On Thu, Feb 26, 2009 at 5:05 PM, Mickael Remond
<mickael.rem...@process-one.net> wrote:
> Hello,
>
> As a follow-up of the latest XMPP summit in Brussels, we would like to
> request a small but useful addition to XEP-0198.
>
> The feedback is in session resumption:
>
> Is it possible to require the client to pass the full JID of the session
> being resumed ?
>
> With the JID you can simply reconnect to the existing running session
> without having another shared state. It makes a big difference for large scale
> deployment with clustering support.

In this stanza?

<resume xmlns='urn:xmpp:sm:0' previd='some-long-sm-id'/>

Do you mean using the full jid instead of the previd or in addition?
If it's just the jid it can work only if the server sets a resource
with some random data, otherwise it becomes extremely easy to hijack a
sesssion

-- 
Fabio Forno, Ph.D.
Bluendo srl http://www.bluendo.com
jabber id: f...@jabber.bluendo.com

Reply via email to