Mercurial > prosody-modules
annotate mod_s2s_whitelist/README.markdown @ 5956:97375a78d2b5
mod_http_oauth2: Reject URLs with 'userinfo' part (thanks mimi89999)
The LuaSocket parser supports these but they're deprecated without
replacement by RFC 3986
> Use of the format "user:password" in the userinfo field is deprecated
Allowing it in OAuth2 URLs is probably bad from a security perspective.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Thu, 29 Aug 2024 16:02:46 +0200 |
parents | 313937349fbc |
children |
rev | line source |
---|---|
3155 | 1 This module lets you block connections to any remote servers not on a |
2 whitelist. | |
3 | |
4 ``` {.lua} | |
5184
313937349fbc
mod_s2s_whitelist/README: Show inclusion in modules_enabled in example
Kim Alvefur <zash@zash.se>
parents:
3155
diff
changeset
|
5 modules_enabled = { |
313937349fbc
mod_s2s_whitelist/README: Show inclusion in modules_enabled in example
Kim Alvefur <zash@zash.se>
parents:
3155
diff
changeset
|
6 -- other modules -- |
313937349fbc
mod_s2s_whitelist/README: Show inclusion in modules_enabled in example
Kim Alvefur <zash@zash.se>
parents:
3155
diff
changeset
|
7 "s2s_whitelist", |
313937349fbc
mod_s2s_whitelist/README: Show inclusion in modules_enabled in example
Kim Alvefur <zash@zash.se>
parents:
3155
diff
changeset
|
8 |
313937349fbc
mod_s2s_whitelist/README: Show inclusion in modules_enabled in example
Kim Alvefur <zash@zash.se>
parents:
3155
diff
changeset
|
9 } |
3155 | 10 s2s_whitelist = { |
11 "example.org", | |
12 } | |
13 ``` |