view mod_list_active/mod_list_active.lua @ 5616:59d5fc50f602

mod_http_oauth2: Implement refresh token rotation Makes refresh tokens one-time-use, handing out a new refresh token with each access token. Thus if a refresh token is stolen and used by an attacker, the next time the legitimate client tries to use the previous refresh token, it will not work and the attack will be noticed. If the attacker does not use the refresh token, it becomes invalid after the legitimate client uses it. This behavior is recommended by draft-ietf-oauth-security-topics
author Kim Alvefur <zash@zash.se>
date Sun, 23 Jul 2023 02:56:08 +0200
parents c06c59b99b3c
children
line wrap: on
line source

-- Copyright (C) 2012-2013 Kim Alvefur

local um = require "core.usermanager";
local sm = require "core.storagemanager";
local dm = require "util.datamanager";
local jid_join = require"util.jid".join;

local multipliers = {
	d = 86400, -- day
	w = 604800, -- week
	m = 2629746, -- month
	y = 31556952, -- year
}

local output_formats = {
	default = "%s",
	event = "%s %s",
}

function module.command(arg)
	if #arg < 2 then
		print("usage: prosodyctl mod_list_active example.net time [format]");
		print("time is a number followed by 'day', 'week', 'month' or 'year'");
		print("formats are:");
		for name, fmt in pairs(output_formats) do
			print(name, fmt:format("user@example.com", "last action"))
		end
		return;
	end
	local items = {};
	local host = arg[1];
	assert(hosts[host], "Host "..tostring(host).." does not exist");
	sm.initialize_host(host);
	um.initialize_host(host);

	local max_age, unit = assert(arg[2], "No time range given"):match("^(%d*)%s*([dwmy]?)");
	max_age = os.time() - ( tonumber(max_age) or 1 ) * ( multipliers[unit] or 1 );

	local output = assert(output_formats[arg[3] or "default"], "No such output format: "..tostring(arg[3] or "default"));

	for user in dm.users(host, "lastlog") do
		local last_active = dm.load(user, host, "lastlog");
		local last_action = last_active and last_active.event or "?"
		last_active = last_active and last_active.timestamp or 0;
		if last_active > max_age then
			print(output:format(jid_join(user, host), last_action));
		end
	end
end