log

age author description
22 months ago Matthew Wild mod_firewall: Improve error when mark name contains invalid characters
22 months ago Matthew Wild mod_firewall: marks: Fix marking a user with no previous marks
22 months ago Matthew Wild mod_firewall: Update user marks to store instantly via map store
22 months ago Matthew Wild mod_firewall: Split some long lines [luacheck]
22 months ago Matthew Wild mod_firewall: Fix inverted logic of 'FROM FULL JID?'
22 months ago Matthew Wild mod_firewall: spam-blocking.pfw: Remove requirement for invites to have no body
22 months ago Matthew Wild mod_firewall: scripts: spam-blocklists: Check sender and inviter of MUC invitations against blocklist
22 months ago Matthew Wild mod_firewall: scripts: spam-blocking.pfw: Add special handling for MUC invites
22 months ago Matthew Wild mod_firewall: Add 'FROM FULL JID?' condition
22 months ago Matthew Wild mod_firewall: README: Add some emphasis on the exact behaviour of TO FULL JID
22 months ago Kim Alvefur mod_rest: Merge some common properties between openapi and schema
22 months ago Kim Alvefur mod_rest: Apply normalization to openapi spec
22 months ago Kim Alvefur mod_http_oauth2: Simplify template using if-falsy operator
22 months ago Kim Alvefur mod_http_dir_listing2: Fix wrong name for resource directory
22 months ago Kim Alvefur mod_http_dir_listing2: Include html resources with plugin installer
22 months ago Kim Alvefur mod_http_dir_listing: Strip path to using plugin installer
22 months ago Kim Alvefur mod_firewall: Include scripts with plugin installer (thanks gooya)
22 months ago Kim Alvefur mod_http_oauth2: Add some words about supported flows and defaults
22 months ago Kim Alvefur mod_http_oauth2/README: Expand summary to include OAuth 2.0 role
22 months ago Kim Alvefur mod_http_oauth2: Return Authentication Time per OpenID Core Section 2
22 months ago Kim Alvefur mod_http_oauth2: Validate the OpenID 'prompt' parameter
22 months ago Kim Alvefur mod_http_oauth2: Apply text color to OOB input field
22 months ago Kim Alvefur mod_client_management: Include client software version number in listing
22 months ago Kim Alvefur mod_http_oauth2: Present OOB code in an input field for easier selection
22 months ago Kim Alvefur mod_http_oauth2: Revert strict form check to allow consent of multiple scopes
22 months ago Kim Alvefur mod_http_oauth2: Reject duplicate form-urlencoded parameters
22 months ago Kim Alvefur mod_http_oauth2: Bind refresh tokens to client
22 months ago Kim Alvefur mod_http_oauth2: Record hash of client_id to allow future verification
22 months ago Kim Alvefur mod_http_oauth2: Add client verification wrapper function
22 months ago Kim Alvefur mod_http_oauth2: Add Cache-Control and Pragma headers per by RFC 6749
22 months ago Kim Alvefur mod_http_oauth2: Linkify mod_client_management in README
22 months ago Kim Alvefur mod_http_oauth2: Fix messed up section about redirect_uris requirements
22 months ago Kim Alvefur mod_http_oauth2: Restructure description of client metadata requirements
22 months ago Kim Alvefur mod_http_oauth2: Correct loopback URL example
22 months ago Kim Alvefur mod_groups_oidc: Expose groups to OAuth clients
22 months ago Kim Alvefur mod_oidc_userinfo_vcard4: Advertise OpenID scopes via new mechanism
22 months ago Kim Alvefur mod_http_oauth2: Add provisions for dynamically adding simple scopes
22 months ago Kim Alvefur mod_http_oauth2: Sort imports
22 months ago Kim Alvefur mod_http_oauth2: Fix closing h1 tag
22 months ago Kim Alvefur mod_auth_oauth_external: Correct docs about default scope
22 months ago Kim Alvefur misc/lnav: Add a README with installation instructions
22 months ago Kim Alvefur misc/lnav: Fix delimiting of timestamp in pattern
