Releases: processone/ejabberd
Release list
26.09
Release notes copied from the original ejabberd 26.09 announcement post:
We are pleased to announce the publication of ejabberd 26.09, which includes several security fixes, some improvements and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.
Contents:
- Security fixes
- Fixed the ordering of some XML child elements
- New option for CAPTCHA POW
- ChangeLog
- Acknowledgments
- Improvements in ejabberd Business Edition
- ejabberd 26.09 download & feedback
Security fixes
This release contains fixes for those security issues:
- Unauthenticated Remote Code Execution on ejabberd (reported by Gia Bui) when:
- ejabberd versions is at least 25.10
- BOSH is enabled on any port
- S2S is enabled
- mod_adhoc_api is loaded
- outbound connectivity from ejabberd on ports epmd (default 4369), s2s (default 5269) and Erlang distribution port (dynamically assigned, typically in the range 49152-65535 unless FIREWALL_WINDOW is set in ejabberdctl.cfg).
- DoS attack on 16.12+ versions if BOSH is enabled on any port.
- Cross-Tenant MUC, Roster and Shared-Roster unauthorized access (reported by Hoang Gia).
Fixed the ordering of some XML child elements
There was a reference-ordering problem in the fast_xml generator, it generated XML encoders that could reorder child elements in a different order from the one declared in the codec specification. From now, the order is the one declared in the codec specification. See details in processone/fast_xml#53
Additionally there was an incorrect sasl2_continue declaration order in the xmpp erlang library: it declared "additional-data, text, tasks". Now it follows the ordering defined in XEP-0388 schema: "additional-data, tasks, text". See details in processone/xmpp#112
New option for CAPTCHA POW
New toplevel option captcha_pow adds a SHA-256 hashcash challenge as described in XEP-0158 in the CAPTCHA form, alongside the image challenge or on its own.
Unlike the image challenge, this does not require setting the option captcha_cmd.
This option is used only by mod_register when registering a new account using In-Band Registration, not in MUC rooms or in mod_register_web. It is disabled by default.
Improved support for vhost-admins
It is well known how to grant administrative privileges to an account: by adding that account to an acl called admin:
acl:
admin:
user: admin1@localhostThe default ejabberd configuration uses this admin ACL in many places:
- the
announceaccess rule used bymod_announce - the
configureaccess rule used bymod_configureand WebAdmin - several
api_permissionsentries used to execute API commands in WebAdmin,mod_adhoc_api,mod_http_api, ... - some
shaper_rules - many options modules, for example
access_adminoption inmod_muc
Consequently, that admin account can administer all of ejabberd: all the global features, all the modules, in all the vhosts... For now let's call it a "global admin".
If you have several vhosts, you can allow specific accounts to administer only specific vhosts. Let's call them "vhost-admins". In this example admin1@localhost can execute commands on all vhosts. Additionally, localhost has a vhost-admin, second has two vhosts-admins, and third has a vhost-admin:
hosts:
- localhost
- second
- third
acl:
admin:
user: admin1@localhost
append_host_config:
localhost:
acl:
aclhostadmin:
- user: hostadmin@localhost
second:
acl:
aclhostadmin:
- user: hostadmin@second
- user: hostadmin@third
third:
acl:
aclhostadmin:
- user: hostadmin@second
api_permissions:
"vhost http access":
from: mod_http_api
who:
access:
allow:
- acl: admin
allow:
- acl: aclhostadmin
what: "*"Example call of a vhost command by a vhost-admin:
$ curl --basic --user hostadmin@third:somepass -k \
'https://localhost:5443/api/status_num_host?host=second&status=dnd'
7
If a vhost-admin tries to execute an API command directed to a vhost he does not administer, or a global command (that has no host argument, and affects all ejabberd), they are rejected:
$ curl --basic --user hostadmin@third:somepass -k \
'https://localhost:5443/api/status_num_host?host=third&status=dnd'
{"code":32,
"message":"AccessRules: Account does not have the right to perform the operation.",
"status":"error"}
$ curl --basic --user hostadmin@third:somepass -k \
'https://localhost:5443/api/stats?name=registeredusers'
{"code":32,
"message":"AccessRules: Account does not have the right to perform the operation.",
"status":"error"}
ChangeLog
Security fixes
- Unauthenticated Remote Code Execution on ejabberd
- DoS attack on BOSH
- Cross-Tenant MUC, Roster and Shared-Roster unauthorized access
Core
- Add
forcevalue toauth_external_user_exists_checkoption - Add XEP-0158 SHA-256 hashcash CAPTCHA challenge (#4594)
- Add gen_mod:get_module_proc_check()
- Fix to preserve reference order in XML, done in fast_xml and xmpp (#4606)
- Get rid of couple
*_to_atom - Make
ejabberd_cluster:*calloperate only on known nodes - More fixes for arguments in commands for vhost-admin
- Optimize
acl:load_tab() ejabberd_systemd: Prefer matching overlength/1- Updated Portuguese-Brazil and Chinese-Simplified translations
Modules
mod_auth_fast: Make sure that fast tokens can be used only with method that they were created formod_invites: don't apply overuse limit ifmax_invitesisinfinity(#4615)mod_invites: don't crash inget_invite_by_invitee_tifreset_tokenpresent (#4620)mod_invites: now that Conversations is for free we remove Yaxim (#4621)mod_mix: Make access_create rule be applied when creating channelmod_mqtt: Add lower limits for pre-auth packetsmod_muc_room: Fix handling of hats request with missing xdatamod_muc_rtbl: Accept also plain account and domain JIDsmod_muc_rtbl: Fix handling of remote ban servers (#4622)mod_register: After changing password disallow password change on currently authenticated sessions
SQL
- Add
db_serializetomod_privacyandmod_pubsub - Add
rename_columnop toejabbrd_sql_schemaupdate routines - Make
rename_columncompatible with older mysql versions ejabberd_sql_schema: Escape all column/table names- Update
mod_rosterserializer with info about approved field
Administration
- Allow vhost-admin to execute MUC commands for his vhost (#4603)
- Fix method to check vhost-admin permission in Host API (#4619)
- WebAdmin: Fix shared roster page when visited by vhost-admin
- WebAdmin: For vhost-admins, hide useless link to node page
- WebAdmin: Show proper domain in URLs, not the first configured vhost
Installers and Container
make-binaries: Bump Elixir to 1.19.6make-binaries: Bump Erlang/OTP version to 28.5.0.7make-binaries: Bump Expat version to 2.8.5make-binaries: Bump JPEG version to 10make-binaries: Bump OpenSSL 3.6.4make-binaries: Bump PNG version to 1.6.58make-binaries: Bump SQLite version to 3530400make-binaries: Bump WebP version to 1.6.0Dockerfile: Workaround to get image withamd64(#4598)
Full Changelog
Acknowledgments
We would like to thank for the security reports provided by:
- Gia Bui from Calif.io
- Hoang Gia
- Nguyễn Huy Hoàng
- Pham Kiet
- On3nvm
the contributions to the source code by:
- rallep71 for the fixes in
fast_xmlandxmppXML child ordering - [Mr...
