view mod_broadcast/README.markdown @ 5616:59d5fc50f602

mod_http_oauth2: Implement refresh token rotation Makes refresh tokens one-time-use, handing out a new refresh token with each access token. Thus if a refresh token is stolen and used by an attacker, the next time the legitimate client tries to use the previous refresh token, it will not work and the attack will be noticed. If the attacker does not use the refresh token, it becomes invalid after the legitimate client uses it. This behavior is recommended by draft-ietf-oauth-security-topics
author Kim Alvefur <zash@zash.se>
date Sun, 23 Jul 2023 02:56:08 +0200
parents 34fb3d239ac1
children
line wrap: on
line source

---
labels:
- 'Stage-Stable'
summary: Broadcast a message to online users
...

Introduction
============

This module largely duplicates the functionality of the standard
mod\_announce that is included with Prosody. It was developed for
compatibility with some clients (e.g. iChat) that do not support ad-hoc
commands or sending to JIDs with the format
'example.com/announce/online'.

It may also be useful in other specific cases.

Configuration
=============

    Component "broadcast@example.com" "broadcast"

By default, only server admins are allowed to post to this address. You
can override this, by specifying the 'broadcast\_senders' option:

    Component "broadcast@example.com" "broadcast"
        broadcast_senders = { "user1@example.com", "user2@example.com" }

Compatibility
=============

  ------ -------
  0.9    Works
  0.10   Works
  trunk  Doesn't work (uses is_admin)
  ------ -------