22 months ago Kim Alvefur misc/lnav: Fix timestamp-format to be an array as per schema
22 months ago Kim Alvefur mod_http_oauth2: Create proper template for OOB code delivery
22 months ago Kim Alvefur mod_http_oauth2: Add an example of client registration
22 months ago Kim Alvefur mod_http_oauth2: Document client registration requirements
22 months ago Kim Alvefur mod_http_debug: Handle any path under /debug/* as well
22 months ago Kim Alvefur mod_http_debug: Log some extended info about requests
22 months ago Kim Alvefur mod_http_debug: Handle more HTTP methods
22 months ago Kim Alvefur mod_http_debug: Add a brief README
22 months ago Kim Alvefur mod_rest/example: Include 'application_type' in registration
22 months ago Kim Alvefur mod_s2sout_override: Add support for Direct TLS
22 months ago Kim Alvefur mod_s2sout_override: New module for overriding s2s connections
22 months ago Matthew Wild mod_pubsub_alertmanager: Support for per-path config overrides
22 months ago Kim Alvefur mod_muc_moderation: Point to new Conversations issue tracker
22 months ago Matthew Wild mod_invites_adhoc: Fall back to generic allow_user_invites for role-less users
22 months ago Kim Alvefur mod_invites{,_adhoc,_register}: Recommend using version included with prosody
22 months ago Kim Alvefur mod_welcome_page: Remove dependency on mod_invites (included with Prosody)
22 months ago Kim Alvefur mod_http_oauth2: Allow CORS for browser clients
22 months ago Kim Alvefur mod_http_oauth2: Disable Referrer via header
22 months ago Kim Alvefur mod_http_oauth2: Always render errors as HTML for OOB redirect URI
22 months ago Kim Alvefur mod_http_oauth2: Use validated redirect URI when returning errors to client
22 months ago Kim Alvefur mod_http_oauth2: Return OAuth error for authz code store error
22 months ago Kim Alvefur mod_http_oauth2: Validate redirect_uri before using it for error redirects
22 months ago Kim Alvefur mod_http_oauth2: Don't return redirects or HTML from token endpoint
22 months ago Kim Alvefur mod_http_oauth2: Tweak formatting of log message
22 months ago Kim Alvefur mod_http_oauth2: Always show early errors to user
22 months ago Kim Alvefur mod_http_oauth2: Clarify some error messages
22 months ago Kim Alvefur mod_http_oauth2: Use error status code when rendering error page
22 months ago Kim Alvefur mod_http_oauth2: Add human-readable error messages
22 months ago Kim Alvefur mod_http_oauth2: Fix returning errors from response handlers
22 months ago Kim Alvefur mod_http_oauth2: Add a special "xmpp" scope that grants the users' default role
22 months ago Kim Alvefur mod_http_oauth2: Add support for the OpenID 'login_hint' parameter
22 months ago Kim Alvefur mod_http_oauth2: Note about partial OpenID Discovery implementation
22 months ago Kim Alvefur mod_http_oauth2: Split long list line in README
22 months ago Kim Alvefur mod_http_oauth2: Proper OAuth error for invalid redirect URI in implicit flow too
22 months ago Kim Alvefur mod_http_oauth2: Return proper OAuth error for invalid redirect URI
22 months ago Kim Alvefur mod_http_oauth2: Fix use of arbitrary ports in loopback redirect URIs
22 months ago Kim Alvefur mod_http_oauth2: Add FIXME about loopback redirect URIs
22 months ago Kim Alvefur mod_http_oauth2: Rename variables to improve clarity
22 months ago Kim Alvefur mod_http_oauth2: Do minimal validation of private-use URI schemes
22 months ago Kim Alvefur mod_http_oauth2: Reject relative redirect URIs
22 months ago Kim Alvefur mod_http_oauth2: Reject duplicate list items in client registration
22 months ago Kim Alvefur mod_http_oauth2: Require non-empty arrays in client registration
