6 Commits
Author SHA1 Message Date
aitzol 8fa78be70a prosody 13.0.6 2026-08-02 19:35:07 +02:00
aitzol 3861f209d4 v1.3.5 2026-08-02 18:58:42 +02:00
aitzol 6fa59321c0 v1.3.5 2026-08-02 18:57:40 +02:00
aitzol 5e5ab8681a modules 2026-08-02 15:38:47 +02:00
aitzol fc0ef6de28 tests 2026-08-02 15:33:08 +02:00
aitzol b2eb145a6f tests 2026-08-02 15:26:07 +02:00
23 changed files with 162 additions and 168 deletions
+12
View File
@@ -1,5 +1,17 @@
# Changelog # Changelog
## v 1.3.6
* Updated to LuaRocks 3.13.0
* Updated to Prosody 13.0.6
* Updated deprecated modules
## v 1.3.5
* Added `prosodyctl check config` result to server test.
* A few minor tweaks.
* Move defaults to config files
## v 1.3.4 ## v 1.3.4
* Migration from Docker to Podman. * Migration from Docker to Podman.
+10 -17
View File
@@ -1,14 +1,14 @@
FROM debian:bookworm-slim FROM debian:trixie-slim
ARG BUILD_DATE ARG BUILD_DATE
ARG VCS_REF ARG VCS_REF
ARG VERSION ARG VERSION
ARG LUAROCKS_VERSION=3.12.2 ARG LUAROCKS_VERSION=3.13.0
ARG PROSODY_VERSION=0.12.5 ARG PROSODY_VERSION=13.0.6
ARG LUAROCKS_SHA256="b0e0c85205841ddd7be485f53d6125766d18a81d226588d2366931e9a1484492" ARG LUAROCKS_SHA256="245bf6ec560c042cb8948e3d661189292587c5949104677f1eecddc54dbe7e37"
ARG PROSODY_DOWNLOAD_SHA256="778fb7707a0f10399595ba7ab9c66dd2a2288c0ae3a7fe4ab78f97d462bd399f" ARG PROSODY_DOWNLOAD_SHA256="ec696f9cf562c3af4a04b07d3fb36a1cedcc4e69a392fddcfc524bc67d93050f"
LABEL luarocks.version="${LUAROCKS_VERSION}" LABEL luarocks.version="${LUAROCKS_VERSION}"
LABEL org.opencontainers.image.authors="Wproject Garapenak" LABEL org.opencontainers.image.authors="Wproject Garapenak"
@@ -25,8 +25,7 @@ LABEL prosody.version="${PROSODY_VERSION}"
RUN apt-get update \ RUN apt-get update \
&& DEBIAN_FRONTEND=noninteractive apt-get install -y \ && DEBIAN_FRONTEND=noninteractive apt-get install -y \
libevent-dev `# this is no build dependency, but needed for luaevent` \ libicu76 \
libicu72 \
libidn2-0 \ libidn2-0 \
libpq-dev \ libpq-dev \
libsqlite3-0 \ libsqlite3-0 \
@@ -45,7 +44,7 @@ RUN apt-get update \
&& apt-get clean \ && apt-get clean \
&& rm -rf /var/lib/apt/lists/* && rm -rf /var/lib/apt/lists/*
RUN buildDeps='gcc git libc6-dev libidn2-dev liblua5.2-dev libsqlite3-dev libssl-dev libicu-dev make unzip' \ RUN buildDeps='gcc git libc6-dev libidn2-dev liblua5.4-dev libsqlite3-dev libssl-dev libicu-dev make unzip' \
&& set -x \ && set -x \
&& apt-get update && apt-get install -y $buildDeps --no-install-recommends \ && apt-get update && apt-get install -y $buildDeps --no-install-recommends \
&& rm -rf /var/lib/apt/lists/* \ && rm -rf /var/lib/apt/lists/* \
@@ -71,14 +70,14 @@ RUN buildDeps='gcc git libc6-dev libidn2-dev liblua5.2-dev libsqlite3-dev libssl
&& tar zxpf luarocks-${LUAROCKS_VERSION}.tar.gz \ && tar zxpf luarocks-${LUAROCKS_VERSION}.tar.gz \
&& cd luarocks-${LUAROCKS_VERSION} \ && cd luarocks-${LUAROCKS_VERSION} \
&& ./configure \ && ./configure \
&& make bootstrap \ && make \
&& make install \
&& cd / && rm -r /usr/src/luarocks \ && cd / && rm -r /usr/src/luarocks \
\ \
# && luarocks install luaevent \
&& luarocks install luadbi \ && luarocks install luadbi \
`#&& luarocks install luadbi-mysql MYSQL_INCDIR=/usr/include/mariadb/` \ `#&& luarocks install luadbi-mysql MYSQL_INCDIR=/usr/include/mariadb/` \
&& luarocks install luadbi-sqlite3 \ && luarocks install luadbi-sqlite3 \
# && luarocks install stringy \ && luarocks install stringy \
\ \
