Mercurial > prosody-modules
annotate mod_proxy65_whitelist/README.markdown @ 5425:3b30635d215c
mod_http_oauth2: Support granting zero role-scopes
It seems Very Bad that if you uncheck all roles on the consent page, you
get the default scopes, which seems the opposite of what you probably
intended. Currently, mod_tokenauth will do the same thing, so work is
needed there too to allow issuing tokens without roles.
A token without a role could be used for OIDC login, and not much else.
This seems like a valuable thing to support.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 07 May 2023 19:29:15 +0200 |
parents | 8de50be756e5 |
children | 694b62d8a82f |
rev | line source |
---|---|
1820
8de50be756e5
Various README files: Correct indentation levels, fix syntax and other small fixes
Kim Alvefur <zash@zash.se>
parents:
1803
diff
changeset
|
1 --- |
1803 | 2 labels: 'Stage-Alpha' |
3 summary: Limit which file transfer users can use | |
4 ... | |
5 | |
6 Introduction | |
7 ------------ | |
8 | |
9 This module attempts to restrict use of non-whitelisted XEP-0065 | |
10 proxies. | |
11 | |
12 Configuration | |
13 ------------- | |
14 | |
15 Without any options, the module will restrict users to local [proxy65 | |
16 components](https://prosody.im/doc/modules/mod_proxy65). | |
17 | |
18 -- additional proxies to allow | |
19 allowed_streamhosts = { "proxy.eu.jabber.org" } | |
20 | |
21 The module will add all local proxies to that list. To prevent it from | |
22 doing that, set | |
23 | |
24 allow_local_streamhosts = false |