Mercurial > prosody-modules
view mod_invites_register/README.markdown @ 5390:f2363e6d9a64
mod_http_oauth2: Advertise the currently supported id_token signing algorithm
This field is REQUIRED. The algorithm RS256 MUST be included, but isn't
because we don't implement it, as that would require implementing a pile
of additional cryptography and JWT stuff. Instead the id_token is
signed using the client secret, which allows verification by the client,
since it's a shared secret per OpenID Connect Core 1.0 ยง 10.1 under
Symmetric Signatures.
OpenID Connect Discovery 1.0 has a lot of REQUIRED and MUST clauses that
are not supported here, but that's okay because this is served from the
RFC 8414 OAuth 2.0 Authorization Server Metadata .well-known endpoint!
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 30 Apr 2023 16:13:40 +0200 |
parents | 027fb71ad509 |
children | 2f7fff6c8c73 |
line wrap: on
line source
--- labels: - 'Stage-Beta' summary: 'Allow account registration using invite tokens' ... Introduction ============ This module is part of the suite of modules that implement invite-based account registration for Prosody. The other modules are: - [mod_invites] - [mod_invites_adhoc] - [mod_invites_page] - [mod_invites_register_web] - [mod_invites_api] - [mod_register_apps] For details and a full overview, start with the [mod_invites] documentation. Details ======= This module allows clients to register an account using an invite ('preauth') token generated by mod_invites. It implements the protocol described at [docs.modernxmpp.org/client/invites](https://docs.modernxmpp.org/client/invites) and [XEP-0401 version 0.3.0](https://xmpp.org/extensions/attic/xep-0401-0.3.0.html). **Note to developers:** the XEP-0401 protocol is expected to change in the future, though Prosody will attempt to maintain backwards compatibility with the 0.3.0 protocol for as long as necessary. This module is also responsible for implementing the optional server-side part of [XEP-0379: Pre-Authenticated Roster Subscriptions](https://xmpp.org/extensions/xep-0379.html). **Note to admins:** Loading this module will disable registration for users without an invite token by default. Control this behaviour # Configuration | Name | Description | Default | |--------------------------|----------------------------------------------------------|---------| | registration_invite_only | Require an invitation token for all account registration | `true` | ## Example: Invite-only registration This setup enables registration **only** for users that have a valid invite token. ``` {.lua} allow_registration = true registration_invite_only = true ``` ## Example: Open registration This setup allows completely **open registration**, even without an invite token. ``` {.lua} allow_registration = true registration_invite_only = false ```