Mercurial > prosody-modules
view mod_email_pass/templates/style.css @ 5682:527c747711f3
mod_http_oauth2: Limit revocation to clients own tokens in strict mode
RFC 7009 section 2.1 states:
> The authorization server first validates the client credentials (in
> case of a confidential client) and then verifies whether the token was
> issued to the client making the revocation request. If this
> validation fails, the request is refused and the client is informed of
> the error by the authorization server as described below.
The first part was already covered (in strict mode). This adds the later
part using the hash of client_id recorded in 0860497152af
It still seems weird to me that revoking a leaked token should not be
allowed whoever might have discovered it, as that seems the responsible
thing to do.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 29 Oct 2023 11:30:49 +0100 |
parents | 0ae065453dc9 |
children |
line wrap: on
line source
body{ font-family:"Lucida Grande", "Lucida Sans Unicode", Verdana, Arial, Helvetica, sans-serif; font-size:12px; } p, h1, form, button{border:0; margin:0; padding:0;} .spacer{clear:both; height:1px;} /* ----------- My Form ----------- */ .formulario{ margin:0 auto; width:500px; padding:14px; } /* ----------- stylized ----------- */ #estilo { border:solid 2px #b7ddf2; background:#ebf4fb; } #estilo h1 { font-size:14px; font-weight:bold; margin-bottom:8px; } #estilo p { font-size:11px; color:#666666; margin-bottom:20px; border-bottom:solid 1px #b7ddf2; padding-bottom:10px; } #estilo p.error { font-size:12px; font-weight:bold; color:red; margin-bottom:20px; border-bottom:solid 1px #b7ddf2; padding-bottom:10px; } #estilo label{ display:block; font-weight:bold; text-align:right; width:140px; float:left; } #estilo .small{ color:#666666; display:block; font-size:11px; font-weight:normal; text-align:right; width:140px; } #estilo input{ float:left; font-size:12px; padding:4px 2px; border:solid 1px #aacfe4; width:200px; margin:2px 0 20px 10px; } .button { -moz-box-shadow:inset 0px 1px 0px 0px #cae3fc; -webkit-box-shadow:inset 0px 1px 0px 0px #cae3fc; box-shadow:inset 0px 1px 0px 0px #cae3fc; background-color:#79bbff; -webkit-border-top-left-radius:18px; -moz-border-radius-topleft:18px; border-top-left-radius:18px; -webkit-border-top-right-radius:18px; -moz-border-radius-topright:18px; border-top-right-radius:18px; -webkit-border-bottom-right-radius:18px; -moz-border-radius-bottomright:18px; border-bottom-right-radius:18px; -webkit-border-bottom-left-radius:18px; -moz-border-radius-bottomleft:18px; border-bottom-left-radius:18px; text-indent:0; border:1px solid #469df5; display:inline-block; color:#ffffff; font-family:Arial; font-size:15px; font-weight:bold; font-style:normal; height:40px; line-height:40px; width:100px; text-decoration:none; text-align:center; text-shadow:1px 1px 0px #287ace; } .button:hover { background-color:#4197ee; } .button:active { position:relative; top:1px; }