<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[Freeswitch-trunk][16200] </title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<div id="header">FreeSWITCH Subversion</div>
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://fisheye.freeswitch.org/changelog/FreeSWITCH?cs=16200">16200</a></dd>
<dt>Author</dt> <dd>intralanman</dd>
<dt>Date</dt> <dd>2010-01-07 12:47:53 -0600 (Thu, 07 Jan 2010)</dd>
</dl>

<h3>Log Message</h3>
<pre><a href="http://jira.freeswitch.org/browse/BOUNTY-12">BOUNTY-12</a></pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#freeswitchtrunksrcmodendpointsmod_sofiasofia_regc">freeswitch/trunk/src/mod/endpoints/mod_sofia/sofia_reg.c</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="freeswitchtrunksrcmodendpointsmod_sofiasofia_regc"></a>
<div class="modfile"><h4>Modified: freeswitch/trunk/src/mod/endpoints/mod_sofia/sofia_reg.c (16199 => 16200)</h4>
<pre class="diff"><span>
<span class="info">--- freeswitch/trunk/src/mod/endpoints/mod_sofia/sofia_reg.c        2010-01-07 16:52:01 UTC (rev 16199)
+++ freeswitch/trunk/src/mod/endpoints/mod_sofia/sofia_reg.c        2010-01-07 18:47:53 UTC (rev 16200)
</span><span class="lines">@@ -1365,7 +1365,7 @@
</span><span class="cx">                 if (ok &amp;&amp; !sofia_test_pflag(profile, PFLAG_BLIND_REG)) {
</span><span class="cx">                         type = REG_AUTO_REGISTER;
</span><span class="cx">                 } else if (!ok) {
</span><del>-                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_WARNING, &quot;IP %s Rejected by acl \&quot;%s\&quot;\n&quot;, network_ip, profile-&gt;reg_acl[x]);
</del><ins>+                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_WARNING, &quot;IP %s Rejected by register acl \&quot;%s\&quot;\n&quot;, network_ip, profile-&gt;reg_acl[x]);
</ins><span class="cx">                         nua_respond(nh, SIP_403_FORBIDDEN, NUTAG_WITH_THIS(nua), TAG_END());
</span><span class="cx">                         goto end;
</span><span class="cx">                 }
</span><span class="lines">@@ -1656,6 +1656,7 @@
</span><span class="cx">         switch_event_t *params = NULL;
</span><span class="cx">         const char *auth_acl = NULL;
</span><span class="cx">         long ncl = 0;
</span><ins>+        sip_unknown_t *un;
</ins><span class="cx"> 
</span><span class="cx">         username = realm = nonce = uri = qop = cnonce = nc = response = NULL;
</span><span class="cx"> 
</span><span class="lines">@@ -1787,6 +1788,17 @@
</span><span class="cx">                 }
</span><span class="cx">         }
</span><span class="cx"> 
</span><ins>+        for (un = sip-&gt;sip_unknown; un; un = un-&gt;un_next) {
+                if (!strncasecmp(un-&gt;un_name, &quot;X-&quot;, 2)) {
+                        if (!zstr(un-&gt;un_value)) {
+                                switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG, &quot;adding %s =&gt; %s to xml_curl request\n&quot;, un-&gt;un_name, un-&gt;un_value);
+                                switch_event_add_header_string(params, SWITCH_STACK_BOTTOM, un-&gt;un_name, un-&gt;un_value);
+                        }
+                } else {
+                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG, &quot;skipping %s =&gt; %s from xml_curl request\n&quot;, un-&gt;un_name, un-&gt;un_value);
+                }
+        }
+
</ins><span class="cx">         if (qop) {
</span><span class="cx">                 switch_event_add_header_string(params, SWITCH_STACK_BOTTOM, &quot;sip_auth_qop&quot;, qop);
</span><span class="cx">         }
</span><span class="lines">@@ -1927,17 +1939,77 @@
</span><span class="cx"> 
</span><span class="cx">         if (auth_acl) {
</span><span class="cx">                 if (!switch_check_network_list_ip(ip, auth_acl)) {
</span><del>-                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_WARNING, &quot;IP %s Rejected by user acl %s\n&quot;, ip, auth_acl);
-                        ret = AUTH_FORBIDDEN;
-                        goto end;
</del><ins>+                        int network_ip_is_proxy, x = 0;
+                        char *last_acl = NULL;
+                        if (profile-&gt;proxy_acl_count == 0) {
+                                switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_WARNING, &quot;IP %s Rejected by user acl [%s] and no proxy acl present\n&quot;, ip, auth_acl);
+                                ret = AUTH_FORBIDDEN;
+                                goto end;
+                        } else {
+                                switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG, &quot;IP %s Rejected by user acl [%s] checking proxy ACLs now\n&quot;, ip, auth_acl);
+                        }
+                        /* Check if network_ip is a proxy allowed to send us calls */
+                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG, &quot;%d acls to check for proxy\n&quot;, profile-&gt;proxy_acl_count);
+                        
+                        for (x = 0; x &lt; profile-&gt;proxy_acl_count; x++) {
+                                last_acl = profile-&gt;proxy_acl[x];
+                                switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG,
+                                                                  &quot;checking %s against acl %s\n&quot;,
+                                                                  ip, last_acl
