Mercurial > prosody-modules
annotate mod_limits_exception/mod_limits_exception.lua @ 5448:9d542e86e19a
mod_http_oauth2: Allow requesting a subset of scopes on token refresh
This enables clients to request access tokens with fewer permissions
than the grant they were given, reducing impact of token leak. Clients
could e.g. request access tokens with some privileges and immediately
revoke them after use, or other strategies.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Thu, 11 May 2023 21:40:09 +0200 |
parents | 28c16c93d79a |
children |
rev | line source |
---|---|
4562
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
1 local unlimited_jids = module:get_option_inherited_set("unlimited_jids", {}); |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
2 |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
3 if unlimited_jids:empty() then |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
4 return; |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
5 end |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
6 |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
7 module:hook("authentication-success", function (event) |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
8 local session = event.session; |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
9 local jid = session.username .. "@" .. session.host; |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
10 if unlimited_jids:contains(jid) then |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
11 if session.conn and session.conn.setlimit then |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
12 session.conn:setlimit(0); |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
13 elseif session.throttle then |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
14 session.throttle = nil; |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
15 end |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
16 end |
28c16c93d79a
mod_limits_exception: New module to except some JIDs from rate limiting
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
17 end); |