26.07
Release notes copied from the original ejabberd 26.07 announcement post:
We are publishing this security release ejabberd 26.07, which includes several security fixes, some improvements and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.
Contents:
- Changes in SQL schemas
- Security fixes
- mod_invites: New pages to create invites and WebAdmin
- mod_conversejs: Support ConverseJS 14
- Erlang/OTP 27.0 as a soft minimum
- Rebar/Rebar3: Update binaries to work with Erlang/OTP 26-29
- ChangeLog
- Acknowledgments
- Improvements in ejabberd Business Edition
- ejabberd 26.07 download & feedback
Changes in SQL schema
If you upgrade ejabberd from a previous release to 26.07, there are no changes in SQL schemas, but there is one for ejabberd Business Edition (see below).
Security fixes
This release contains fixes for those security issues:
- It's possible to craft PLAIN auth request and authenticate as one user, but then open session for different one.
mod_capspersistent cache can be poisoned by using legacy version requests.This cache was only used to determine list of nodes that should trigger notifications in PubSub presence-based delivery.- SQL injection in
mod_pubsubhandling of paging requests. - Possible atom exhaustion that can be triggered by issuing REST requests to
mod_http_api. - It was possible to make ejabberd send redirect response for OAuth requests to unvetted url. This required enabling ejabberd to act as OAuth provider (by adding request handler for
ejabberd_oauthin http listener). As part of this fix we changedoauth_client_id_checkdefault value todb. - using ejabberd as OAuth provider will be only allowed by clients
that were previously registered withoauth_add_client_passwordoroauth_add_client_implicitcommands. - Tokens generated by
mod_bosh,captcha,mod_auth_fast,mod_http_uploadandmod_invitesused not cryptographically strong random number generators. - Files server by
mod_http_uploaddidn't have XSS prevention headers. - Issues in authentication of SIP requests.
- Request to web_admin were lacking CSRF protection.
- It was possible to skip captcha verification in mod_register_web.
mod_conversejsallowed putting unescaped value from url in page content.
mod_invites: New pages to create invites and WebAdmin
mod_invites now includes a startpage where regular users can use their account credentials to generate new account creation invites.
This is useful for people using XMPP clients that do no support that feature. The URL of that page is the root of mod_invites; you can find a link to that page in the bottom of WebAdmin left menu.
There are also new WebAdmin pages to view the existing invites, generate new invites, expire, delete ... Go and take a look at WebAdmin > "Virtual Hosts" > one of your hosts > "Invites"
mod_conversejs: Support ConverseJS 14
ConverseJS published version 14.0.0 recently, and it requires some changes in the web server. In this sense, mod_conversejs is updated to support ConverseJS 14, and also got other minor cosmetic improvements.
Erlang/OTP 27.0 as a soft minimum
Are you compiling ejabberd with Erlang/OTP 25 or 26? Then please try to update to Erlang/OTP 27, 28, or 29. For example, the ejabberd installers are compiled with Erlang/OTP 28.5.0.4.
ejabberd supports compilation with Erlang/OTP 25 and 26, and those versions are still tested in runtime.yml and weekly.yml, but those Erlang/OTP versions are not actively maintained anymore by Erlang/OTP.
Following the erlang security recommendation to Use Actively Maintained Versions of Erlang/OTP, from now ejabberd softly rejects compilation with Erlang/OTP lower than 27.
What does softly mean? If you really want to compile ejabberd with Erlang/OTP lower than 27 at your own risk, you can bypass that soft requirement by defining this option (Erlang/OTP 25.0 included Erlang Run-Time System 13.0, and that is the number to provide in that option):
./configure --with-min-erlang=13.0Rebar/Rebar3: Update binaries to work with Erlang/OTP 26-29
ejabberd source code includes Rebar and Rebar3 binaries, in case you don't have installed in your system. But those programs only support four Erlang releases (26 up to 29).
If you want to compile ejabberd with Erlang 25, then you need to grab a compatible Rebar3 (or Rebar) binary: either install one from your operating system, or you can download the old binaries included with ejabberd 26.04 (those still supported Erlang 25):
https://github.com/processone/ejabberd/raw/26.04/rebar
https://github.com/processone/ejabberd/raw/26.04/rebar3
ChangeLog
Security fixes
This release contains fixes for those issues:
- It's possible to craft PLAIN auth request and authenticate as one user, but then open session for different one.
- mod_caps persistent cache can be poisoned by using legacy version requests.
This cache was only used to determine list of nodes that should trigger notifications in PubSub presence-based delivery. - SQL injection in mod_pubsub handling of paging requests.
- Possible atom exhaustion that can be triggered by issuing REST requests to mod_http_api
- It was possible to make ejabberd send redirect response for OAuth requests to unvetted url. This required enabling ejabberd to act as OAuth provider (by adding request handler for ejabberd_oauth in http listener). As part of this fix we changed
oauth_client_id_checkdefault value todb - using ejabberd as OAuth provider will be only allowed by clients
that were previously registered withoauth_add_client_passwordoroauth_add_client_implicitcommands. - Tokens generated by mod_bosh, captcha, mod_auth_fast, mod_http_upload and mod_invites used not cryptographically strong random number generators.
- Files server by mod_http_upload didn't have XSS prevention headers.
- Issues in authentication of SIP requests.
- Request to web_admin were lacking CSRF protection.
- It was possible to skip captcha verification in mod_register_web.
- mod_conversejs allowed putting unescaped value from url in page content.
Core
- Fixes
delete_old_messages_batchcommand when used on pgsql - Adds
export_db_extwhich allows exporting db content to json files - Use constant time functions when doing password checks
- Optimize
room_unused_*commands when room hibernation is configured - We no longer add flag requesting client certificate for tls connections
where certificate authentication is not enabled
Modules
mod_auth_fast: Fixes exception for session that didn't set user agentmod_invites: Add page for creating invites.mod_invites: Fix generation of CSRF tokens.mod_invites: Update to changes in latest XEP-0401mod_http_upload: Attach custom headers from config when serving files.
