view mod_c2s_conn_throttle/README.markdown @ 5264:d3ebaef1ea7a

mod_http_oauth2: Correctly verify OAuth client credentials on revocation Makes no sense to validate against username and password here, or using a token to revoke another token, or itself? In fact, upon further discussion, why do you need credentials to revoke a token? If you are not supposed to have the token, revoking it seems the most responsible thing to do with it, so it should be allowed, while if you are supposed to have it, you should be allowed to revoke it.
author Kim Alvefur <zash@zash.se>
date Tue, 21 Mar 2023 21:57:18 +0100
parents 4d73a1a6ba68
children
line wrap: on
line source

---
labels:
- 'Stage-Stable'
summary: c2s connections throttling module
...

Introduction
============

This module allows to throttle those client connections which exceed a
n\*seconds limit.

Usage
=====

Copy the module folder into your prosody modules directory. Place the
module between your enabled modules either into the global or a vhost
section.

Optional configuration directives:

``` {.lua}

cthrottler_logins_count = 3 -- number of login attempts allowed, default is 3
cthrottler_time = 60 -- .. in number of seconds, default is 60
```

Info
====

-   0.8, works
-   0.9, works