22 months ago Kim Alvefur mod_http_oauth2: Reject duplicate redirect URIs in registration
22 months ago Kim Alvefur mod_http_oauth2: Fix schema to enforce at least one redirect URI
22 months ago Kim Alvefur mod_http_oauth2: Show only roles the user can use in consent dialog
22 months ago Kim Alvefur mod_http_oauth2: Reference grant by id instead of value
22 months ago Kim Alvefur mod_http_oauth2: Scope FIXMEs
22 months ago Kim Alvefur mod_http_oauth2: Describe type signatures of scope handling functions
22 months ago Kim Alvefur mod_http_oauth2: Allow requesting a subset of scopes on token refresh
22 months ago Kim Alvefur mod_http_oauth2: Enforce client scope restrictions in authorization
22 months ago Kim Alvefur mod_http_oauth2: Fix inclusion of role in refreshed access tokens
22 months ago Kim Alvefur mod_http_oauth2: Fix unintentional persistence
23 months ago Kim Alvefur mod_auth_oauth_external: Update compatibility section with unknowns
23 months ago Kim Alvefur mod_auth_oauth_external: Also do XEP-0106 escaping in SASL OAUTHBEARER
23 months ago Kim Alvefur mod_auth_oauth_external: Stub not implemented auth module methods
23 months ago Kim Alvefur mod_auth_oauth_external: Add Mastodon to README
23 months ago Kim Alvefur mod_auth_oauth_external: Allow different username in PLAIN vs final JID
23 months ago Kim Alvefur mod_auth_oauth_external: Remove untested JID mapping
23 months ago Kim Alvefur mod_auth_oauth_external: Remove untested role mapping
23 months ago Kim Alvefur mod_auth_oauth_external: Expect XEP-0106 escaped username in PLAIN
23 months ago Kim Alvefur mod_auth_oauth_external: Make 'scope' configurable in password grant request
23 months ago Kim Alvefur mod_auth_oauth_external: Add setting for client_secret
23 months ago Kim Alvefur mod_auth_oauth_external: Work without token validation endpoint
23 months ago Kim Alvefur mod_auth_oauth_external: Fix missing import of util.jid
23 months ago Kim Alvefur mod_rest/rest.sh: Trim trailing whitespace
23 months ago Kim Alvefur mod_rest/rest.sh: Add --logout to revoke token
23 months ago Kim Alvefur mod_rest/rest.sh: Make scopes to request configurable in restrc
23 months ago Kim Alvefur mod_http_oauth2: Strip unknown scopes from consent page
23 months ago Kim Alvefur mod_http_oauth2: Simplify code with the power of first class functions
23 months ago Kim Alvefur mod_http_oauth2: More functional functions
23 months ago Kim Alvefur mod_http_oauth2: Add function for filtering roles
23 months ago Kim Alvefur mod_http_oauth2: Support granting zero role-scopes
23 months ago Kim Alvefur mod_http_oauth2: Revert role selector, going to try something else
23 months ago Kim Alvefur mod_http_oauth2: Include all granted roles in scopes
23 months ago Kim Alvefur mod_block_registrations: Refresh Compatibility section
23 months ago Kim Alvefur mod_block_registrations: Update description expansion of default list
23 months ago Kim Alvefur mod_http_oauth2: Bail out of implicit flow on invalid or missing redirect
23 months ago Kim Alvefur mod_http_oauth2: Fix error if no scopes requested
23 months ago Kim Alvefur mod_http_oauth2: Add role selector to consent page
23 months ago Kim Alvefur mod_http_oauth2: Refactor scope handling into smaller functions
23 months ago Kim Alvefur mod_http_oauth2: Add option for specifying TTL of registered clients
23 months ago Kim Alvefur mod_strict_https: Add way to disable redirect
23 months ago Kim Alvefur mod_strict_https: Refresh README
23 months ago Kim Alvefur mod_prometheus: Wrap pointer to mod_http_openmetrics in a box
23 months ago Kim Alvefur mod_listusers: Obsolete, suggest prosodyctl shell instead
23 months ago Kim Alvefur mod_strict_https: Update to use modern APIs instead of monkey patching