Full Changelog
Acknowledgments
We would like to thank for the security reports provided by:
- arthurscchan
- EkiXu
- kah-ja
- LautaroPetaccio
- Marius Schwarz
- tinyb0y
- X1AOxiang
the contributions to the source code by:
- Stefan Strigler for the new features, improvements and fixes in
mod_invites - Christian Dröge
- Holger Weiß
- Jonathan Davies
- Kirill A. Korinsky
and the translation by:
- Mr. EddX for updating the Bulgarian translation
- Arif Budiman for updating the Indonesian translation
- TamilNeram for updating the Tamil translation
And also to all the people contributing in the ejabberd chatroom, issue tracker...
Improvements in ejabberd Business Edition
Customers of the ejabberd Business Edition, in addition to all those bugfixes, also get the following changes:
Changes in SQL schema
This release modifies the push_customizations table in the SQL database schemas to support the new push notifications mute option (see below). This task is performed automatically by ejabberd by default.
However, if your configuration file has disabled update_sql_schema toplevel option, you must perform the SQL schem...
26.04
Release notes copied from the original ejabberd 26.04 announcement post:
We are publishing this security release ejabberd 26.04, which includes options to limit XML parser, and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.
Contents:
New limits options for XML parser
This release adds new options that limit max memory used by XML parser used to process XMPP payloads, to prevent potential Denial of Service attack. The default values for pre-auth provide sufficient protection for ejabberd against non-authenticated users on c2s and s2s, so there is no need to change your configuration.
The option max_stanza_elements sets a limit on the maximum number of XML elements that an individual stanza can contain. By default, this option is set to infinity.
The pair of options pre_auth_max_stanza_elements and pre_auth_max_stanza_size define separate limits for sessions that haven't authenticated yet. The session will switch to the limits defined by the options max_stanza_elements and max_stanza_size after the client has successfully authenticated. The default values for these options are: 32 for pre_auth_max_stanza_elements and 8192 for pre_auth_max_stanza_size.
All those options are recognized inside listener sections, and can be applied to ejabberd_c2s and ejabberd_s2s_in listeners.
ChangeLog
Core
- Add new listener options to limit xml parser accepted input
- Improve
leave_clustercommand to work even in own node - New predefined keyword
DATABASE_PATHthat points to the Mnesia spool dir - Support HOST keyword in
sql_databasetoplevel option, set nice default value - Provide more details in log messages when using SQLite
- Update documentation of jwt_key to match the Docs site
- ejabberd_config: New default_ram_db/3 clause that checks module support
- ejabberd_sm: Remove session_counter, used for get_vh_session_number now removed
Modules
mod_http_fileserver: Use integer inejabberd_hooks:addas expected by "make hooks"mod_invites: Add--enable-bootstrap=noto configure options to bypass download (#4558)mod_invites: don't crash inget_invite_by_invitee_tfor sql backend (#4566)mod_invites: quick howto for creating integrity check checksumsmod_invites: remove dependency on jquerymod_mqtt: Define RAM callbacks as optionalmod_mqtt: Usedefault_ram_dbonly if it really supports RAM storagemod_roster: Fix bug introduced in 26.03 in commit d5c1440 (#4564)mod_roster_sql: Castapprovedinteger as boolean when exporting Mnesia to SQLmod_shared_roster_sql: Fix typo introduced 10 years ago in commit 0ea0ba3
Container and Installers
- Bump Erlang/OTP 28.4.2
- make-binaries: Bump OpenSSL to 3.5.6
Full Changelog
Acknowledgments
We would like to thank the contributions to the source code, documentation, and translation provided for this release by:
- Stefan Strigler for the improvements in
mod_invites
And also to all the people contributing in the ejabberd chatroom, issue tracker...
ejabberd 26.04 download & feedback
As usual, the release is tagged in the Git source code repository on GitHub.
The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.
For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.
The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.
If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.
26.03
Release notes copied from the original ejabberd 26.03 announcement post:
We are pleased to announce another bugfix release: ejabberd 26.03. This brings support for roster pre-approval, and more than 100 commits with bugfixes all around, many of them dedicated to the new mod_invites, including also many security fixes.
If you are upgrading from a previous version, there is a change in the SQL schemas, please read below. There are no changes in configuration, API commands or hooks.
Contents:
- Changes in SQL schemas
- SASL channel binding changes
- ChangeLog
- Acknowledgments
- Improvements in ejabberd Business Edition
- ejabberd 26.03 download & feedback
Changes in SQL schema
This release adds a new column to the rosterusers table in the SQL database schemas to support roster pre-approval. This task is performed automatically by ejabberd by default.
However, if your configuration file has disabled update_sql_schema toplevel option, you must perform the SQL schema update manually yourself. Those instructions are valid for MySQL, PostgreSQL and SQLite, both default and new schemas:
ALTER TABLE rosterusers ADD COLUMN approved boolean NOT NULL AFTER subscription;SASL channel binding changes
This version adds ability to configure handling of client flag "wanted to use channel-bindings but was not offered one".
By default ejabberd will abort connections that present this flag, as that could mean that between server and client is
rogue MITM proxy that strips exchanged data with informations that are required for this.
This can cause problems for servers that use proxy server that terminated TLS connection (there is MITM proxy, but approved by server admin). To be able to handle this situation, we added code that ignore this flag, if server admin disable channel-binding handling by disabling -PLUS auth mechanisms in config file:
disable_sasl_mechanisms:
- SCRAM-SHA-1-PLUS
- SCRAM-SHA-256-PLUS
- SCRAM-SHA-512-PLUSWe also ignore this flag for SASL2 connections if offered authentication methods filtered by available user passwords did disable all -PLUS mechanisms.