&& apt-get purge -y --auto-remove $buildDeps && apt-get purge -y --auto-remove $buildDeps
@@ -103,16 +102,10 @@ COPY *.bash /usr/local/bin/
RUN download-prosody-modules.bash \ RUN download-prosody-modules.bash \
&& podman-prosody-module-install.bash \ && podman-prosody-module-install.bash \
#bookmarks `# XEP-0411: Bookmarks Conversion` \
#carbons `# message carbons (XEP-0280)` \
cloud_notify `# XEP-0357: Push Notifications` \
#csi `# client state indication (XEP-0352)` \
e2e_policy `# require end-2-end encryption` \ e2e_policy `# require end-2-end encryption` \
filter_chatstates `# disable "X is typing" type messages` \ filter_chatstates `# disable "X is typing" type messages` \
smacks `# stream management (XEP-0198)` \ smacks `# stream management (XEP-0198)` \
throttle_presence `# presence throttling in CSI` \ throttle_presence `# presence throttling in CSI` \
vcard_muc `# XEP-0153: vCard-Based Avatar (MUC)` \
#&& podman-prosody-module-pre-install.bash \
firewall `# anti-spam firewall` \ firewall `# anti-spam firewall` \
&& rm -rf "/usr/src/prosody-modules" && rm -rf "/usr/src/prosody-modules"
RUN echo "TLS_REQCERT allow" >> /etc/ldap/ldap.conf RUN echo "TLS_REQCERT allow" >> /etc/ldap/ldap.conf
+8 -3
View File
@@ -1,3 +1,5 @@
local getenv = Lua.os.getenv
plugin_paths = { "/usr/local/lib/prosody/custom-modules/" }; plugin_paths = { "/usr/local/lib/prosody/custom-modules/" };
-- table of enabled modules -- table of enabled modules
@@ -19,6 +21,7 @@ modules_enabled = {
"carbons"; -- Share and sync conversations (XEP-0280) "carbons"; -- Share and sync conversations (XEP-0280)
"csi_simple"; -- Buffer unimportant traffic for simple optimisation for clients using state indication "csi_simple"; -- Buffer unimportant traffic for simple optimisation for clients using state indication
"limits"; -- Enable bandwidth limiting for XMPP connections "limits"; -- Enable bandwidth limiting for XMPP connections
"bookmarks"; -- Converts between old and new ways to store chat room bookmarks
-- Nice to have -- Nice to have
"version"; -- Replies to server version requests "version"; -- Replies to server version requests
@@ -39,15 +42,17 @@ modules_enabled = {
--"http_files"; -- Serve static files from a directory over HTTP --"http_files"; -- Serve static files from a directory over HTTP
-- Other specific functionality -- Other specific functionality
"posix"; -- POSIX functionality, sends server to background, enables syslog, etc. --"posix"; -- POSIX functionality, sends server to background, enables syslog, etc.
--"groups"; -- Shared roster support --"groups"; -- Shared roster support
"announce"; -- Send announcement to all online users "announce"; -- Send announcement to all online users
"welcome"; -- Welcome users who register accounts --"welcome"; -- Welcome users who register accounts
--"watchregistrations"; -- Alert admins of registrations --"watchregistrations"; -- Alert admins of registrations
--"motd"; -- Send a message to users when they log in --"motd"; -- Send a message to users when they log in
--"legacyauth"; -- Legacy authentication. Only used by some old clients and bots. --"legacyauth"; -- Legacy authentication. Only used by some old clients and bots.
"lastactivity"; "lastactivity";
"server_contact_info"; -- This module lets you advertise various contact addresses for your XMPP service via XEP-0157. "server_info"; -- This module lets you advertise various contact addresses for your XMPP service via XEP-0158.