23 months ago Kim Alvefur mod_http_oauth2: Link to RFC 7009: OAuth 2.0 Token Revocation
23 months ago Kim Alvefur mod_http_oauth2: Add service documentation URL to metadata
23 months ago Kim Alvefur mod_http_oauth2: Allow configuring links to policy and terms in metadata
23 months ago Kim Alvefur mod_http_oauth2: Don't issue client_secret when not using authentication
23 months ago Kim Alvefur mod_http_oauth2: Validate consistency of response and grant types
23 months ago Kim Alvefur mod_http_oauth2: Enforce response type encoded in client_id
23 months ago Kim Alvefur mod_http_oauth2: Strip unknown extra fields from client registration
23 months ago Kim Alvefur mod_http_oauth2: Simplify validation of various URIs
23 months ago Kim Alvefur mod_http_oauth2: More appropriate error conditions in client validation
23 months ago Kim Alvefur mod_http_oauth2: Reject loopback URIs as client_uri
23 months ago Kim Alvefur mod_http_oauth2: Reduce line count of metadata construction
23 months ago Kim Alvefur mod_http_oauth2: Advertise response modes
23 months ago Kim Alvefur mod_http_oauth2: Advertise supported grant types
23 months ago Kim Alvefur mod_http_oauth2: Advertise revocation endpoint in metadata
23 months ago Kim Alvefur mod_http_oauth2: Return status 405 for GET to endpoints without GET handler
23 months ago Kim Alvefur mod_inotify_reload: Update to use FD watching method
23 months ago Kim Alvefur mod_http_oauth2: Allow loopback IP literals in redirect URIs
23 months ago Kim Alvefur mod_http_oauth2: Add way to retrieve registration schema
23 months ago Kim Alvefur mod_http_oauth2: Fix missing base64 part of base64url (Thanks KeyCloak)
23 months ago Kim Alvefur mod_http_oauth2: Fix accidental uppercase in invocation of hash function
23 months ago Kim Alvefur mod_http_oauth2: Advertise the currently supported id_token signing algorithm
23 months ago Kim Alvefur mod_http_oauth2: Specify that 'contacts' items are emails in client registration
23 months ago Kim Alvefur Back out 6f13200c9fc1: Confused request URI with redirect URI
23 months ago Kim Alvefur mod_rest/rest.sh: Implement RFC 7636 PKCE with the 'plain' method
23 months ago Kim Alvefur mod_http_oauth2: Advertise required registration of redirect URIs
23 months ago Kim Alvefur mod_http_oauth2: Advertise supported token endpoint auth methods
23 months ago Kim Alvefur mod_http_oauth2: Allow configuring PKCE challenge methods
23 months ago Kim Alvefur mod_http_oauth2: Implement RFC 7628 Proof Key for Code Exchange
23 months ago Kim Alvefur mod_http_oauth2: Reorder routes into order they happen in OAuth 2.0
23 months ago Matthew Wild mod_firewall: Initialize compiled chunk just once for all handlers
23 months ago Kim Alvefur mod_rest/rest.sh: Set software_id in client registration to something
23 months ago Kim Alvefur mod_rest/rest.sh: Include .sh suffix in client registration
23 months ago Kim Alvefur mod_http_oauth2: Record OAuth software id and version attached to tokens
23 months ago Kim Alvefur mod_http_oauth2: Fix misplaced 'default' on wrong side of } in client registration schema
23 months ago Matthew Wild mod_remote_roster: Set id on generated iq stanzas (thanks @agwa)
23 months ago Kim Alvefur mod_http_oauth2: Fix to include "openid" scope in discovery metadata
23 months ago Kim Alvefur mod_client_management: Show time for recent timestamps in shell command
23 months ago Kim Alvefur mod_client_management: Fix changed column cell "key"
23 months ago Kim Alvefur mod_client_management: Fix error when called against host without this module
23 months ago Kim Alvefur mod_client_management: Move table cell formatting into column specification