ChangeLog
Core
- Fix mysql authentication for tls connections that required auth plugin switch
- Improve handling of scram "wanted to use channel-bindings but was not offered one" flag
- Add ability for mod_options values to depend on other options
- Don't fail to classify stand-alone chat states
- Fix some warnings compiling with Erlang/OTP 29 (#4527)
ejabberd_ctl: Document how to set empty lists in ejabberdctl and WebAdminejabberd_http: Add handling ofEtagandIf-Modified-Sinceheaders to files served bymod_http_uploadejabberd_http: Ignore whitespaces at end of host header- SQL: Add ability to mark that column can be null in e_sql_schema
- Tests: Add tests for sasl2
- Tests: Make table cleanup in test more robust
Modules
mod_fast_auth: Offered methods are based on available channel bindingsmod_http_api: Always hide password in log entriesmod_mam: Callstore_mam_messagehook for messages thatuser_mucsub_from_muc_archivewas filtering outmod_mam_sql: Only provide the new XEP-0431fulltextfield, not old customwithtextmod_muc_room: Fix duplicate stanza-id in muc mam responses generated from local history (#4544)mod_muc_room: Fix hook name in commit 7732984 (#4526)mod_pubsub_serverinfo: Don't usegen_server:callfor resolving pubsub hostmod_roster: Add support for roster pre-approval (#4512)mod_roster: Fix display of groups in WebAdmin when it's a listmod_roster: in WebAdmin page, first execute SET actions, later GETmod_roster_mnesia: Improve transformation code
mod_invites
- Makefile: Run invites-deps only when files are missing
- Fix path to bootstrap files
- Check at start time the syntax of landing_page option (#4525)
- Send 'Link' http header (#4531)
- Set meta.pre-auth to skip redirect_url if token validated (#4535)
- Many security fixes (#4539)
- Add favicon and change color to match ejabberd branding
- Enable dark mode
- Add support for webchat_url
- Migrate to bootstrap5 and update jquery
- No inline scripts
- Make format csrf token
- Add csrf token to failed post
- Include js/css deps in static dir
- Correct hashes for bootstrap 4.6.2
- Hint at type for landing_page opt
- Many more security fixes (#4538)
- Check CSRF token in register form
- Add integrity hashes to scripts and css
- Comment unused resources
- Add security headers
- Remove debug log of whole query parameters (including pw)
- Don't crash on unknown host from http host header
- Make creating invite transactional
- Set overuse limits (#4540)
- Fix broken path when behind proxy with prefix (#4547)
Container and Installers
- Bump Erlang/OTP 28.4.1
- make-binaries: Bump libexpat to 2.7.5
- make-binaries: Bump zlib to 1.3.2
- make-binaries: Enable missing crypto features (#4542)
Translations
- Update Bulgarian translation
- Update Catalan and Spanish translations
- Update Chinese Simplified translation
- Update Czech translation
- Update French translation
- Update German translation
Acknowledgments
We would like to thank the contributions to the source code, documentation, and translation provided for this release by:
- Stefan Strigler for the roster pre-approval feature, sponsored by NLnet
- Stefan Strigler for the improvements in
mod_invites - Holger Weiß for improvements in binary installers
- Mr. EddX for updating the Bulgarian translation
- Sketch6580 for updating the Chinese (Simplified) translation
- ffunk for updating the Czech translation
- Dyxux for updating the French translation
- Stefan Strigler for updating the German translation
And also to all the people contributing in the ejabberd chatroom, issue tracker...
Improvements in ejabberd Business Edition
Customers of the ejabberd Business Edition, in addition to all those improvements and bugfixes, also get the following changes:
- Add p1db backend for mod_auth_fast
- Fix issue when cleaning MAM messages stored in p1db
- mod_unread fixes
- Web push fixes
Full Changelog
ejabberd 26.03 download & feedback
As usual, the release is tagged in the Git source code repository on GitHub.
The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.
For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.
The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.
If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.
26.02
Release notes copied from the original ejabberd 26.02 announcement post:
Contents:
- ChangeLog
- Acknowledgments
- Improvements in ejabberd Business Edition
- ejabberd 26.02 download & feedback
ChangeLog
- Fixes issue with adding hats data in presences send by group chats (#4516)
- Removes
mod_muc_occupantidmodules, and integrates its functionality directly intomod_muc(#4521) - Fixes issue with reset occupant-id values after restart of ejabberd (#4521)
- Improves handling of mediated group chat invitations in
mod_block_stranger(#4523) - Properly install
mod_invitestemplates inmake installcall (#4514) - Better errors in
mod_invites(#4515) - Accessibility improvements in
mod_invites(#4524) - Improves handling of request with invalid url encoded values in request handled by
ejabberd_http - Improves handling of invalid responses to disco queries in
mod_pubsub_serverinfo - Fixes conversion of MUC room configs from ejabberd older than 21.12
- Fixes to autologin in WebAdmin
If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.
Notice that mod_muc now incorporates the feature from mod_muc_occupantid, and that module has been removed. You can remove mod_muc_occupantid in your configuration file as it is unnecessary now, and ejabberd simply ignores it.
Check also the commit log: 26.01...26.02
Acknowledgments
We would like to thank the contributions to the source code and translations provided by:
- Stefan Strigler for the improvements in
mod_invites - Mr. EddX for updating the Bulgarian translation
- Sketch6580 for updating the Chinese (Simplified) translation
- ffunk for updating the Czech translation
- Stefan Strigler for updating the German translation
And also to all the people contributing in the ejabberd chatroom, issue tracker...
Improvements in ejabberd Business Edition
Customers of the ejabberd Business Edition, in addition to all those improvements and bugfixes, also get the following change:
- Change
default_ram_dbfrommnesiatop1dbwhen usingp1dbcluster_backend
ejabberd 26.02 download & feedback
As usual, the release is tagged in the Git source code repository on GitHub.
The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.
For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.
The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.
If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.
26.01
Release notes copied from the original ejabberd 26.01 announcement post:
We are pleased to announce ejabberd 26.01. This release addresses real operational pain points: export your data from one database backend and import it into another, and let your users invite others without opening the gates to spam.
This release is the result of three months of development, implementing those new features, and fixing bugs.
Release Highlights:
If you are upgrading from a previous version, there are no mandatory changes in SQL schemas, configuration, API commands or hooks. However new mod_invites uses a new table in databases, see below.
Other contents:
- SQL table for
mod_invites - New
replaced_connection_timeout - Improved
mod_http_fileserverdocrootoption - Supported XEP Versions
- Erlang, Elixir and Container
- Improved
ERL_DIST_PORT - New
make relivectl - WebAdmin Menu Links
- Acknowledgments
- Improvements in ejabberd Business Edition
- ChangeLog
- ejabberd 26.01 download & feedback
Below is a detailed breakdown of the improvements and enhancements:
Database Serialization
This feature adds new way for migrating data between database backends by exporting data from one backend to a file and importing that into different backend (or possibly to same backend but on different machine).
Migrating data using this can be executed by first exporting all data with export_db command, changing configuration of ejabberd and switching modules to use new database backend, and then importing previously exported data using import_db command.
This mechanism works by calling those new command from ejabberdctl, for exporting data:
ejabberdctl export_db <host name> <path to directory where exported files should be placed>ejabberdctl export_db_abort <host name>ejabberdctl export_db_status <host name>
and for importing:
ejabberdctl import_db <host name> <path to directory with exported data>ejabberdctl import_db_abort <host name>ejabberdclt import_db_status <host name>
Exporting and importing work in background after starting them from ejabberdctl (commands executed by ejabberdctl have time limit for how long they can work, with this setup there should be not issue with export or import getting aborted by that), and current progress of background operation can be tracked by calling corresponding *_db_status command. Operation in progress can be also aborted by executing *_db_abort command.
