Mercurial > prosody-modules
view mod_stanza_counter/README.markdown @ 5616:59d5fc50f602
mod_http_oauth2: Implement refresh token rotation
Makes refresh tokens one-time-use, handing out a new refresh token with
each access token. Thus if a refresh token is stolen and used by an
attacker, the next time the legitimate client tries to use the previous
refresh token, it will not work and the attack will be noticed. If the
attacker does not use the refresh token, it becomes invalid after the
legitimate client uses it.
This behavior is recommended by draft-ietf-oauth-security-topics
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 23 Jul 2023 02:56:08 +0200 |
parents | 4d73a1a6ba68 |
children |
line wrap: on
line source
--- labels: - 'Stage-Stable' summary: Simple incoming and outgoing stanza counter ... Introduction ============ This module counts incoming and outgoing stanzas from when the instance started, and makes the data available to other modules by creating a global prosody. object Details ======= The counter module is "stanza\_counter", the example output module is stanza\_counter\_http. Usage ===== Copy both files into prosody's module directory and place 'em into your enabled modules (stanza\_counter\_http requires to be loaded into the global section!) Config for stanza\_counter\_http: ``` {.lua} stanza_counter_basepath = "/counter-path-custom/" ``` Info ==== - As of now to count components stanzas, it needs to be manually loaded (inserted into modules\_enabled of the components' sections) on these. - This version isn't compatible with previous versions of prosody (looks at 0.8-diverge branch for olders).