From b13f38b10192ab081183b1c20df82e0f60bb3dad Mon Sep 17 00:00:00 2001 From: Kees Monshouwer Date: Tue, 22 Jul 2014 21:08:52 +0200 Subject: [PATCH] apply AXFR access rules to IXFR --- pdns/tcpreceiver.cc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pdns/tcpreceiver.cc b/pdns/tcpreceiver.cc index 9ad38f66b5..5314d54ca6 100644 --- a/pdns/tcpreceiver.cc +++ b/pdns/tcpreceiver.cc @@ -983,7 +983,7 @@ int TCPNameserver::doIXFR(shared_ptr q, int outsock) s_P=new PacketHandler; } - if(!s_P->getBackend()->getSOA(q->qdomain, sd)) { + if(!s_P->getBackend()->getSOA(q->qdomain, sd) || !canDoAXFR(q)) { L<qdomain<<"' failed: not authoritative"<setRcode(9); // 'NOTAUTH' sendPacket(outpacket,outsock); -- 2.47.2