Roster Invites and Invite-based Account Registration
Until now the canonical method to register an account in ejabberd was to let anybody register accounts using In-Band Registration (IBR) (mod_register) or Web Registration (mod_register_web), and then try to limit abuse with access limitations or CAPTCHAs. Often this process got abused, with the result that account registration had to be disabled and rely on manual registration by administrators.
The new mod_invites implements support for invite-based account registration: administrators can generate invitation URLs, and send them to the desired users (by email or whatever). Then the user that receives an invitation can visit this invitation URL to register a new account.
On top of that, mod_invites lets you create Roster Invites: you can send a link to some other person so they can connect to you in a very user-friendly and intuitive way that doesn't require any further interaction. If account creation is allowed, these links will also allow to setup an account in case the recipient doesn't have one yet.
Relevant links:
- mod_invites documentation
- Great Invitations, the original Prosody blog post that described this feature
- XEP-0379: Pre-Authenticated Roster Subscription
- XEP-0401: Ad-hoc Account Invitation Generation
- XEP-0445: Pre-Authenticated In-Band Registration
- This development was funded by NLnet
Quick setup:
-
If using SQL storage for the modules and have disabled the update_sql_schema toplevel option, then create manually the SQL table, see below.
-
If you plan to use the landing page included with
mod_invites, install JavaScript libraries jQuery version 3.7.1 and Bootstrap version 4.6.2. This example configuration will assume they are installed in/usr/share/javascript. Theejabberdcontainer image already includes those libraries. Some quick examples, in case you need some help:-
Debian and related:
apt install libjs-jquery libjs-bootstrap4
-
AlpineLinux and other operating systems where you can install
npm, for example:apk -U add --no-cache nodejs npm ca-certificates npm init -y \ && npm install --silent jquery@3.7.1 bootstrap@4.6.2 mkdir -p /usr/share/javascript/jquery mkdir -p /usr/share/javascript/bootstrap4/{css,js} cp node_modules/jquery/dist/jquery.min.js /usr/share/javascript/jquery/ cp node_modules/bootstrap/dist/css/bootstrap.min.css /usr/share/javascript/bootstrap4/css/ cp node_modules/bootstrap/dist/js/bootstrap.min.js /usr/share/javascript/bootstrap4/js/ -
Generic method using the included script:
tools/dl_invites_page_deps.sh /usr/share/javascript
-
-
Configure ejabberd to serve the JavaScript libraries in path
/share; serve mod_invites in any path of your selection; and enable mod_invites with some basic options. Remember to setup mod_register to allow registering accounts using mod_invites. For example:listen: - port: 5443 ip: "::" module: ejabberd_http tls: true request_handlers: /invites: mod_invites /share: mod_http_fileserver modules: mod_http_fileserver: docroot: /share: /usr/share/javascript mod_invites: access_create_account: configure landing_page: auto mod_register: allow_modules: - mod_invites
-
There are many ways to generate invitations:
- Login with an admin account, then you can execute Ad-Hoc Commands like "Invite User" and "Create Account"
- If mod_adhoc_api is enabled, you can execute equivalent API Commands generate_invite and generate_invite_with_username
- Run those API Commands from the command-line, for example:
ejabberdctl generate_invite localhost
-
All those methods give you an invitation URL that you can send it to the desired user, and looks like
https://localhost:5443/invites/Yrw5nuC1Kpxy9ymbRzmVGzWQ -
The destination user (or yourself) can visit that invitation URL and follow the instructions to register the account and download a compatible client.
If the user has installed already a compatible XMPP client, you don't no need to install JavaScript libraries and setup a landing page. In that case, when generating an invitation you will get only the XMPP URI; when the user opens that URI in a web browser, it will automatically open the XMPP client and the corresponding registration window.
Probably you don't want to expose the port directly, then you need to setup Nginx or Apache to act as a "reverse" proxy and change your landing_page parameter accordingly, for example just https://@HOST@/invites/{{ invite.token }}
Notice that the landing page can be fully translated using the existing ejabberd localization feature.
SQL table for mod_invites
There is a new table invite_token in SQL schemas, used by the new mod_invites. If you want to use this module, there are two methods to update the SQL schema of your existing database:
If using MySQL or PosgreSQL, you can enable the option update_sql_schema and ejabberd will take care to update the SQL schema when needed: add in your ejabberd configuration file the line update_sql_schema: true
Notice that support for MSSQL in mod_invites has not yet been implemented or tested.
If you are using other database,...
25.10
Release notes copied from the original ejabberd 25.10 announcement post:
Release Highlights:
If you are upgrading from a previous version, there are no mandatory changes in SQL schemas, configuration, API commands or hooks.
Other contents:
- New option
archive_muc_as_mucsubinmod_mam - Removed support for Erlang/OTP older than 25.0
- Support for the new Erlang
maybeexpression - Rename
NewSQL schema toMultihost, andDefaulttoSinglehost - Improved GitHub Workflows
- Acknowledgments
- Improvements in ejabberd Business Edition
- ChangeLog
- ejabberd 25.10 download & feedback
Below is a detailed breakdown of the improvements and enhancements:
New option archive_muc_as_mucsub in mod_mam
When this option is enabled incoming groupchat messages for users that have MucSub subscription to a room from which message originated will have those messages archived after being converted to mucsub event messages.
Removed support for Erlang/OTP older than 25.0
The ejabberd 24.12 release announcement explained that support for Erlang/OTP older than 25.0 was discouraged, it would be deprecated in future releases, and completely removed sometime after ejabberd 25.01. That explanation was mentioned several times in the subsequent ejabberd releases.
The initial reason to require Erlang/OTP 25 was that this version is the lowest we can easily use nowadays for running the CI tests.
Other reasons to remove support for Erlang lower than 25 are: to support maybe expression, and to remove duplicate code.
In order to support both new and very old Erlang/OTP versions, ejabberd source code included many duplicate code. All that duplicate code that is nowadays useless will be removed in a future ejabberd release.
Support for the new Erlang 'maybe' expression
The new maybe expression is supported since Erlang/OTP 25 (requires being enabled), and it is enabled by default since 27.
Now that ejabberd requires Erlang/OTP 25, and it enables the maybe expression, this can be used freely in ejabberd source code and modules.
See:
- Erlang Documentation:
maybeExpression - EEP 49: Value-Based Error Handling Mechanisms
Rename 'New' SQL schema to 'Multihost', and 'Default' to 'Singlehost'
When ejabberd first got support for SQL storage, it only supported one vhost, so it made sense to not store the host in the SQL tables. Additionally, the SQL schema in ejabberd followed that of jabberd14, which didn't support multiple vhosts either.