23 months ago Kim Alvefur mod_client_management: Fix type confusion
23 months ago Kim Alvefur mod_client_management: Fix error when last password change is unknown (or never)
23 months ago Kim Alvefur mod_rest/rest.sh: Register as native application
23 months ago Kim Alvefur mod_http_oauth2: Validate redirect URI depending on application type
23 months ago Kim Alvefur mod_http_oauth2: Fill in some client metadata defaults
23 months ago Kim Alvefur mod_http_oauth2: Allow only l10n variants of name in client metadata
23 months ago Kim Alvefur mod_http_oauth2: Normalize whitespace in client metadata schema
23 months ago Matthew Wild mod_log_ringbuffer: Fix description and examples of level configuration
23 months ago Matthew Wild mod_log_ringbuffer: Fix example config
23 months ago Kim Alvefur mod_oidc_userinfo_vcard4: Fix phone number claim
23 months ago Kim Alvefur mod_oidc_userinfo_vcard4: Unpack <vcard> from PubSub <item>
23 months ago Kim Alvefur mod_http_oauth2: Use new Lua pattern schema properties
23 months ago Kim Alvefur mod_http_oauth2: Include additional OpenID scopes in metadata
23 months ago Kim Alvefur mod_http_oauth2: Validate (unused at this point) localized URIs
23 months ago Kim Alvefur mod_http_oauth2: Declare https as required of URIs in schema
23 months ago Kim Alvefur mod_http_oauth2: Enforce https requirement on TOS URI
23 months ago Kim Alvefur mod_http_oauth2: Use new mod_cron API for periodic cleanup
23 months ago Kim Alvefur mod_audit_status: Fix error on first start
23 months ago Matthew Wild mod_muc_rtbl: Use correct occupant object
23 months ago Kim Alvefur mod_audit: Move underscore to avoid luacheck warning
23 months ago Kim Alvefur mod_oidc_userinfo_vcard4: Provide profile details in mod_http_oauth2
23 months ago Kim Alvefur mod_auth_oauth_external: Add configuration example
23 months ago Kim Alvefur mod_auth_oauth_external: Linkify password grant
23 months ago Kim Alvefur mod_auth_oauth_external: Some notes in README
2023-03-16 Kim Alvefur mod_auth_oauth_external: Allow setting identity instead of discovery URL
2023-03-16 Kim Alvefur mod_auth_oauth_external: Support PLAIN via resource owner password grant
2023-03-16 Kim Alvefur mod_auth_oauth_external: Authenticate against an OAuth 2 provider
23 months ago Kim Alvefur mod_client_management: Fix import of util.error (not errors)
23 months ago Kim Alvefur mod_rest: Implement use of refresh tokens in rest.sh example
23 months ago Kim Alvefur mod_http_oauth2: Fix error due to reference loop when using refresh token
23 months ago Kim Alvefur mod_http_oauth2: Fix table index error when using refresh token
23 months ago Maxime “pep” Buquet mod_muc_http_defaults: Use the new set_subject API. Thanks John Livingston
24 months ago Kim Alvefur mod_service_outage_status: XEP-0455: Service Outage Status
24 months ago Kim Alvefur mod_http_oauth2: Support OpenID UserInfo claims
24 months ago Kim Alvefur mod_http_oauth2: Add some debug logging for UserInfo endpoint
24 months ago Kim Alvefur mod_http_oauth2: Correct error code when missing credentials for userinfo
24 months ago Kim Alvefur mod_rest: Get correct type from config
24 months ago Kim Alvefur mod_http_debug: Module that echos back HTTP request info for debugging
24 months ago Kim Alvefur mod_rest: Allow passing configuring a timeout for <iq> responses
24 months ago Matthew Wild mod_audit: Add expiration of entries, and handling of full archive stores
24 months ago Kim Alvefur mod_rest/rest.sh: Update 'client_uri' to module page
24 months ago Kim Alvefur mod_rest/rest.sh: List dependencies in comment
24 months ago Kim Alvefur mod_http_oauth2/README: Add rest.sh to known implementations
24 months ago Matthew Wild mod_audit: Add 'note' column
