Mercurial > prosody-modules
view mod_disable_tls/README.markdown @ 5956:97375a78d2b5
mod_http_oauth2: Reject URLs with 'userinfo' part (thanks mimi89999)
The LuaSocket parser supports these but they're deprecated without
replacement by RFC 3986
> Use of the format "user:password" in the userinfo field is deprecated
Allowing it in OAuth2 URLs is probably bad from a security perspective.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Thu, 29 Aug 2024 16:02:46 +0200 |
parents | 4d73a1a6ba68 |
children |
line wrap: on
line source
--- labels: - 'Stage-Beta' summary: Disable TLS on certain client ports ... Introduction ============ This module can be used to prevent Prosody from offering TLS on client ports that you specify. This can be useful to work around buggy clients when transport security is not required. Configuration ============= Load the module, and set `disable_tls_ports` to a list of ports: disable_tls_ports = { 5322 } Don't forget to add any extra ports to c2s\_ports, so that Prosody is actually listening for connections! Compatibility ============= ----- ------- 0.9 Works ----- -------