When ejabberd got support for multiple vhosts, if several of them want to use SQL storage, the solution is to configure a different SQL database for each vhost using the host_config toplevel option.
However, when there are many vhosts configured in ejabberd, all of them using SQL storage, it is preferable to setup one single SQL database, and store the vhost in the tables. When that feature was added to ejabberd, it got the name of "new SQL schema". And the previous SQL schema was called "legacy", "old", and nowadays "default".
The problem with the terms "default" and "new" is that they are circumstantial, and do not really describe the schema features or purposes.
Now those terms have been renamed:
- "default SQL schema" ⟹ "singlehost SQL schema"
- "new SQL schema" ⟹ "multihost SQL schema"
Right now all names are supported, the previous (obsolete) and the renamed (preferred). No changes are needed in your existing configuration file or building instructions, but it is preferable if you can update your setup to the new terms:
When preparing configuration, the old and new arguments are:
./configure --enable-new-sql-schema
./configure --enable-multihost-sql-schema
When configuring ejabberd, the old and new toplevel options are:
new_sql_schema: true
sql_schema_multihost: true
When developing source code, the old and new functions are:
ejabberd_sql:use_new_schema()
ejabberd_sql:use_multihost_schema()
New API Commands
Several ejabberd modules implement new API Commands, most of them inspired by XEP-0133:
ejabberd_admin:- mod_admin_extra:
- mod_announce:
- mod_muc_admin:
Added more Ad-Hoc Commands from XEP-0133
XEP-0133 describes 31 administrative tasks that should be available as ad-hoc commands.
ejabberd already implemented many of those ad-hoc commands in mod_configure, but there were a few missing that nowadays are fairly easy to implement: this new ejabberd release supports all of them... except 5.
The five ad-hoc commands from XEP-0133 that are not supported are:
6. Get User Password, because it was already retracted in the XEP and should not be implemented12. Edit Whitelist, because the corresponding feature is not implemented in ejabberd27. Set Welcome Message, because in ejabberd this message is set in the configuration file, optionwelcome_messageof mod_register28. Delete Welcome Message, for similar reason29. Edit Admin List, because in ejabberd the administrative rights to accounts are granted in the configuration file, toplevel optionacl.
On the other hand, ejabberd implements more than 200 API commands in all over its source code, providing those and many other administrative tasks. And you can execute those API commands using the command line, ReST calls, XML-RPC, WebAdmin, ... and ad-hoc commands too!!! See the available API frontends.
Nowadays, all the ad-hoc commands described in XEP-0133 have a similar API command in ejabberd that you can execute using ad-hoc commands too:
| Ad-hoc command in XEP-0133 | Status in ejabberd 25.10 | Equivalent API command |
|---|---|---|
| Add User | 〽️ (no vCard arguments) | register |
| Delete User | ✅ | unregister |
| Disable User | ✅ | ban_account |
| Re-Enable User | ✅ | unban_account |
| End User Session | 〽️ (argument) | kick_session |
| Get User Password (retracted) | check_password | |
| Change User Password | ✅ | change_password |
| Get User Roster | 〽️ (result syntax) | get_roster |
| Get User Last Login Time | ✅ | get_last |
| Get User Statistics | ✅ | user_sessions_info |
| Edit Blacklist | add_blocked_domain | |
| Edit Whitelist | ❌ | - |
| Get Number of Registered Users | ✅ | stats |
| Get Number of Disabled Users | ✅ | count_banned |
| Get Number of Online Users | ✅ | stats |
| Get Number of Active Users | ✅ | [status_num](https://docs.ejabberd.im/developer/ejabberd-api/admi... |
25.08
Release notes copied from the original ejabberd 25.08 announcement post:
Release Highlights:
This release includes the support for Hydra rooms in our Matrix gateway, which fixes high severity protocol vulnerabilities.
- Improvements in Matrix gateway
- Fixed ACME in Erlang/OTP 28.0.2
- New
mod_providersto serve XMPP Providers file
If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.
Other contents:
- Improved Unicode support in configuration
- New option
conversejs_pluginsto enable OMEMO - Easier erlang node name change with
mnesia_change - Colorized interactive log
- Document API tags in modules
- Acknowledgments
- Improvements in ejabberd Business Edition
- ChangeLog
- ejabberd 25.08 download & feedback
Below is a detailed breakdown of the improvements and enhancements:
Improvements in Matrix gateway
The ejabberd Matrix gateway now supports Hydra rooms (Matrix room version 12). This fix some high severity protocol vulnerabilities. The state resolution has been partially rewritten in our gateway.
A double colon is used for separating a matrix server from a room ID in JID with Hydra rooms.
Other changes to the matrix gateway:
- The new option
notary_serversofmod_matrix_gwcan now be used to set a list of notary servers. - Add
leave_timeoutoption tomod_matrix_gw(#4386) - Don't send empty direct Matrix messages (thanks to snoopcatt) (#4420)
Fixed ACME in Erlang/OTP 28.0.2
The ejabberd 25.07 release notes mentioned that Erlang/OTP 28.0.1 was not yet fully supported because there was a problem with ACME support.
Good news! this problem with ACME is fixed and tested to work when using Erlang/OTP 28.0.2, the latest p1_acme library, and ejabberd 25.08.
If you are playing with ejabberd and Erlang/OTP 28, please report any problem you find. If you are running ejabberd in production, better stick with Erlang/OTP 27.3, this is the one used in installers and container images.
New mod_providers to serve XMPP Providers file
mod_providers is a new module to serve easily XMPP Providers files.
The standard way to perform this task is to first generate the Provider File, store in the disk with the proper name, and then serve the file using an HTTP server or mod_http_fileserver. And repeat this for each vhost.
Now this can be replaced with mod_providers, which automatically sets some values according to your configuration. Try configuring ejabberd like:
listen:
-
port: 443
module: ejabberd_http
tls: true
request_handlers:
/.well-known/xmpp-provider-v2.json: mod_providers
modules:
mod_providers: {}Check the URL https://localhost:443/.well-known/xmpp-provider-v2.json, and finetune it by setting a few mod_providers options.
Improved Unicode support in configuration
When using non-latin characters in a vhost served by ejabberd, you can write it in the configuration file as unicode, or using the IDNA/punycode. For example:
hosts:
- localhost1
- locälhost2
- xn--loclhost4-x2a
- 日本語
host_config:
"locälhost2":
modules:
mod_disco: {}
mod_muc:
host: "conference3.@HOST@"
"xn--loclhost4-x2a":
modules:
mod_disco: {}
mod_muc:
host: "conference4.@HOST@"This raises a problem in mod_http_upload if the option put_url contains the @HOST@ keyword. In that case, please use the new predefined keyword HOST_URL_ENCODE.