"cloud_notify";
}; };
-- modules_enabled = mods_enabled; -- modules_enabled = mods_enabled;
+9 -7
View File
@@ -1,12 +1,14 @@
local getenv = Lua.os.getenv
default_storage = "sql" default_storage = "sql"
sql = { sql = {
driver = os.getenv("DB_DRIVER") or "SQLite3"; driver = getenv("DB_DRIVER") or "SQLite3";
database = os.getenv("DB_DATABASE") or "prosody.sqlite"; database = getenv("DB_DATABASE") or "prosody.sqlite";
host = os.getenv("DB_HOST"); host = getenv("DB_HOST");
port = os.getenv("DB_PORT"); port = getenv("DB_PORT");
username = os.getenv("DB_USERNAME"); username = getenv("DB_USERNAME");
password = os.getenv("DB_PASSWORD"); password = getenv("DB_PASSWORD");
} }
-- make 0.10-distributed mod_mam use sql store -- make 0.10-distributed mod_mam use sql store
@@ -30,4 +32,4 @@ archive_expires_after = "1y"
--}; --};
--} --}
http_max_content_size = os.getenv("HTTP_MAX_CONTENT_SIZE") or 1024 * 1024 * 10 -- Default is 10MB http_max_content_size = getenv("HTTP_MAX_CONTENT_SIZE") or 1024 * 1024 * 10 -- Default is 10MB
+8 -12
View File
@@ -1,16 +1,12 @@
local function _split(s, sep) local getenv = Lua.os.getenv
if not s then return nil; end local stringy = Lua.require "stringy"
sep = sep or ",";
local parts = {}; e2e_policy_chat = getenv("E2E_POLICY_CHAT") or "required"
for part in s:gmatch("[^"..sep.."]+") do e2e_policy_muc = getenv("E2E_POLICY_MUC") or "required"
parts[#parts+1] = part;
end local whitelist = getenv("E2E_POLICY_WHITELIST") or ""
return parts; e2e_policy_whitelist = stringy.split(whitelist, ", ")
end
e2e_policy_chat = os.getenv("E2E_POLICY_CHAT")
e2e_policy_muc = os.getenv("E2E_POLICY_MUC")
e2e_policy_whitelist = _split(os.getenv("E2E_POLICY_WHITELIST"), ", ")
e2e_policy_message_optional_chat = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for conversations on this server." e2e_policy_message_optional_chat = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for conversations on this server."
e2e_policy_message_required_chat = "For security reasons, OMEMO, OTR or PGP encryption is required for conversations on this server." e2e_policy_message_required_chat = "For security reasons, OMEMO, OTR or PGP encryption is required for conversations on this server."
e2e_policy_message_optional_muc = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for MUC on this server." e2e_policy_message_optional_muc = "For security reasons, OMEMO, OTR or PGP encryption is STRONGLY recommended for MUC on this server."
-28
View File
@@ -1,28 +0,0 @@
local function _split(s, sep)
if not s then return nil; end
sep = sep or ",";
local parts = {};
for part in s:gmatch("[^"..sep.."]+") do
parts[#parts+1] = part;
end
return parts;
end
local domain = os.getenv("DOMAIN")
local abuse = os.getenv("SERVER_CONTACT_INFO_ABUSE") or "xmpp:abuse@" .. domain
local admin = os.getenv("SERVER_CONTACT_INFO_ADMIN") or "xmpp:admin@" .. domain
local feedback = os.getenv("SERVER_CONTACT_INFO_FEEDBACK") or "xmpp:feedback@" .. domain
local sales = os.getenv("SERVER_CONTACT_INFO_SALES") or "xmpp:sales@" .. domain
local security = os.getenv("SERVER_CONTACT_INFO_SECURITY") or "xmpp:security@" .. domain
local support = os.getenv("SERVER_CONTACT_INFO_SUPPORT") or "xmpp:support@" .. domain
contact_info = {
abuse = _split(abuse, ", ");
admin = _split(admin, ", ");
feedback = _split(feedback, ", ");
sales = _split(sales, ", ");
security = _split(security, ", ");
support = _split(support, ", ");
}
welcome_message = "Kaixo $username, ongi etorri $host IM zerbitzura! Mesedez irakurri itzazu ondorengo <a href='https://lainoa.eus/terms/tos.html'>Erabilpen baldintzak</a>."
+21
View File
@@ -0,0 +1,21 @@
local getenv = Lua.os.getenv
local stringy = Lua.require "stringy"
local domain = getenv("DOMAIN")
local abuse = getenv("SERVER_CONTACT_INFO_ABUSE") or "xmpp:abuse@" .. domain
local admin = getenv("SERVER_CONTACT_INFO_ADMIN") or "xmpp:admin@" .. domain
local feedback = getenv("SERVER_CONTACT_INFO_FEEDBACK") or "xmpp:feedback@" .. domain
local sales = getenv("SERVER_CONTACT_INFO_SALES") or "xmpp:sales@" .. domain
local security = getenv("SERVER_CONTACT_INFO_SECURITY") or "xmpp:security@" .. domain
local support = getenv("SERVER_CONTACT_INFO_SUPPORT") or "xmpp:support@" .. domain
contact_info = {
abuse = stringy.split(abuse, ", ");
admin = stringy.split(admin, ", ");
feedback = stringy.split(feedback, ", ");
sales = stringy.split(sales, ", ");
security = stringy.split(security, ", ");
support = stringy.split(support, ", ");
}
welcome_message = "Kaixo $username, ongi etorri $host IM zerbitzura! Mesedez irakurri itzazu ondorengo <a href='https://lainoa.eus/terms/tos.html'>Erabilpen baldintzak</a>."
