use user provider 'ldap'\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ load 'bats/bats-support/load'
|
|||||||
load 'bats/bats-assert/load'
|
load 'bats/bats-assert/load'
|
||||||
|
|
||||||
@test "Should use postgres" {
|
@test "Should use postgres" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Connecting to \[PostgreSQL\] prosody\.\.\.\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Connecting to \[PostgreSQL\] prosody\.\.\.\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|||||||
+15
-25
@@ -4,95 +4,85 @@ load 'bats/bats-support/load'
|
|||||||
load 'bats/bats-assert/load'
|
load 'bats/bats-assert/load'
|
||||||
|
|
||||||
@test "Should send 5 messages" {
|
@test "Should send 5 messages" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Received\[c2s\]: <message\" | wc -l"
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Received\[c2s\]: <message\" | wc -l"
|
||||||
assert_success
|
assert_success
|
||||||
assert_output "5"
|
assert_output "5"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should select certificate for example.com" {
|
@test "Should select certificate for example.com" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \" example.com:tls\" | wc -l"
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \" example.com:tls\" | wc -l"
|
||||||
assert_success
|
assert_success
|
||||||
assert_output "1"
|
assert_output "1"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should select certificate for conference.example.com" {
|
@test "Should select certificate for conference.example.com" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"conference.example.com:tls\" | wc -l"
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"conference.example.com:tls\" | wc -l"
|
||||||
assert_success
|
assert_success
|
||||||
assert_output "1"
|
assert_output "1"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should select certificate for proxy.example.com" {
|
@test "Should select certificate for proxy.example.com" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"proxy.example.com:tls\" | wc -l"
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"proxy.example.com:tls\" | wc -l"
|
||||||
assert_success
|
assert_success
|
||||||
assert_output "1"
|
assert_output "1"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should select certificate for pubsub.example.com" {
|
@test "Should select certificate for pubsub.example.com" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"pubsub.example.com:tls\" | wc -l"
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"pubsub.example.com:tls\" | wc -l"
|
||||||
assert_success
|
assert_success
|
||||||
assert_output "1"
|
assert_output "1"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should select certificate for upload.example.com" {
|
@test "Should select certificate for upload.example.com" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"upload.example.com:tls\" | wc -l"
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"upload.example.com:tls\" | wc -l"
|
||||||
assert_success
|
assert_success
|
||||||
assert_output "1"
|
assert_output "1"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should log error for user with wrong password" {
|
@test "Should log error for user with wrong password" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"Session closed by remote with error: undefined-condition (user intervention: authentication failed: authentication aborted by user)\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Session closed by remote with error: undefined-condition (user intervention: authentication failed: authentication aborted by user)\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should activate s2s" {
|
@test "Should activate s2s" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 's2s' on (\[::\]:5269|\[\*\]:5269), (\[::\]:5269|\[\*\]:5269)\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 's2s' on (\[::\]:5269|\[\*\]:5269), (\[::\]:5269|\[\*\]:5269)\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should activate c2s" {
|
@test "Should activate c2s" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'c2s' on (\[::\]:5222|\[\*\]:5222), (\[::\]:5222|\[\*\]:5222)\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'c2s' on (\[::\]:5222|\[\*\]:5222), (\[::\]:5222|\[\*\]:5222)\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should activate c2s_direct_tls" {
|
@test "Should activate legacy_ssl" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'c2s_direct_tls' on (\[::\]:5223|\[\*\]:5223), (\[::\]:5223|\[\*\]:5223)\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'legacy_ssl' on (\[::\]:5223|\[\*\]:5223), (\[::\]:5223|\[\*\]:5223)\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should activate proxy65" {
|
@test "Should activate proxy65" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'proxy65' on (\[::\]:5000|\[\*\]:5000), (\[::\]:5000|\[\*\]:5000)\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'proxy65' on (\[::\]:5000|\[\*\]:5000), (\[::\]:5000|\[\*\]:5000)\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should activate https" {
|
@test "Should activate https" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'https' on (\[::\]:5281|\[\*\]:5281), (\[::\]:5281|\[\*\]:5281)\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'https' on (\[::\]:5281|\[\*\]:5281), (\[::\]:5281|\[\*\]:5281)\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should load module cloud_notify" {
|
@test "Should load module cloud_notify" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"example.com:cloud_notify.*info.*Module loaded\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"example.com:cloud_notify.*info.*Module loaded\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should show upload URL" {
|
@test "Should show upload URL" {
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep \"Serving 'file_share' at https:\/\/upload.example.com:5281\/file_share\""
|
run bash -c "sudo docker-compose logs $batsContainerName | grep \"URL: <https:\/\/upload.example.com:5281\/upload> - Ensure this can be reached by users\""
|
||||||
assert_success
|
assert_success
|
||||||
assert_output
|
assert_output
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "Should not use deprecated config" {
|
|
||||||
run bash -c "sudo docker compose exec $batsContainerName /bin/bash -c \"/entrypoint.bash check\" | grep 'deprecated' -A 3"
|
|
||||||
assert_failure
|
|
||||||
}
|
|
||||||
|
|
||||||
@test "Should not have warnings in log" {
|
|
||||||
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"warn\""
|
|
||||||
assert_failure
|
|
||||||
}
|
|
||||||
|
|||||||
Reference in New Issue
Block a user