This change was also applied to ejabberd.yml.example.
New option conversejs_plugins to enable OMEMO
mod_conversejs gets a new option conversejs_plugins that points to additional local files to include as scripts in the homepage.
Right now this is useful to enable OMEMO encryption.
Please make sure those files are available in the path specified in conversejs_resources option, in subdirectory plugins/. For example, copy a file to path /home/ejabberd/conversejs-x.y.z/package/dist/plugins/libsignal-protocol.min.js and then configure like:
modules:
mod_conversejs:
conversejs_resources: "/home/ejabberd/conversejs-x.y.z/package/dist"
conversejs_plugins: ["libsignal-protocol.min.js"]If you are using the public Converse client, then you can set "libsignal", which gets replaced with the URL of the public library. For example:
modules:
mod_conversejs:
conversejs_plugins: ["libsignal"]
websocket_url: "ws://@HOST@:5280/websocket"Easier erlang node name change with mnesia_change
ejabberd uses by default the distributed Mnesia database. Being distributed, Mnesia enforces consistency of its file, so it stores the Erlang node name, which may include the hostname of the computer.
When the erlang node name changes (which may happen when changing the computer name, or moving ejabberd to another computer), then mnesia refused to start with an error message like this:
2025-08-21 11:06:31.831594+02:00 [critical]
Erlang node name mismatch:
I'm running in node [ejabberd2@localhost],
but the mnesia database is owned by [ejabberd@localhost]
2025-08-21 11:06:31.831782+02:00 [critical]
Either set ERLANG_NODE in ejabberdctl.cfg
or change node name in Mnesia
To change the computer hostname in the mnesia database, it was required to follow a tutorial with 10 steps that starts ejabberd a pair of times and runs the mnesia_change_nodename API command.
Well, now all this tutorial is implemented in one single command for the ejabberdctl command line script. When mnesia refuses to start due to an erlang node name change, it mentions that new solution:
$ echo "ERLANG_NODE=ejabberd2@localhost" >>_build/relive/conf/ejabberdctl.cfg
$ ejabberdctl live
2025-08-21 11:06:31.831594+02:00 [critical]
Erlang node name mismatch:
I'm running in node [ejabberd2@localhost],
but the mnesia database is owned by [ejabberd@localhost]
2025-08-21 11:06:31.831782+02:00 [critical]
Either set ERLANG_NODE in ejabberdctl.cfg
or change node name in Mnesia by running:
ejabberdctl mnesia_change ejabberd@localhost
Let's use the new command to change the erlang node name stored in the mnesia database:
$ ejabberdctl mnesia_change ejabberd@localhost
==> This changes your mnesia database from node name 'ejabberd@localhost' to 'ejabberd2@localhost'
...
==> Finished, now you can start ejabberd normallyGreat! Now ejabberd can start correctly:
$ ejabberdctl live
...
2025-08-21 11:18:52.154718+02:00 [info]
ejabberd 25.07.51 is started in the node ejabberd2@localhost in 1.77sNotice that the command mnesia_change must start and stop ejabberd a pair of times. For that reason, it cannot be implemented as an API command. Instead, it is implemented as an ejabberdctl command directly in the ejabberdctl command line script.
Colorized interactive log
When ejabberd starts with an erlang shell using Mix, it prints error lines in a remarkable color: orange for warnings and red for errors. This helps to detect those lines when reading the log interactively.
Now this is also supported when using Rebar3. To test it, start ejabberd either:
ejabberdctl live: to start interactive mode with erlang shellejabberdctl foreground: to start in server mode with attached log output
You will see log lines colorized with:
- green+white for informative log messages
- grey for debug
- yellow for warnings
- red for errors
- magenta for messages coming from other Erlang libraries (xmpp, OTP library), not ejabberd itself
Document API Tags in modules
Many ejabberd modules implement their own API commands, and now the documentation of those modules mention which tags contain their commands.
See for example at the end of modules [...
25.07
Release notes copied from the original ejabberd 25.07 announcement post:
We are pleased to announce a new ejabberd release: ejabberd 25.07, with three months of work and more than 110 commits to bring new modules, new features, improvements and bugfixes.
Release Highlights:
This release focus on integration in a wider federated network, with support for spam fighting features, better compliance with Matrix network and native support for PubSub Server Information to have your server count as part of the wider XMPP network (for example, you can register your server on XMPP Network Graph.
- Spam filter with block lists support
- Support for XEP-0485: PubSub Server Information
- Support for older Matrix rooms in ejabberd XMPP <-> Matrix Gateway
If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.
Other contents:
- Workaround for zip module in unpatched Erlang
- Erlang/OTP 28 supported
- Erlang/OTP 25 required
- New mod_antispam with RTBL support
- New mod_pubsub_serverinfo
- Improvements in Matrix gateway
- XEP-0431: Full Text Search in MAM
- New rest_proxy options
- New auth_password_types_hidden_in_scram1 option
- New host_alias option
- New predefined keywords
- Link to Converse in WebAdmin
- Updates in source code formatting
- New target test-group
- Acknowledgments
- Improvements in ejabberd Business Edition
- ChangeLog
- ejabberd 25.07 download & feedback
Below is a detailed breakdown of the improvements and enhancements:
Workaround for zip module in unpatched Erlang
A vulnerability was published three weeks ago that affects the zip library included in Erlang/OTP: CVE-2025-4748: Absolute path in zip module.
The ejabberd installers and the ejabberd container image already use a patched version Erlang/OTP 27.3.4.1, but the ecs container image uses Erlang/OTP 26.2.
ejabberd 25.07 includes a specific protection that workarounds that vulnerability regardless of what Erlang/OTP version you are using.
Erlang/OTP 28 supported
Updating ejabberd to support Erlang/OTP 28 has required quite some work due to the replacement of ancient ASN.1 modules from Erlang/OTP public_key library.
Improvements were done on ejabberd, fast_xml, p1_acme, xmpp libraries, and also rebar/rebar3 binaries were recompiled.
However, there is still one last problem not yet solved which implies that ACME support is broken when using Erlang/OTP 28.0.1. The fix will probably be included in the next Erlang/OTP 28 release.
Erlang/OTP 25 required
The minimum Erlang/OTP version supported since now is 25.0.