+12 -11
View File
@@ -1,16 +1,17 @@
local domain = os.getenv("DOMAIN") local getenv = Lua.os.getenv
local domain_http_upload = os.getenv("DOMAIN_HTTP_UPLOAD")
local domain_muc = os.getenv("DOMAIN_MUC")
local domain_proxy = os.getenv("DOMAIN_PROXY")
local domain_pubsub = os.getenv("DOMAIN_PUBSUB")
local domain = getenv("DOMAIN")
local domain_http_upload = getenv("DOMAIN_HTTP_UPLOAD") or "upload." .. domain
local domain_muc = getenv("DOMAIN_MUC") or "conference." .. domain
local domain_proxy = getenv("DOMAIN_PROXY") or "proxy." .. domain
local domain_pubsub = getenv("DOMAIN_PUBSUB") or "pubsub." .. domain
-- XEP-0368: SRV records for XMPP over TLS -- XEP-0368: SRV records for XMPP over TLS
-- https://compliance.conversations.im/test/xep0368/ -- https://compliance.conversations.im/test/xep0368/
legacy_ssl_ssl = { c2s_direct_tls_ssl = {
certificate = "certs/" .. domain .. "/fullchain.pem"; certificate = "certs/" .. domain .. "/fullchain.pem";
key = "certs/" .. domain .. "/privkey.pem"; key = "certs/" .. domain .. "/privkey.pem";
} }
legacy_ssl_ports = { 5223 } c2s_direct_tls_ports = { 5223 }
-- https://prosody.im/doc/certificates#service_certificates -- https://prosody.im/doc/certificates#service_certificates
-- https://prosody.im/doc/ports#ssl_configuration -- https://prosody.im/doc/ports#ssl_configuration
@@ -24,9 +25,9 @@ VirtualHost (domain)
-- Set up a http file upload -- Set up a http file upload
Component (domain_http_upload) "http_file_share" Component (domain_http_upload) "http_file_share"
http_file_share_expires_after = 60 * 60 * 24 * 7 -- a week in seconds http_file_share_expires_after = 60 * 60 * 24 * 7 -- a week in seconds
local size_limit = os.getenv("HTTP_FILE_SHARE_SIZE_LIMIT") or 10 * 1024 * 1024 -- Default is 10MB local size_limit = getenv("HTTP_FILE_SHARE_SIZE_LIMIT") or 10 * 1024 * 1024 -- Default is 10MB
http_file_share_size_limit = size_limit http_file_share_size_limit = size_limit
http_file_share_daily_quota = os.getenv("HTTP_FILE_SHARE_DAILY_QUOTA") or 10 * size_limit -- Default is 10x the size limit http_file_share_daily_quota = getenv("HTTP_FILE_SHARE_DAILY_QUOTA") or 10 * size_limit -- Default is 10x the size limit
Component (domain_muc) "muc" Component (domain_muc) "muc"
name = "Prosody Chatrooms" name = "Prosody Chatrooms"
@@ -34,7 +35,7 @@ Component (domain_muc) "muc"
max_history_messages = 20 max_history_messages = 20
modules_enabled = { modules_enabled = {
"muc_mam", "muc_mam",
"vcard_muc" --"vcard_muc"
} }
-- Set up a SOCKS5 bytestream proxy for server-proxied file transfers -- Set up a SOCKS5 bytestream proxy for server-proxied file transfers
+2 -1
View File
@@ -2,8 +2,9 @@
set -e set -e
dir="/usr/src/prosody-modules" dir="/usr/src/prosody-modules"
#dir="/usr/local/lib/prosody/custom-modules"
mkdir -p "${dir}" mkdir -p "${dir}"
#wget https://hg.prosody.im/prosody-modules/archive/233691533318.tar.gz -O tip.tar.gz
wget https://hg.prosody.im/prosody-modules/archive/tip.tar.gz wget https://hg.prosody.im/prosody-modules/archive/tip.tar.gz
tar -xzf tip.tar.gz -C "${dir}" --strip-components=1 tar -xzf tip.tar.gz -C "${dir}" --strip-components=1
rm tip.tar.gz rm tip.tar.gz
+3 -3
View File
@@ -19,7 +19,7 @@ ShowJoinPart=false
################################################################### ###################################################################
[telegram] [telegram]
[telegram.chat_xmppBot] [telegram.chat_xmppBot]
Token="434963xxx:AAHRbJAw9oN30b9KdjWacnyYyHS22r05xxx" #token berriket_xmppBot Token="123456789:ABCdefGhIJKlmNoPQRsTUVwxYZ" #token berriket_xmppBot
MessageFormat="HTMLNick" MessageFormat="HTMLNick"
EditDisable=false EditDisable=false
EditSuffix=" (edited)" EditSuffix=" (edited)"
@@ -49,6 +49,6 @@ enable=true
[[gateway.inout]] [[gateway.inout]]
account="telegram.chat_xmppBot" account="telegram.chat_xmppBot"
#channel="-241666435" #Telegram xmpp_test taldearen ID-a #channel="-10012112121212" #Telegram xmpp_test taldearen ID-a
