view mod_muc_offline_delivery/README.md @ 5682:527c747711f3

mod_http_oauth2: Limit revocation to clients own tokens in strict mode RFC 7009 section 2.1 states: > The authorization server first validates the client credentials (in > case of a confidential client) and then verifies whether the token was > issued to the client making the revocation request. If this > validation fails, the request is refused and the client is informed of > the error by the authorization server as described below. The first part was already covered (in strict mode). This adds the later part using the hash of client_id recorded in 0860497152af It still seems weird to me that revoking a leaked token should not be allowed whoever might have discovered it, as that seems the responsible thing to do.
author Kim Alvefur <zash@zash.se>
date Sun, 29 Oct 2023 11:30:49 +0100
parents 3b7847c9bd26
children
line wrap: on
line source

---
labels:
- 'Stage-Alpha'
summary: 'Support for sending MUC messages to offline users'
...

Introduction
============

This module implements support for sending messages in a MUC to affiliated users
who are not in the room. This is a custom extension by Tigase to allow push notifications
from MUCs to users who are not currently connected.

It is planned that this will evolve to a XEP in the near future.

The protocol is described below. It is implemented in the Siskin client for iOS.

Details
=======

Add to modules_enabled under your MUC component (i.e. **not** the global modules_enabled
list). There are no configuration options.

Compatibility
=============

Requires Prosody trunk (0.12) for the API introduced in commit 336cba957c88.

Protocol
========

To enable this feature, a client must fetch the registration form from a MUC,
as per XEP-0045. The form will include the usual field for nickname (this is
required), and also a boolean field named `{http://tigase.org/protocol/muc}offline`.

Submit the form with that field set to true, and the MUC will forward messages
to your bare JID when you are not connected to the room. Two things to note:

1. This will achieve nothing unless your server is capable of handling these
    messages correctly.
2. Messages are only sent when you are not in the room. This includes other
    resources of the same account.