Mercurial > prosody-modules
view mod_authz_delegate/README.md @ 5407:149634647b48
mod_http_oauth2: Don't issue client_secret when not using authentication
This is pretty much only for implicit flow, which is considered insecure
anyway, so this is of limited value. If we delete all the implicit flow
code, this could be reverted.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Tue, 02 May 2023 16:39:32 +0200 |
parents | f61564b522f7 |
children |
line wrap: on
line source
--- summary: Authorization delegation rockspec: {} ... This module allows delegating authorization questions (role assignment and role policies) to another host within prosody. The primary use of this is for a group of virtual hosts to use a common authorization database, for example to allow a MUC component to grant administrative access to an admin on a corresponding user virtual host. ## Configuration The following example will make all role assignments for local and remote JIDs from domain.example effective on groups.domain.example: ``` VirtualHost "domain.example" Component "groups.domain.example" "muc" authorization = "delegate" authz_delegate_to = "domain.example" ```