view mod_default_vcard/README.markdown @ 5616:59d5fc50f602

mod_http_oauth2: Implement refresh token rotation Makes refresh tokens one-time-use, handing out a new refresh token with each access token. Thus if a refresh token is stolen and used by an attacker, the next time the legitimate client tries to use the previous refresh token, it will not work and the attack will be noticed. If the attacker does not use the refresh token, it becomes invalid after the legitimate client uses it. This behavior is recommended by draft-ietf-oauth-security-topics
author Kim Alvefur <zash@zash.se>
date Sun, 23 Jul 2023 02:56:08 +0200
parents 4d73a1a6ba68
children
line wrap: on
line source

---
labels:
- 'Stage-Beta'
summary: Automatically populate vcard based on account details
...

Introduction
============

It is possible for the user to supply more than just a username and
password when creating an account using
[mod\_register](https://prosody.im/doc/modules/mod_register). This
module automatically copies over that data to the user's vcard.

Details
=======

There is no configuration for this module, just add it to
modules\_enabled as normal.

Note that running this on a public-facing server that prompts for email
during registration will make the user's email address publicly visible
in their vcard.

Compatibility
=============

  ----- -------
  0.9   Works
  ----- -------