24 months ago Matthew Wild mod_audit: Improve filtering options and add documentation to README
24 months ago Matthew Wild mod_audit: Add some control over output columns via command-line flags
24 months ago Matthew Wild mod_audit_status: Include shutdown reason in log entry
24 months ago Matthew Wild mod_audit: Let util.human.io pick a suitable default width
24 months ago Matthew Wild mod_audit: Use proportional columns in table output
24 months ago Matthew Wild mod_audit: Fix iteration of custom payloads to use ipairs
24 months ago Matthew Wild mod_audit_status: New module to log server status to audit log
24 months ago Matthew Wild mod_audit: Display most recent entries first, rather than showing oldest
24 months ago Matthew Wild mod_audit: Minor style nit
24 months ago Matthew Wild mod_audit: Allow caller to specify time of the event
24 months ago Kim Alvefur mod_http_oauth2/README: Link to mod_rest
24 months ago Kim Alvefur mod_http_oauth2/README: Link to OAuth and OIDC sites
24 months ago Matthew Wild mod_client_management: README: Update docs to detail shell and XMPP interfaces
24 months ago Matthew Wild mod_http_oauth2: README: Updated documentation to reflect module status
24 months ago Matthew Wild mod_client_management: Add list-clients + manage-clients permissions to users
24 months ago Matthew Wild mod_client_management: Add support for revoking client access via XMPP
24 months ago Matthew Wild mod_client_management: Improve representation of authentication methods
24 months ago Matthew Wild mod_client_management: Improve table output
24 months ago Matthew Wild mod_client_management: Fix user:clients() shell command to take a JID
24 months ago Matthew Wild mod_client_management: Use grant id from key
24 months ago Matthew Wild mod_client_management: Fail to revoke clients that have used passwords
24 months ago Matthew Wild mod_client_management: Add support for revocation of clients (when possible)
24 months ago Matthew Wild mod_client_management: Include client type in XML response listing
24 months ago Matthew Wild mod_sasl2_fast: Add API method to revoke FAST tokens for a given client
24 months ago Matthew Wild mod_cloud_notify_filters: Fix traceback when invalid JIDs are submitted
24 months ago Matthew Wild mod_client_management: Add XMPP and shell interfaces to fetch client list
24 months ago Matthew Wild .luacheckrc: Add module.once
24 months ago Matthew Wild mod_audit: Add a command to print the audit log on the command-line
24 months ago Matthew Wild mod_audit: Support for adding location (GeoIP) to audit events
24 months ago Jonas Schäfer mod_isolate_host: potentially pedantic optimization
24 months ago Jonas Schäfer mod_isolate_host: handle server-generated stanzas
2023-03-31 Jonas Schäfer mod_authz_delegate: make resistant against startup order issues
2023-03-30 Matthew Wild mod_client_management: New module for users to view/manage permitted clients
2023-03-30 Kim Alvefur mod_http_admin_api: Add roles to user schema in openapi
2023-03-30 Kim Alvefur mod_http_admin_api: Fix types of numbers in openapi spec
2023-03-29 Kim Alvefur Merge accidental extra head
2023-03-29 Jonas Schäfer mod_vcard_muc: take roles into account for access check
2023-03-29 Jonas Schäfer mod_authz_delegate: introduce module to "link" authorization of hosts
2023-03-29 Jonas Schäfer mod_authz_delegate: introduce module to "link" authorization of hosts
2023-03-29 Matthew Wild mod_sasl2_fast: Add an API that allows modules to check if a client has FAST
2023-03-29 Matthew Wild mod_sasl2_fast: Add flag to FAST sasl_handler for easier identification
2023-03-29 Matthew Wild mod_sasl2_fast: Fix harmless off-by-one error (invalidates existing tokens!)
