Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions changelog.html
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ <h1>
<p><b>1.12.1</b> (to be determined)</p>
<ul>
<li>[<a href="https://github.com/igniterealtime/openfire-restAPI-plugin/issues/251">#251</a>] - Enable JUnit 5 tests</li>
<li>[<a href="https://github.com/igniterealtime/openfire-restAPI-plugin/issues/244">#244</a>] - Prevent REST API plugin from exposing its own configuration (including authentication) via its own endpoints</li>
<li>[<a href="https://github.com/igniterealtime/openfire-restAPI-plugin/issues/242">#242</a>] - Fix individual System Property GETs returning HTTP/404</li>
<li>[<a href="https://github.com/igniterealtime/openfire-restAPI-plugin/issues/213">#213</a>] - Improve setting a subject in a chat room</li>
<li>[<a href="https://github.com/igniterealtime/openfire-restAPI-plugin/issues/217">#217</a>] - Add Hurl e2e tests, and CI to run them</li>
Expand Down
1 change: 1 addition & 0 deletions plugin.xml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@
<version>${project.version}</version>
<date>2025-10-02</date>
<minServerVersion>5.0.0</minServerVersion>
<priorToServerVersion>5.2.0</priorToServerVersion> <!-- because of OF-3313 compatibility -->
<adminconsole>
<tab id="tab-server">
<sidebar id="sidebar-server-settings">
Expand Down
6 changes: 6 additions & 0 deletions src/i18n/restapi_i18n.properties
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
system_property.plugin.restapi.allowedIPs=List of IP addresses that are allowed to access the REST API services. An empty list will allow all IP addresses.
system_property.plugin.restapi.customAuthFilter=The class name of a custom authentication filter implementation.
system_property.plugin.restapi.enabled=Enables or disables the processing of REST API service requests.
system_property.plugin.restapi.httpAuth=The authentication mechanism used to authenticate REST API service requests.
system_property.plugin.restapi.muc.case-insensitive-lookup.enabled=Names of MUC rooms should be node-prepped. This, however, was not guaranteed the case in some versions of Openfire and this plugin. Earlier versions of this plugin used a case-insensitive lookup to work around this. As this should be unneeded, and is quite resource intensive, this behavior has been made configurable (disabled by default).
system_property.plugin.restapi.muc.room-mutex.enabled=Controls if a mutual exclusion lock is used when an API interacts with a room.
system_property.plugin.restapi.secret=The value that is used to authenticate requests when using 'shared secret' authentication.
system_property.plugin.restapi.serviceLoggingEnabled=Enables or disables additional logging of REST API service calls.

stat.restapi_responses.informational.name=REST API 1xx responses
stat.restapi_responses.informational.desc=The amount of HTTP responses that had an 'Informational' status (a code in the 1xx range).
Expand Down
6 changes: 6 additions & 0 deletions src/i18n/restapi_i18n_nl.properties
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
system_property.plugin.restapi.allowedIPs=Een lijst van IP-adressen die toegang hebben tot de REST API-services. Een lege lijst staat alle IP-adressen toe.
system_property.plugin.restapi.customAuthFilter=De klassenaam van een authenticatie-filter implementatie.
system_property.plugin.restapi.enabled=Schakelt de verwerking van REST API-serviceverzoeken in of uit.
system_property.plugin.restapi.httpAuth=Het authenticatiemechanisme dat wordt gebruikt om REST API-serviceverzoeken te authenticeren.
system_property.plugin.restapi.muc.case-insensitive-lookup.enabled=Namen van MUC-kamers zouden genode-prepped moeten zijn. Dit werd echter niet gegarandeerd in sommige versies van Openfire en deze plugin. Oudere versies van deze plugin gebruikten een hoofdletter-ongevoelige zoekopdracht om hier omheen te werken. Dit vergt behoorlijk wat rekenkracht en zou onnodig moeten zijn. Hierom is dit gedrag configureerbaar gemaakt (standaard-instelling: uit)
system_property.plugin.restapi.muc.room-mutex.enabled=Bepaald of een MUC-kamer-specifieke mutex wordt gebruikt wanneer de API interacteert met een MUC-kamer.
system_property.plugin.restapi.secret=De waarde die wordt gebruikt om verzoeken te authenticeren wanneer authenticatie met een 'gedeeld geheim' wordt gebruikt.
system_property.plugin.restapi.serviceLoggingEnabled=Aanvullende logging van REST API-serviceaanroepen in- of uitschakelen.

stat.restapi_responses.informational.name=REST API 1xx antwoorden
stat.restapi_responses.informational.desc=Het aantal HTTP antwoorden met een 'Informational' status (een code in de 1xx reeks).
Expand Down
12 changes: 6 additions & 6 deletions src/java/org/jivesoftware/openfire/plugin/rest/AuthFilter.java
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
/*
* Copyright (c) 2022.
* Copyright (C) 2022-2026 Ignite Realtime Foundation. All rights reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
Expand Down Expand Up @@ -66,7 +66,7 @@ public void filter(ContainerRequestContext containerRequest) throws IOException
return;
}

if (!plugin.isEnabled()) {
if (!RESTServicePlugin.ENABLED.getValue()) {
LOG.debug("REST API Plugin is not enabled");
throw new WebApplicationException(Status.FORBIDDEN);
}
Expand All @@ -83,7 +83,7 @@ public void filter(ContainerRequestContext containerRequest) throws IOException
return;
}

if (!plugin.getAllowedIPs().isEmpty()) {
if (!RESTServicePlugin.ALLOWED_IPS.getValue().isEmpty()) {
// Get client's IP address
String ipAddress = httpRequest.getHeader("x-forwarded-for");
if (ipAddress == null) {
Expand All @@ -95,7 +95,7 @@ public void filter(ContainerRequestContext containerRequest) throws IOException
}
}
}
if (!plugin.getAllowedIPs().contains(ipAddress)) {
if (!RESTServicePlugin.ALLOWED_IPS.getValue().contains(ipAddress)) {
LOG.warn("REST API rejected service for IP address: " + ipAddress);
throw new WebApplicationException(Status.UNAUTHORIZED);
}
Expand All @@ -109,7 +109,7 @@ public void filter(ContainerRequestContext containerRequest) throws IOException
}

// HTTP Basic Auth or Shared Secret key
if ("basic".equals(plugin.getHttpAuth())) {
if (RESTServicePlugin.AuthType.basic.equals(RESTServicePlugin.AUTH_TYPE.getValue())) {
String[] usernameAndPassword = BasicAuth.decode(auth);

// If username or password fail
Expand Down Expand Up @@ -138,7 +138,7 @@ public void filter(ContainerRequestContext containerRequest) throws IOException
throw new WebApplicationException(Status.UNAUTHORIZED);
}
} else {
if (!auth.equals(plugin.getSecret())) {
if (!auth.equals(RESTServicePlugin.SECRET.getValue())) {
LOG.warn("Wrong secret key authorization. Provided key: " + auth);
throw new WebApplicationException(Status.UNAUTHORIZED);
}
Expand Down
Loading
Loading