diff --git a/site-cookbooks/kosmos-ejabberd/templates/ejabberd.yml.erb b/site-cookbooks/kosmos-ejabberd/templates/ejabberd.yml.erb index f1b9fd9..3ee18db 100644 --- a/site-cookbooks/kosmos-ejabberd/templates/ejabberd.yml.erb +++ b/site-cookbooks/kosmos-ejabberd/templates/ejabberd.yml.erb @@ -69,7 +69,6 @@ listen: request_handlers: "/api": mod_http_api tls: false - captcha: false - port: 5443 ip: "::" @@ -87,7 +86,6 @@ listen: tls: true ## "/pub/archive": mod_http_fileserver ## register: true - captcha: false s2s_use_starttls: optional @@ -280,7 +278,6 @@ modules: mod_stream_mgmt: {} mod_s2s_dialback: {} mod_http_api: {} - mod_muc_occupantid: {} mod_muc_rtbl: {} mod_s3_upload: region: <%= @mod_s3_upload[:region] %> diff --git a/site-cookbooks/kosmos-ejabberd/test/integration/default/default_test.rb b/site-cookbooks/kosmos-ejabberd/test/integration/default/default_test.rb index 26d9512..bb636e8 100644 --- a/site-cookbooks/kosmos-ejabberd/test/integration/default/default_test.rb +++ b/site-cookbooks/kosmos-ejabberd/test/integration/default/default_test.rb @@ -33,4 +33,11 @@ describe file('/opt/ejabberd/conf/ejabberd.yml') do # Regression guard for the unauthenticated RCE fixed in 26.09: mod_adhoc_api # is one of the exploit prerequisites and must never be enabled. its('content') { should_not match(/mod_adhoc_api:/) } + + # mod_muc_occupantid was merged into mod_muc in 26.02 and the standalone + # module removed, so it must not be configured anymore. + its('content') { should_not match(/mod_muc_occupantid:/) } + + # the listen option 'captcha' was deprecated in 26.09 + its('content') { should_not match(/^\s*captcha:/) } end