channel="-1001617641xxx" channel="-10012112121212"
-22
View File
@@ -1,28 +1,6 @@
#!/bin/bash #!/bin/bash
set -e set -e
export ALLOW_REGISTRATION=${ALLOW_REGISTRATION:-true}
export DOMAIN_HTTP_UPLOAD=${DOMAIN_HTTP_UPLOAD:-"upload.$DOMAIN"}
export DOMAIN_MUC=${DOMAIN_MUC:-"conference.$DOMAIN"}
export DOMAIN_PROXY=${DOMAIN_PROXY:-"proxy.$DOMAIN"}
export DOMAIN_PUBSUB=${DOMAIN_PUBSUB:-"pubsub.$DOMAIN"}
export DB_DRIVER=${DB_DRIVER:-"SQLite3"}
export DB_DATABASE=${DB_DATABASE:-"prosody.sqlite"}
export E2E_POLICY_CHAT=${E2E_POLICY_CHAT:-"required"}
export E2E_POLICY_MUC=${E2E_POLICY_MUC:-"required"}
export E2E_POLICY_WHITELIST=${E2E_POLICY_WHITELIST:-""}
export LOG_LEVEL=${LOG_LEVEL:-"info"}
export C2S_REQUIRE_ENCRYPTION=${C2S_REQUIRE_ENCRYPTION:-true}
export S2S_REQUIRE_ENCRYPTION=${S2S_REQUIRE_ENCRYPTION:-true}
export S2S_SECURE_AUTH=${S2S_SECURE_AUTH:-true}
export SERVER_CONTACT_INFO_ABUSE=${SERVER_CONTACT_INFO_ABUSE:-"xmpp:abuse@$DOMAIN"}
export SERVER_CONTACT_INFO_ADMIN=${SERVER_CONTACT_INFO_ADMIN:-"xmpp:admin@$DOMAIN"}
export SERVER_CONTACT_INFO_FEEDBACK=${SERVER_CONTACT_INFO_FEEDBACK:-"xmpp:feedback@$DOMAIN"}
export SERVER_CONTACT_INFO_SALES=${SERVER_CONTACT_INFO_SALES:-"xmpp:sales@$DOMAIN"}
export SERVER_CONTACT_INFO_SECURITY=${SERVER_CONTACT_INFO_SECURITY:-"xmpp:security@$DOMAIN"}
export SERVER_CONTACT_INFO_SUPPORT=${SERVER_CONTACT_INFO_SUPPORT:-"xmpp:support@$DOMAIN"}
export PROSODY_ADMINS=${PROSODY_ADMINS:-""}
if [[ "$1" != "prosody" ]]; then if [[ "$1" != "prosody" ]]; then
exec prosodyctl $* exec prosodyctl $*
exit 0; exit 0;
+1 -1
View File
@@ -49,7 +49,7 @@ for ext in $exts; do
# firewall module configuration # firewall module configuration
if [ "$ext" == "firewall" ] ; then if [ "$ext" == "firewall" ] ; then
echo " - setting up mod_${ext}" echo " - setting up mod_${ext}"
new_config=$(cat "${config}" | echo -e "\nlocal spam_blocklist = os.getenv(\"SPAM_BLOCKLIST\") and \"/usr/local/etc/prosody/firewall/\" .. os.getenv(\"SPAM_BLOCKLIST\") or \"module:scripts/spam-blocklists.pfw\"\n\nfirewall_scripts = {\n\t\"module:scripts/spam-blocking.pfw\";\n\tspam_blocklist;\n};") new_config=$(cat "${config}" | echo -e "\nlocal spam_blocklist = getenv(\"SPAM_BLOCKLIST\") and \"/usr/local/etc/prosody/firewall/\" .. getenv(\"SPAM_BLOCKLIST\") or \"module:scripts/spam-blocklists.pfw\"\n\nfirewall_scripts = {\n\t\"module:scripts/spam-blocking.pfw\";\n\tspam_blocklist;\n};")
echo "${new_config}" >> "${config}" echo "${new_config}" >> "${config}"
fi fi
done done
+20 -27
View File
@@ -1,40 +1,33 @@
-- see example config at https://hg.prosody.im/0.12/file/tip/prosody.cfg.lua.dist -- see example config at https://hg.prosody.im/-1.9/file/0.9.10/prosody.cfg.lua.dist
-- easily extendable by putting into different config files within conf.d folder -- easily extendable by putting into different config files within conf.d folder
local getenv = Lua.os.getenv
local stringy = Lua.require "stringy"
local function _split(s, sep) local prosody_admins = getenv("PROSODY_ADMINS") or "";
if not s then return nil; end admins = stringy.split(prosody_admins, ", ");
sep = sep or ",";
local parts = {};
for part in s:gmatch("[^"..sep.."]+") do
parts[#parts+1] = part;
end
return parts;
end
admins = _split(os.getenv("PROSODY_ADMINS"), ", ");
pidfile = "/var/run/prosody/prosody.pid" pidfile = "/var/run/prosody/prosody.pid"
allow_registration = os.getenv("ALLOW_REGISTRATION"); allow_registration = getenv("ALLOW_REGISTRATION") or "true";
c2s_require_encryption = os.getenv("C2S_REQUIRE_ENCRYPTION"); c2s_require_encryption = getenv("C2S_REQUIRE_ENCRYPTION") or "true";
s2s_require_encryption = os.getenv("S2S_REQUIRE_ENCRYPTION"); s2s_require_encryption = getenv("S2S_REQUIRE_ENCRYPTION") or "true";
s2s_secure_auth = os.getenv("S2S_SECURE_AUTH"); s2s_secure_auth = getenv("S2S_SECURE_AUTH") or "true";
