view mod_authz_delegate/README.md @ 5451:6705f2a09702

mod_http_oauth2: Reference grant by id instead of value Fixes that the grant got mutated on use of refresh token, notably it would gain 'id' and 'jid' properties set there by mod_tokenauth. Previously also the secret token that we should not be remembering.
author Kim Alvefur <zash@zash.se>
date Fri, 12 May 2023 11:11:38 +0200
parents f61564b522f7
children
line wrap: on
line source

---
summary: Authorization delegation
rockspec: {}
...

This module allows delegating authorization questions (role assignment and
role policies) to another host within prosody.

The primary use of this is for a group of virtual hosts to use a common
authorization database, for example to allow a MUC component to grant
administrative access to an admin on a corresponding user virtual host.

## Configuration

The following example will make all role assignments for local and remote JIDs
from domain.example effective on groups.domain.example:

```
VirtualHost "domain.example"

Component "groups.domain.example" "muc"
    authorization = "delegate"
    authz_delegate_to = "domain.example"
```