Mercurial > prosody-modules
view mod_http_libjs/README.markdown @ 5956:97375a78d2b5
mod_http_oauth2: Reject URLs with 'userinfo' part (thanks mimi89999)
The LuaSocket parser supports these but they're deprecated without
replacement by RFC 3986
> Use of the format "user:password" in the userinfo field is deprecated
Allowing it in OAuth2 URLs is probably bad from a security perspective.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Thu, 29 Aug 2024 16:02:46 +0200 |
parents | 88a469b285f5 |
children |
line wrap: on
line source
--- labels: - 'Stage-Stable' summary: 'Serve common Javascript libraries' ... Introduction ============ This module serves common static CSS and Javascript libraries from the filesystem, allowing other HTTP modules to easily reference them. The default configuration works out of the box with Debian (and derivatives) `libjs-*` packages, such as libjs-jquery and libjs-bootstrap. You can override the filesystem location using the `libjs_path` configuration option. The default is `/usr/share/javascript`. Compatibility ============= ----- ------- 0.11 Works ----- -------