2023-03-28 Kim Alvefur mod_http_admin_api: Fix missing import
2023-03-28 Kim Alvefur mod_http_admin_api: Tweak token session to please module:may()
2023-03-28 Matthew Wild mod_sasl2_fast: Invalidate tokens issued prior to last password change
2023-03-27 Kim Alvefur mod_rest: Add an example bash script for using mod_rest
2023-03-27 Matthew Wild mod_http_oauth2: Update to use new API of Prosody mod_tokenauth @ 601d9a375b86
2023-03-24 Matthew Wild mod_http_oauth2: Add support for refresh tokens
2023-03-26 Kim Alvefur mod_http_oauth2: Declare additional client registration fields as strings
2023-03-26 Kim Alvefur mod_http_oauth2: Stricten check of urlencoded form data
2023-03-26 Kim Alvefur mod_http_oauth2: Pedantic optimization
2023-03-25 Kim Alvefur mod_pubsub_feeds: Fix packaging of support library for installer
2023-03-17 Kim Alvefur mod_muc_rtbl: Handle node purge
2023-03-23 Kim Alvefur mod_http_oauth2: Fix traceback on missing 'scope' parameter
2023-03-23 Kim Alvefur mod_http_oauth2: Focus username field automatically
2023-03-23 Kim Alvefur mod_http_oauth2: Allow user to decide which requested scopes to grant
2023-03-23 Kim Alvefur mod_http_oauth2: Use <fieldset> in templates because it looks nice
2023-03-23 Kim Alvefur mod_rest: Update prosody_oauth.py example to non-legacy OAuth2
2023-03-21 Kim Alvefur mod_http_oauth2: Remove another reference to obsolete function
2023-03-21 Kim Alvefur mod_http_oauth2: Relax payload content type checking in revocation
2023-03-21 Kim Alvefur mod_http_oauth2: Remove now unused code
2023-03-21 Kim Alvefur mod_http_oauth2: Allow revoking a token without OAuth client credentials
2023-03-21 Kim Alvefur mod_http_oauth2: Correctly verify OAuth client credentials on revocation
2023-03-21 Kim Alvefur mod_http_oauth2: Group metadata section into OAuth and OpenID
2023-03-21 Kim Alvefur mod_http_oauth2: Rename oauth client credential related functions
2023-03-21 Matthew Wild mod_sasl2: Pull user-agent info into sasl_handler for later reference
2023-03-19 Kim Alvefur mod_adhoc_oauth2_client: Update to call into mod_http_oauth2
2023-03-19 Kim Alvefur mod_http_oauth2: Refactor to allow reuse of OAuth client creation
2023-03-16 Kim Alvefur mod_http_oauth2: Fix userinfo status code off-by-one
2023-03-16 Kim Alvefur mod_http_oauth2: Implement and return ID Token in authorization code flow
2023-03-16 Kim Alvefur mod_http_oauth2: Reject non-local hosts in more code paths
2023-03-16 Kim Alvefur mod_http_oauth2: Add support for the "openid" scope
2023-03-16 Kim Alvefur mod_http_oauth2: Prepare to handle multiple e.g. non-role scopes
2023-03-16 Kim Alvefur mod_adhoc_oauth2_client: Make note in README about current broken state
2023-03-15 Kim Alvefur mod_http_oauth2: Fix attempt to index a boolean value
2023-03-14 Matthew Wild mod_audit: Allow disabling IP logging, or limiting it to a prefix
2023-03-14 Matthew Wild mod_audit: Include client id in audit log entries (if known)
