Mercurial > prosody-modules
view mod_authz_delegate/README.md @ 5448:9d542e86e19a
mod_http_oauth2: Allow requesting a subset of scopes on token refresh
This enables clients to request access tokens with fewer permissions
than the grant they were given, reducing impact of token leak. Clients
could e.g. request access tokens with some privileges and immediately
revoke them after use, or other strategies.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Thu, 11 May 2023 21:40:09 +0200 |
parents | f61564b522f7 |
children |
line wrap: on
line source
--- summary: Authorization delegation rockspec: {} ... This module allows delegating authorization questions (role assignment and role policies) to another host within prosody. The primary use of this is for a group of virtual hosts to use a common authorization database, for example to allow a MUC component to grant administrative access to an admin on a corresponding user virtual host. ## Configuration The following example will make all role assignments for local and remote JIDs from domain.example effective on groups.domain.example: ``` VirtualHost "domain.example" Component "groups.domain.example" "muc" authorization = "delegate" authz_delegate_to = "domain.example" ```