[mod_sofia] Add enable-chat-api-proto to gate the api chat proto (#3135)

The chat layer lets an inbound SIP MESSAGE select which chat proto handles it,
and the `api` proto runs the address as a FreeSWITCH API command. The new
per-profile `enable-chat-api-proto` param controls that route and is off unless
set. A MESSAGE selecting the proto on a profile without it is answered 403 and
logged with the source and the requested command.

The proto compare is case-insensitive, matching the chat interface registry,
which is created with `switch_core_hash_init_nocase()`.

The param ships commented out in the four vanilla profiles and the mod_sofia
sofia.conf.xml sample.
This commit is contained in:
Dmitry Verenitsin
2026-08-26 16:46:56 +03:00
committed by GitHub
parent 098018df3d
commit 7015f6a73a
8 changed files with 38 additions and 0 deletions
@@ -56,6 +56,8 @@
<param name="inbound-codec-negotiation" value="generous"/>
<param name="nonce-ttl" value="60"/>
<param name="auth-calls" value="false"/>
<!-- lets an inbound MESSAGE to api+<command> run FreeSWITCH API commands, so enable only for trusted peers -->
<!-- <param name="enable-chat-api-proto" value="true"/> -->
<param name="inbound-late-negotiation" value="true"/>
<!--
DO NOT USE HOSTNAMES, ONLY IP ADDRESSES IN THESE SETTINGS!
+2
View File
@@ -56,6 +56,8 @@
<param name="inbound-codec-negotiation" value="generous"/>
<param name="nonce-ttl" value="60"/>
<param name="auth-calls" value="false"/>
<!-- lets an inbound MESSAGE to api+<command> run FreeSWITCH API commands, so enable only for trusted peers -->
<!-- <param name="enable-chat-api-proto" value="true"/> -->
<param name="inbound-late-negotiation" value="true"/>
<!--
DO NOT USE HOSTNAMES, ONLY IP ADDRESSES IN THESE SETTINGS!
@@ -93,6 +93,8 @@
<!-- add a ;received="<ip>:<port>" to the contact when replying to register for nat handling -->
<!--<param name="NDLB-received-in-nat-reg-contact" value="true"/>-->
<param name="auth-calls" value="$${internal_auth_calls}"/>
<!-- lets an inbound MESSAGE to api+<command> run FreeSWITCH API commands, so enable only for trusted peers -->
<!-- <param name="enable-chat-api-proto" value="true"/> -->
<!-- on authed calls, authenticate *all* the packets not just invite -->
<param name="auth-all-packets" value="false"/>
<!-- Shouldn't set these on IPv6 -->
+3
View File
@@ -107,6 +107,9 @@
<!-- extended info parsing -->
<!-- <param name="extended-info-parsing" value="true"/> -->
<!-- lets an inbound MESSAGE to api+<command> run FreeSWITCH API commands, so enable only for trusted peers -->
<!-- <param name="enable-chat-api-proto" value="true"/> -->
<!--<param name="aggressive-nat-detection" value="true"/>-->
<!--
There are known issues (asserts and segfaults) when 100rel is enabled.