authentication = os.getenv("AUTHENTICATION") or "internal_hashed"; authentication = getenv("AUTHENTICATION") or "internal_hashed";
ldap_base = os.getenv("LDAP_BASE"); ldap_base = getenv("LDAP_BASE");
ldap_server = os.getenv("LDAP_SERVER") or "localhost"; ldap_server = getenv("LDAP_SERVER") or "localhost";
ldap_rootdn = os.getenv("LDAP_ROOTDN") or ""; ldap_rootdn = getenv("LDAP_ROOTDN") or "";
ldap_password = os.getenv("LDAP_PASSWORD") or ""; ldap_password = getenv("LDAP_PASSWORD") or "";
ldap_filter = os.getenv("LDAP_FILTER") or "(uid=$user)"; ldap_filter = getenv("LDAP_FILTER") or "(uid=$user)";
ldap_scope = os.getenv("LDAP_SCOPE") or "subtree"; ldap_scope = getenv("LDAP_SCOPE") or "subtree";
ldap_tls = os.getenv("LDAP_TLS") or "false"; ldap_tls = getenv("LDAP_TLS") or "false";
ldap_mode = os.getenv("LDAP_MODE") or "bind"; ldap_mode = getenv("LDAP_MODE") or "bind";
ldap_admin_filter = os.getenv("LDAP_ADMIN_FILTER") or ""; ldap_admin_filter = getenv("LDAP_ADMIN_FILTER") or "";
log = { log = {
{levels = {min = os.getenv("LOG_LEVEL")}, to = "console"}; {levels = {min = getenv("LOG_LEVEL") or "info"}, to = "console"};
}; };
Include "conf.d/*.cfg.lua"; Include "conf.d/*.cfg.lua";
-2
View File
@@ -1,5 +1,3 @@
version: "3.9"
services: services:
prosody: prosody:
image: prosody image: prosody
+2 -2
View File
@@ -1,4 +1,4 @@
aioxmpp==0.13.3 aioxmpp==0.13.3
pip-chill==1.0.3 pip-chill==1.0.1
pytest-asyncio==0.21.0 pytest-asyncio==0.21.0
pytz==2023.3 pytz==2022.7.1
+22 -13
View File
@@ -19,7 +19,7 @@ registerTestUser() {
local userName="$1" local userName="$1"
local containerName="$2" local containerName="$2"
echo "Registering TestUser '$userName' in container '$containerName'" echo "Registering TestUser '$userName' in container '$containerName'"
sudo docker compose exec "$containerName" /bin/bash -c "/entrypoint.bash register $userName example.com 12345678" sudo docker compose exec "$containerName" /bin/bash -c "prosodyctl register $userName example.com 12345678"
} }
registerTestUsers() { registerTestUsers() {
@@ -32,8 +32,7 @@ registerTestUsers() {
runTests() { runTests() {
local containerName="$1" local containerName="$1"
python --version \ python3 --version \
&& python3 --version \
&& python3 -m venv venv \ && python3 -m venv venv \
&& source venv/bin/activate \ && source venv/bin/activate \
&& python --version \ && python --version \
@@ -42,12 +41,19 @@ runTests() {
&& pytest \ && pytest \
&& deactivate \ && deactivate \
&& sleep 5 \ && sleep 5 \
&& sudo docker-compose logs "$containerName" \ && sudo docker compose logs "$containerName" \
&& export batsContainerName="$containerName" \ && export batsContainerName="$containerName" \
&& ./bats/bats-core/bin/bats tests.bats \ && ./bats/bats-core/bin/bats tests.bats \
&& ./bats/bats-core/bin/bats tests-"$containerName".bats && ./bats/bats-core/bin/bats tests-"$containerName".bats
} }
checkFeatures() {
local containerName="$1"
sudo docker compose up -d "$containerName"
sudo docker compose exec -T "$containerName" prosodyctl check features || true
sudo docker compose down
}
generateCert "example.com" generateCert "example.com"
generateCert "conference.example.com" generateCert "conference.example.com"
generateCert "proxy.example.com" generateCert "proxy.example.com"
@@ -56,22 +62,25 @@ generateCert "upload.example.com"
# Run tests for first container with postgres # Run tests for first container with postgres
# Start postgres first and wait for 10 seconds before starting prosody. # Start postgres first and wait for 10 seconds before starting prosody.
sudo docker-compose down sudo docker compose down
sudo docker-compose up -d postgres sudo docker compose up -d postgres
sleep 10 sleep 10
sudo docker-compose up -d prosody_postgres sudo docker compose up -d prosody_postgres
registerTestUsers prosody_postgres registerTestUsers prosody_postgres
runTests prosody_postgres runTests prosody_postgres
sudo docker-compose down sudo docker compose down
