[Wocky] Flaw in reciprocal buddy-adding

Greg Hudson ghudson at MIT.EDU
Tue Dec 20 14:31:17 EST 2005


Until today, I never actually added anyone to my Gaim buddies
proactively (except for myself).  I always waited until they added me,
at which point after I authorized them I was asked if I wanted to
reciprocally add them, and I said yes.

Gaim does not seem to request authorization when you reciprocally add
a buddy.  I just tried this with systest (using @mit.edu on all the
JIDs, of course):

  systest adds ghudson as a buddy
  ghudson receives an authorization dialog
  ghudson reciprocally adds systest as a buddy
  systest does *not* receive an authorization dialog
  systest appears offline to gaim, or "Not authorized" if I l-click

If I r-click and "(Re-)request authorization" from systest, systest
gets an authorization dialog and all becomes kosher.

I assume this is a Gaim bug, but it could conceivably be a jabberd bug
if the server is expected to provide reciprocal access.  I will put
this on my list of things to dig into.



More information about the Wocky mailing list