Mercurial > prosody-modules
view mod_group_bookmarks/README.markdown @ 5682:527c747711f3
mod_http_oauth2: Limit revocation to clients own tokens in strict mode
RFC 7009 section 2.1 states:
> The authorization server first validates the client credentials (in
> case of a confidential client) and then verifies whether the token was
> issued to the client making the revocation request. If this
> validation fails, the request is refused and the client is informed of
> the error by the authorization server as described below.
The first part was already covered (in strict mode). This adds the later
part using the hash of client_id recorded in 0860497152af
It still seems weird to me that revoking a leaked token should not be
allowed whoever might have discovered it, as that seems the responsible
thing to do.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 29 Oct 2023 11:30:49 +0100 |
parents | 8de50be756e5 |
children |
line wrap: on
line source
--- labels: - 'Stage-Beta' summary: 'mod\_groups for chatrooms' ... Introduction ============ [mod\_groups](http://prosody.im/doc/modules/mod_groups) allows you to insert contacts into users' contact lists. Well mod\_group\_bookmarks allows you to insert chatrooms into the user's bookmarks. These are fetched by their client and automatically joined when the log in. In short, if you want to automatically join users to rooms when they sign in, this is the module you want. Details ======= Most clients support storing a private list of room "bookmarks" on the server. When they log in, they fetch this list and join any that are marked as "autojoin". Without affecting normal usage of the bookmarks store this module dynamically inserts custom rooms into users' bookmarks lists. Usage ===== Similar to [mod\_groups](http://prosody.im/doc/modules/mod_groups), you need to make a text file in this format: [room@conferenceserver] user1@example.com=User 1 user2@example.com=User 2 [otherroom@conferenceserver] user3@example.net=User 3 Add "group\_bookmarks" to your modules\_enabled list: modules_enabled = { -- ...other modules here... -- "group_bookmarks"; -- ...maybe some more here... -- } Configuration ============= ------------------------ --------------------------------------------------- group\_bookmarks\_file The path to the text file you created (as above). ------------------------ --------------------------------------------------- Compatibility ============= ----- ------------- 0.8 Works 0.7 Should work 0.6 Should work ----- ------------- Todo ==== - Support for injecting into ALL users bookmarks, without needing a list - Allow turning off the autojoin flag - Perhaps support a friendly name for the bookmark (currently uses the room address)