Mercurial > prosody-modules
annotate mod_compat_dialback/README.markdown @ 5390:f2363e6d9a64
mod_http_oauth2: Advertise the currently supported id_token signing algorithm
This field is REQUIRED. The algorithm RS256 MUST be included, but isn't
because we don't implement it, as that would require implementing a pile
of additional cryptography and JWT stuff. Instead the id_token is
signed using the client secret, which allows verification by the client,
since it's a shared secret per OpenID Connect Core 1.0 § 10.1 under
Symmetric Signatures.
OpenID Connect Discovery 1.0 has a lot of REQUIRED and MUST clauses that
are not supported here, but that's okay because this is served from the
RFC 8414 OAuth 2.0 Authorization Server Metadata .well-known endpoint!
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 30 Apr 2023 16:13:40 +0200 |
parents | 41ebdb331b94 |
children |
rev | line source |
---|---|
1900
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
1 --- |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
2 summary: Workaround for Dialback with some servers that violate RFC 6120 |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
3 ... |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
4 |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
5 This module provides a workaround for servers that do not set the `to` |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
6 attribute on stream headers, which is required per [RFC6120]: |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
7 |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
8 > ## 4.7.2. to |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
9 > |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
10 > For initial stream headers in both client-to-server and |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
11 > server-to-server communication, the initiating entity MUST include the |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
12 > 'to' attribute and MUST set its value to a domainpart that the |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
13 > initiating entity knows or expects the receiving entity to service. |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
14 |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
15 As a side effect of [this issue](https://prosody.im/issues/issue/285), |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
16 Prosody 0.10 will be unable to do [Dialback][xep220] with servers that |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
17 don't follow this. |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
18 |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
19 # Known servers affected |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
20 |
41ebdb331b94
mod_compat_dialback: Workaround for Dialback with servers that violate RFC 6120 § 4.7.2
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
21 * Openfire 3.10.2 (and probably earlier versions) |