fix(xmpp): obfuscate client identity in protocol exchanges
Some checks failed
CI Code / Check spelling (pull_request) Successful in 16s
CI Code / Check coding style (pull_request) Successful in 28s
CI Code / Code Coverage (pull_request) Failing after 10m0s
CI Code / Linux (debian) (pull_request) Failing after 12m58s
CI Code / Linux (arch) (pull_request) Failing after 13m56s
CI Code / Linux (ubuntu) (pull_request) Failing after 16m18s

Modify version responses to return a generic client name and omit
version strings. Drop the "profanity." prefix from dynamically
generated JID resources. Clear the XEP-0115 capabilities node URI to
prevent service discovery fingerprinting. These adjustments reduce the
client's attack surface by minimizing identifiable metadata.
This commit is contained in:
2026-07-09 15:23:16 +00:00
parent 60e088ac3c
commit aeb5cfd7db
9 changed files with 56 additions and 18 deletions

View File

@@ -178,7 +178,7 @@ session_connect_with_details(const char* const jid, const char* const passwd, co
saved_details.auth_policy = NULL;
}
// use 'profanity' when no resourcepart in provided jid
// use random string when no resourcepart in provided jid
auto_jid Jid* jidp = jid_create(jid);
if (jidp->resourcepart == NULL) {
auto_gchar gchar* resource = jid_random_resource();