However, we are aware there are still a few specific cases where older Erlang/OTP versions are being used. For that reason, the source code support for those versions is still available, and static source code analysis tools like xref and dialyzer are still run with Erlang/OTP 20 in runtime.yml.
If you really need to use ejabberd with Erlang/OTP 20 - 24, you can bypass the version check during compilation with this ./configure option: ./configure --with-min-erlang=9.0.5
New mod_antispam with RTBL support
mod_antispam is a new module that filters spam messages and subscription requests received from remote servers based on Real-Time Block Lists (RTBL), text lists of known spammer JIDs and/or URLs mentioned in spam messages.
This module is based in mod_spam_filter which was originally published in ejabberd-contrib. If you were using that module, you can update your configuration and start using mod_antispam instead.
New mod_pubsub_serverinfo
mod_pubsub_serverinfo adds support for XEP-0485: PubSub Server Information to expose S2S information over the Pub/Sub service.
This module was originally published in ejabberd-contrib. If you were using that module, you can remove it, as now it's included in ejabberd.
Improvements in Matrix gateway
While we are preparing another big update for the Matrix gateway. The most important change is that we added support to a larger number of room versions. It allows users to let them join a lot of rooms that were already created a while back and running an older version of the room protocol.
Here is the main list of changes to the matrix gateway:
mod_matrix_gw: Support older Matrix rooms versions starting from version 4mod_matrix_gw: Don't send empty messages in Matrix rooms (#4385)mod_matrix_gw: Fix key validation in mod_matrix_gw_s2s:check_signaturemod_matrix_gw: When encoding JSON, handle term that is key-value list (#4379)
XEP-0431: Full Text Search in MAM
Support for XEP-0431: Full Text Search in MAM has been added. For now, it only works if mod_mam is using the MySQL storage backend.
New rest_proxy options
With those new options you can make modules using rest.erl module (like ejabberd_oauth_rest) use HTTP proxy when performing HTTP requests.
The related new top level options are:
rest_proxy: Address of a HTTP Connect proxyrest_proxy_port: Port of a HTTP Connect proxyrest_proxy_username: Username used to authenticate to HTTP Connect proxy (optional)rest_proxy_password: Password used to authenticate to HTTP Connect proxy (optional)
New auth_password_types_hidden_in_scram1 option
This option was added to help with adding new password types in auth_stored_password_types option to existing installations. Adding new password type made server advertise it to clients, but that caused problems for users that didn't have new password type stored, and which clients used SASL1 authentication, if client tried to authenticate with it, authentications would fail.
With this new option, server admin can choose which password types should not be presented to SASL1 clients (they still will be offered to SASL2 clients for users that have password compatible with this type), to later after users update password to have new type, being able to enable them.
This option takes list of password types from auth_stored_password_types that should be disabled
auth_password_types_hidden_in_scram1:
- scram_sha512
- scram_sha256New hosts_alias option
The new hosts_alias toplevel option is used by the ejabberd_http listener to resolve domain names into vhosts served by ejabberd.
For example, ejabberd is serving the vhost redacted.lan, but you configured DNS so xmpp.redacted.lan resolves to that host. If you configure in ejabberd:
hosts:
- redacted.lan
hosts_alias:
xmpp.redacted.lan: redacted.lan
listen:
-
port: 443
ip: "::"
tls: true
module: ejabberd_http
request_handlers:
"/bosh": mod_bosh
"/ws": ejabberd_http_ws
"/conversejs": mod_conversejs
modules:
mod_bosh:
mod_conversejs:
bosh_service_url: "https://xmpp.redacted.lan/bosh"
websocket_url: "wss://xmpp.redacted.lan/ws"then ejabberd_http will accept https://xmpp.redacted.lan/conversejs and deliver it to vhost redacted.lan
In previous ejabberd releases, an option called default_host was documented for the ejabberd_http listener, but it didn't work at all correctly.
New predefined keywords
A few months ago, ejabberd 25.03 introduced new predefined keywords like HOST, HOME, VERSION and SEMVER.
And now two more predefined keywords are added:
CONFIG_PATH: Path to the configuration directory, for example"/home/ejabberd/opt/ejabberd/conf"LOG_PATH: Path to the log directory, for example"/home/ejabberd/opt/ejabberd/logs"
Those keywords are specially u...
25.04
Release notes copied from the original ejabberd 25.04 announcement post:
Just a few weeks after previous release, ejabberd 25.04 is published with an important security fix, several bug fixes and a new API command.
Release Highlights:
If you are upgrading from a previous version, there are no changes in SQL schemas, configuration, API commands or hooks.
Other contents:
- Acknowledgments
- Improvements in ejabberd Business Edition
- ChangeLog
- ejabberd 25.04 download & feedback
Below is a detailed breakdown of the improvements and enhancements:
mod_muc_occupantid: Fix handling multiple occupant-id
Fixed issue with handling of user provided occupant-id in messages and presences sent to muc room. Server was replacing just first instance of occupant-id with its own version, leaving other ones untouched. That would mean that depending on order in which clients send occupant-id, they could see value provided by sender, and that could be used to spoof as different sender.
New kick_users API command
There is a new API command kick_users that disconnects all the client sessions in a given virtual host.
Acknowledgments
We would like to thank the contributions to the source code, documentation, and translation provided for this release by:
- Travis Burtrum for reporting problem in occupant-id
- Marcos de Vera Piquero for the new
kick_usersAPI command - Besnik Bleta, updated the Albanian translation
- Sketch6580, updated the Chinese translation
- Nautilusx, updated the German translation
- Silvério Santos, updated the Portuguese translation
- Wellington Uemura, updated the Portuguese (Brazil) translation
- Максим Горпиніч, updated the Ukrainian translation
And also to all the people contributing in the ejabberd chatroom, issue tracker...
Improvements in ejabberd Business Edition
For customers of the ejabberd Business Edition, in addition to all those improvements and bugfixes:
- Bugfix on
max_concurrent_connectionsformod_gcm,mod_webhookandmod_webpush
ChangeLog
This is a more complete list of changes in this ejabberd release:
Security fixes
mod_muc_occupantid: Fix handling multiple occupant-id
Commands API
kick_users: New command to kick all logged users for a given host
Bugfixes
- Fix issue with sql schema auto upgrade when using
sqlitedatabase - Fix problem with container update, that could ignore previous data stored in
mnesiadatabase - Revert limit of allowed characters in shared roster group names, that will again allow using symbols like
: - Binary installers and
ejabberdcontainer image: Updated to Erlang/OTP 27.3.2
Full Changelog
ejabberd 25.04 download & feedback
As usual, the release is tagged in the Git source code repository on GitHub.
The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.
For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.
The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.
If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.