RFC 5589 states that any REFER request must be appropriately authenticated and authorised using standard SIP mechanisms or calls may be hijacked, that an INVITE carrying Replaces should only be accepted when authenticated and authorised and the requestor authorised to replace the dialog, and that where the replacing dialog adds media streams the user must authorise the addition.

Checked 2026-09-16

Any REFER request MUST be appropriately authenticated and authorized using standard SIP mechanisms or else calls may be hijacked.
Vendor
IETF
Product
Session Initiation Protocol
Subsystem
Security
Deployment
not restricted
Region
not restricted
Release range
BCP 149
Checked
2026-09-16

Sources

Cite this note

APA

WarmTransfer. (2026, September 16). Call transfer semantics REFER and Replaces: source note xfersem-transfer-security-is-authorisation. WarmTransfer. https://warmtransfer.net/knowledge/claims/xfersem-transfer-security-is-authorisation

BibTeX

@misc{warmtransfer-claim-xfersem-transfer-security-is-authorisation,
  title  = {Call transfer semantics REFER and Replaces: source note xfersem-transfer-security-is-authorisation},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/xfersem-transfer-security-is-authorisation},
  note   = {Source note xfersem-transfer-security-is-authorisation, checked 2026-09-16}
}

Read in context