# HG changeset patch # User Matthew Wild # Date 1377775220 -3600 # Node ID a464261deba86ff62b62ce84fce3eb75c0cdf6db # Parent 06e0c279f6a8e546765073643082ee16922665c1 mod_secure_interfaces: New module to mark c2s sessions on given interfaces as 'secure' without encryption diff -r 06e0c279f6a8 -r a464261deba8 mod_secure_interfaces/mod_secure_interfaces.lua --- /dev/null Thu Jan 01 00:00:00 1970 +0000 +++ b/mod_secure_interfaces/mod_secure_interfaces.lua Thu Aug 29 12:20:20 2013 +0100 @@ -0,0 +1,13 @@ +local secure_interfaces = module:get_option_set("secure_interfaces", { "127.0.0.1" }); + +module:hook("stream-features", function (event) + local session = event.origin; + if session.type ~= "c2s_unauthed" then return; end + local socket = session.conn:socket(); + if not socket.getsockname then return; end + local localip = socket:getsockname(); + if secure_interfaces:contains(localip) then + module:log("debug", "Marking session from %s as secure", session.ip or "[?]"); + session.secure = true; + end +end, 2500);