annotate mod_log_sasl_mech/mod_log_sasl_mech.lua @ 5418:f2c7bb3af600

mod_http_oauth2: Add role selector to consent page List includes all roles available to the user, if more than one. Defaults to either the first role in the scope string or the users primary role. Earlier draft listed all roles, but having options that can't be selected is bad UX and the entire list of all roles on the server could be long, and perhaps even sensitive. Allows e.g. picking a role with fewer permissions than what might otherwise have been selected. UX wise, doing this with more checkboxes or possibly radio buttons would have been confusion and/or looked messier. Fixes the previous situation where unselecting a role would default to the primary role, which could be more permissions than requested.
author Kim Alvefur <zash@zash.se>
date Fri, 05 May 2023 01:23:13 +0200
parents 4baaa5a66a5a
children 5ff8022466ab
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
1292
2d061333d0c2 mod_log_sasl_mech: Logs authentication mechanism used
Kim Alvefur <zash@zash.se>
parents:
diff changeset
1
2d061333d0c2 mod_log_sasl_mech: Logs authentication mechanism used
Kim Alvefur <zash@zash.se>
parents:
diff changeset
2 module:hook("authentication-success", function (event)
1393
4baaa5a66a5a mod_log_sasl_mech: Log SASL mechanism attached to session
Kim Alvefur <zash@zash.se>
parents: 1292
diff changeset
3 local session = event.session;
4baaa5a66a5a mod_log_sasl_mech: Log SASL mechanism attached to session
Kim Alvefur <zash@zash.se>
parents: 1292
diff changeset
4 local sasl_handler = session.sasl_handler;
4baaa5a66a5a mod_log_sasl_mech: Log SASL mechanism attached to session
Kim Alvefur <zash@zash.se>
parents: 1292
diff changeset
5 session.log("info", "Authenticated with %s", sasl_handler and sasl_handler.selected or "legacy auth");
1292
2d061333d0c2 mod_log_sasl_mech: Logs authentication mechanism used
Kim Alvefur <zash@zash.se>
parents:
diff changeset
6 end);