Mercurial > prosody-modules
view mod_authz_delegate/README.md @ 5626:a44af1b646f5
mod_http_oauth2: Optionally enforce authentication on revocation endpoint
But why do OAuth require this? If a token leaks, why couldn't anyone
revoke it?
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Mon, 31 Jul 2023 02:07:58 +0200 |
parents | f61564b522f7 |
children |
line wrap: on
line source
--- summary: Authorization delegation rockspec: {} ... This module allows delegating authorization questions (role assignment and role policies) to another host within prosody. The primary use of this is for a group of virtual hosts to use a common authorization database, for example to allow a MUC component to grant administrative access to an admin on a corresponding user virtual host. ## Configuration The following example will make all role assignments for local and remote JIDs from domain.example effective on groups.domain.example: ``` VirtualHost "domain.example" Component "groups.domain.example" "muc" authorization = "delegate" authz_delegate_to = "domain.example" ```