+                                                                  );
+                                if (switch_check_network_list_ip(ip, last_acl)) {
+                                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG,
+                                                                          &quot;%s is a proxy according to the %s acl\n&quot;,
+                                                                          ip, last_acl
+                                                                          );
+                                        network_ip_is_proxy = 1;
+                                        break;
+                                }
+                        }
+                        /*
+                         * if network_ip is a proxy allowed to send traffic, check for auth
+                         * ip header and see if it matches against the auth acl
+                         */
+                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG, &quot;network ip is a proxy [%d]\n&quot;, network_ip_is_proxy);
+                        if (network_ip_is_proxy) {
+                                int x_auth_ip = 0;
+                                for (un = sip-&gt;sip_unknown; un; un = un-&gt;un_next) {
+                                        if (!strcasecmp(un-&gt;un_name, &quot;X-AUTH-IP&quot;)) {
+                                                switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG,
+                                                                                  &quot;found auth ip [%s] header of [%s]\n&quot;,
+                                                                                  un-&gt;un_name, un-&gt;un_value
+                                                                                  );
+                                                if (!zstr(un-&gt;un_value)) {
+                                                        if (!switch_check_network_list_ip(un-&gt;un_value, auth_acl)) {
+                                                                switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_WARNING, &quot;IP %s Rejected by user acl %s\n&quot;, un-&gt;un_value, auth_acl);
+                                                                ret = AUTH_FORBIDDEN;
+                                                                goto end;
+                                                        } else {
+                                                                switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG,
+                                                                                                  &quot;IP %s allowed by acl %s, checking credentials\n&quot;,
+                                                                                                  un-&gt;un_value, auth_acl
+                                                                                                  );
+                                                                x_auth_ip = 1;
+                                                                break;
+                                                        }
+                                                }
+                                        }
+                                }
+                                if (!x_auth_ip) {
+                                        ret = AUTH_FORBIDDEN;
+                                        goto end;
+                                }
+                        }
+                } else {
+                        switch_log_printf(SWITCH_CHANNEL_LOG, SWITCH_LOG_DEBUG, &quot;IP [%s] passed ACL check [%s]\n&quot;, ip, auth_acl);
</ins><span class="cx">                 }
</span><span class="cx">         }
</span><del>-
</del><ins>+        
</ins><span class="cx">         if (zstr(passwd) &amp;&amp; zstr(a1_hash)) {
</span><span class="cx">                 ret = AUTH_OK;
</span><span class="cx">                 goto skip_auth;
</span><span class="cx">         }
</span><del>-
</del><ins>+        
</ins><span class="cx">         if (!a1_hash) {
</span><span class="cx">                 input = switch_mprintf(&quot;%s:%s:%s&quot;, username, realm, passwd);
</span><span class="cx">                 su_md5_init(&amp;ctx);
</span><span class="lines">@@ -2013,12 +2085,12 @@
</span><span class="cx">                         if (mwi_account) {
</span><span class="cx">                                 switch_event_add_header_string(*v_event, SWITCH_STACK_BOTTOM, &quot;mwi-account&quot;, mwi_account);
</span><span class="cx">                         }
</span><del>-
</del><ins>+                        
</ins><span class="cx">                         if ((uparams = switch_xml_child(user, &quot;params&quot;))) {
</span><span class="cx">                                 xparams_type[i] = 0;
</span><span class="cx">                                 xparams[i++] = uparams;
</span><span class="cx">                         }
</span><del>-
</del><ins>+                        
</ins><span class="cx">                         if (group &amp;&amp; (gparams = switch_xml_child(group, &quot;params&quot;))) {
</span><span class="cx">                                 xparams_type[i] = 0;
</span><span class="cx">                                 xparams[i++] = gparams;
</span></span></pre>
</div>
</div>
<div id="footer">See you at ClueCon</div>

</body>
</html>