Mercurial > prosody-modules
view mod_rawdebug/README.markdown @ 5956:97375a78d2b5
mod_http_oauth2: Reject URLs with 'userinfo' part (thanks mimi89999)
The LuaSocket parser supports these but they're deprecated without
replacement by RFC 3986
> Use of the format "user:password" in the userinfo field is deprecated
Allowing it in OAuth2 URLs is probably bad from a security perspective.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Thu, 29 Aug 2024 16:02:46 +0200 |
parents | c5c583fae25d |
children |
line wrap: on
line source
--- summary: Extra verbose logging of sent and received --- Summary ======= Sometimes it is useful to get the raw XML logs from clients for debugging purposes, but some clients don't expose this. This module logs dumps everything sent and received into debug logs, for debugging purposes.