I found that issue, the problem is the @ in the JID and authfilter from openfire. The @ is not allow in the URL.
I could change that to username instead of JID, but that would be restrict external user (with other domain name).
Additionally you can also set roles by update the whole MUC channel.