Mercurial > prosody-modules
view mod_measure_storage/mod_measure_storage.lua @ 5616:59d5fc50f602
mod_http_oauth2: Implement refresh token rotation
Makes refresh tokens one-time-use, handing out a new refresh token with
each access token. Thus if a refresh token is stolen and used by an
attacker, the next time the legitimate client tries to use the previous
refresh token, it will not work and the attack will be noticed. If the
attacker does not use the refresh token, it becomes invalid after the
legitimate client uses it.
This behavior is recommended by draft-ietf-oauth-security-topics
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 23 Jul 2023 02:56:08 +0200 |
parents | 04ae5b45e6c7 |
children |
line wrap: on
line source
module:set_global() local function return_args_after_calling(f, ...) f(); return ... end local function time_method(module, store_name, store_type, method_name, method_function) local opt_use_tags = module:get_option_boolean("measure_storage_tagged_metric", false); local metric_name, metric_tags; if opt_use_tags then metric_name, metric_tags = "storage_operation", ("store_name:%s,store_type:%s,store_operation:%s"):format(store_name, store_type, method_name); else metric_name = store_name.."_"..store_type.."_"..method_name; end local measure_operation_started = module:measure(metric_name, "times", metric_tags); return function (...) module:log("debug", "Measuring storage operation %s (%s)", metric_name, metric_tags or "no tags"); local measure_operation_complete = measure_operation_started(); return return_args_after_calling(measure_operation_complete, method_function(...)); end; end local function wrap_store(module, store_name, store_type, store) local new_store = setmetatable({}, { __index = function (t, method_name) local original_method = store[method_name]; if type(original_method) ~= "function" then if original_method then rawset(t, method_name, original_method); end return original_method; end local timed_method = time_method(module, store_name, store_type, method_name, original_method); rawset(t, method_name, timed_method); return timed_method; end; }); return new_store; end local function hook_event(module) module:hook("store-opened", function(event) event.store = wrap_store(module, event.store_name, event.store_type or "keyval", event.store); end); end function module.load() hook_event(module); end function module.add_host(module) hook_event(module); end