# Run tests for second container with SQLite # Run tests for second container with SQLite
sudo docker-compose up -d prosody sudo docker compose up -d prosody
sleep 5
registerTestUsers prosody registerTestUsers prosody
runTests prosody runTests prosody
sudo docker-compose down sudo docker compose down
# Run tests for prosody with ldap # Run tests for prosody with ldap
sudo docker-compose up -d prosody_ldap sudo docker compose up -d prosody_ldap
runTests prosody_ldap runTests prosody_ldap
sudo docker-compose down sudo docker compose down
# Check server features
checkFeatures prosody
+1 -1
View File
@@ -4,7 +4,7 @@ load 'bats/bats-support/load'
load 'bats/bats-assert/load' load 'bats/bats-assert/load'
@test "Should use sqlite" { @test "Should use sqlite" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\""
assert_success assert_success
assert_output assert_output
} }
+2 -2
View File
@@ -4,13 +4,13 @@ load 'bats/bats-support/load'
load 'bats/bats-assert/load' load 'bats/bats-assert/load'
@test "Should use sqlite" { @test "Should use sqlite" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Connecting to \[SQLite3\] \/usr\/local\/var\/lib\/prosody\/prosody\.sqlite\.\.\.\""
assert_success assert_success
assert_output assert_output
} }
@test "Should use ldap" { @test "Should use ldap" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Host 'example.com' now set to use user provider 'ldap'\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Host 'example.com' now set to use user provider 'ldap'\""
assert_success assert_success
assert_output assert_output
} }
+1 -1
View File
@@ -4,7 +4,7 @@ load 'bats/bats-support/load'
load 'bats/bats-assert/load' load 'bats/bats-assert/load'
@test "Should use postgres" { @test "Should use postgres" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Connecting to \[PostgreSQL\] prosody\.\.\.\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Connecting to \[PostgreSQL\] prosody\.\.\.\""
assert_success assert_success
assert_output assert_output
} }
+25 -15
View File
@@ -4,85 +4,95 @@ load 'bats/bats-support/load'
load 'bats/bats-assert/load' load 'bats/bats-assert/load'
@test "Should send 5 messages" { @test "Should send 5 messages" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Received\[c2s\]: <message\" | wc -l" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Received\[c2s\]: <message\" | wc -l"
assert_success assert_success
assert_output "5" assert_output "5"
} }
@test "Should select certificate for example.com" { @test "Should select certificate for example.com" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \" example.com:tls\" | wc -l" run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \" example.com:tls\" | wc -l"
assert_success assert_success
assert_output "1" assert_output "1"
} }
@test "Should select certificate for conference.example.com" { @test "Should select certificate for conference.example.com" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"conference.example.com:tls\" | wc -l" run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"conference.example.com:tls\" | wc -l"
assert_success assert_success
assert_output "1" assert_output "1"
} }
@test "Should select certificate for proxy.example.com" { @test "Should select certificate for proxy.example.com" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"proxy.example.com:tls\" | wc -l" run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"proxy.example.com:tls\" | wc -l"
assert_success assert_success
assert_output "1" assert_output "1"
} }
@test "Should select certificate for pubsub.example.com" { @test "Should select certificate for pubsub.example.com" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"pubsub.example.com:tls\" | wc -l" run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"pubsub.example.com:tls\" | wc -l"
assert_success assert_success
assert_output "1" assert_output "1"
} }
