view mod_restrict_xmpp/README.markdown @ 5787:e79f9dec35c0

mod_c2s_conn_throttle: Reduce log level from error->info Our general policy is that "error" should never be triggerable by remote entities, and that it is always about something that requires admin intervention. This satisfies neither condition. The "warn" level can be used for unexpected events/behaviour triggered by remote entities, and this could qualify. However I don't think failed auth attempts are unexpected enough. I selected "info" because it is what is also used for other notable session lifecycle events.
author Matthew Wild <mwild1@gmail.com>
date Thu, 07 Dec 2023 15:46:50 +0000
parents 62654f523c6a
children
line wrap: on
line source

---
labels:
- Stage-Alpha
summary: XMPP-layer access control for Prosody
---

Introduction
============

This module enforces access policies using Prosody's new [roles and
permissions framework](https://prosody.im/doc/developers/permissions). It can
be used to grant restricted access to an XMPP account or services.

This module is still in its early stages, and prone to change. Feedback from
testers is welcome. At this early stage, it should not be solely relied upon
for account security purposes.

Configuration
=============

There is no configuration, apart from Prosody's normal roles and permissions
configuration.

Permissions
===========

`xmpp:federate`
:   Communicate with other users and services on other hosts on the XMPP
    network

`xmpp:account:messages:read`
:   Read incoming messages

`xmpp:account:messages:write`
:   Send outgoing messages

`xmpp:account:presence:write`
:   Update presence for the account

`xmpp:account:contacts:read`/`xmpp:account:contacts:write`
:   Controls access to the contact list (roster)

`xmpp:account:bookmarks:read`/`xmpp:account:bookmarks:write`
:   Controls access to the bookmarks (group chats list)

`xmpp:account:profile:read`/`xmpp:account:profile:write`
:   Controls access to the user's profile (e.g. vCard/avatar)

`xmpp:account:omemo:read`/`xmpp:account:omemo:write`
:   Controls access to the user's OMEMO data

`xmpp:account:blocklist:read`/`xmpp:account:blocklist:write`
:   Controls access to the user's block list

`xmpp:account:disco:read`
:   Controls access to the user's service discovery information

Compatibility
=============

Requires Prosody trunk 72f431b4dc2c (build 1444) or later.