@test "Should select certificate for upload.example.com" { @test "Should select certificate for upload.example.com" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"upload.example.com:tls\" | wc -l" run bash -c "sudo docker compose logs $batsContainerName | grep \"Certificates loaded\" | grep \"upload.example.com:tls\" | wc -l"
assert_success assert_success
assert_output "1" assert_output "1"
} }
@test "Should log error for user with wrong password" { @test "Should log error for user with wrong password" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Session closed by remote with error: undefined-condition (user intervention: authentication failed: authentication aborted by user)\"" run bash -c "sudo docker compose logs $batsContainerName | grep \"Session closed by remote with error: undefined-condition (user intervention: authentication failed: authentication aborted by user)\""
assert_success assert_success
assert_output assert_output
} }
@test "Should activate s2s" { @test "Should activate s2s" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 's2s' on (\[::\]:5269|\[\*\]:5269), (\[::\]:5269|\[\*\]:5269)\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 's2s' on (\[::\]:5269|\[\*\]:5269), (\[::\]:5269|\[\*\]:5269)\""
assert_success assert_success
assert_output assert_output
} }
@test "Should activate c2s" { @test "Should activate c2s" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'c2s' on (\[::\]:5222|\[\*\]:5222), (\[::\]:5222|\[\*\]:5222)\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'c2s' on (\[::\]:5222|\[\*\]:5222), (\[::\]:5222|\[\*\]:5222)\""
assert_success assert_success
assert_output assert_output
} }
@test "Should activate legacy_ssl" { @test "Should activate c2s_direct_tls" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'legacy_ssl' on (\[::\]:5223|\[\*\]:5223), (\[::\]:5223|\[\*\]:5223)\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'c2s_direct_tls' on (\[::\]:5223|\[\*\]:5223), (\[::\]:5223|\[\*\]:5223)\""
assert_success assert_success
assert_output assert_output
} }
@test "Should activate proxy65" { @test "Should activate proxy65" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'proxy65' on (\[::\]:5000|\[\*\]:5000), (\[::\]:5000|\[\*\]:5000)\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'proxy65' on (\[::\]:5000|\[\*\]:5000), (\[::\]:5000|\[\*\]:5000)\""
assert_success assert_success
assert_output assert_output
} }
@test "Should activate https" { @test "Should activate https" {
run bash -c "sudo docker-compose logs $batsContainerName | grep -E \"Activated service 'https' on (\[::\]:5281|\[\*\]:5281), (\[::\]:5281|\[\*\]:5281)\"" run bash -c "sudo docker compose logs $batsContainerName | grep -E \"Activated service 'https' on (\[::\]:5281|\[\*\]:5281), (\[::\]:5281|\[\*\]:5281)\""
assert_success assert_success
assert_output assert_output
} }
@test "Should load module cloud_notify" { @test "Should load module cloud_notify" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"example.com:cloud_notify.*info.*Module loaded\"" run bash -c "sudo docker compose logs $batsContainerName | grep \"example.com:cloud_notify.*info.*Module loaded\""
assert_success assert_success
assert_output assert_output
} }
@test "Should show upload URL" { @test "Should show upload URL" {
run bash -c "sudo docker-compose logs $batsContainerName | grep \"Serving 'file_share' at https:\/\/upload.example.com:5281\/file_share\"" run bash -c "sudo docker compose logs $batsContainerName | grep \"Serving 'file_share' at https:\/\/upload.example.com:5281\/file_share\""
assert_success assert_success
assert_output assert_output
} }
@test "Should not use deprecated config" {
run bash -c "sudo docker compose exec $batsContainerName /bin/bash -c \"/entrypoint.bash check\" | grep 'deprecated' -A 3"
assert_failure
}
@test "Should not have warnings in log" {
run bash -c "sudo docker compose logs $batsContainerName | grep -E \"warn\""
assert_failure
}