2023-03-14 Matthew Wild mod_sasl2: Fire authentication-{success,failure} events like mod_saslauth
2023-03-14 Kim Alvefur mod_http_oauth2: Record details of OAuth client a token is issued to
2023-03-12 Kim Alvefur mod_http_oauth2: Invoke mod_http_errors to render error on invalid redirect
2023-03-12 Kim Alvefur mod_http_oauth2: Validate all URIs against client_uri in client registration
2023-03-12 Kim Alvefur mod_http_oauth2: Organize HTTP routes with comments
2023-03-11 Kim Alvefur mod_http_oauth2: Fix validation of informative URIs
2023-03-11 Kim Alvefur mod_http_oauth2: Use more compact IDs
2023-03-11 Kim Alvefur mod_http_oauth2: Validate that informative URLs match the redirect URIs
2023-03-11 Kim Alvefur mod_http_oauth2: Reject insecure redirect URIs
2023-03-11 Kim Alvefur mod_http_oauth2: Validate that redirect URIs are absolute
2023-03-11 Kim Alvefur mod_http_oauth2: Validate basic URI syntax of redirect URIs
2023-03-11 Matthew Wild mod_spam_report_forwarder: Forward spam/abuse reports to one or more JIDs
2023-03-11 Kim Alvefur mod_http_oauth2: Require URL to client informational page in registration
2023-03-11 Kim Alvefur mod_http_oauth2: Reorder client metadata validation schema
2023-03-11 Matthew Wild mod_firewall: Add 'REPORT TO' to report (XEP-0377) a stanza to a specified JID
2023-03-11 Matthew Wild mod_firewall: README: Clarify docs about some of the stanza processing actions
2023-03-11 Matthew Wild mod_firewall: Warn about invalid pubsubitemid list specification
2023-03-11 Matthew Wild mod_firewall: Fix parsing of pubsubitemid list specification
2023-03-10 Kim Alvefur mod_http_oauth2: Fix to disable disabled response handlers correctly
2023-03-10 Kim Alvefur mod_http_oauth2: Log flows enabled and disabled
2023-03-10 Kim Alvefur mod_http_oauth2: Fix appending of query parts in error redirects
2023-03-09 Kim Alvefur mod_http_oauth2: Implement the OpenID userinfo endpoint
2023-03-09 Kim Alvefur mod_http_oauth2: Close site header tags
2023-03-07 Kim Alvefur mod_http_oauth2: Fix contrast of links on consent page
2023-03-07 Matthew Wild mod_http_oauth2: token endpoint: handle missing credentials
2023-03-07 Matthew Wild mod_http_oauth2: Fail early when no authorization header present
2023-03-07 Matthew Wild mod_http_oauth2: Support HTTP Basic auth on token endpoint
2023-03-07 Matthew Wild mod_http_oauth2: Separate extracting credentials from requests and verifying
2023-03-07 Matthew Wild mod_http_oauth2: Reflect ALL attributes of the client registration
2023-03-07 Kim Alvefur mod_rest: Point URLs to mod_http_oauth2 in demo mode
2023-03-07 Matthew Wild mod_http_oauth2: Improve handling of redirect_uri matching and fallback
2023-03-07 Kim Alvefur mod_http_oauth2: Correct field name for HTTP response status code
2023-03-07 Matthew Wild mod_http_oauth2: Fix incorrect function name (thanks Zash/luacheck)
2023-03-07 Matthew Wild mod_cloud_notify: Add note about Lua version requirements to README
2023-03-07 Matthew Wild mod_cloud_notify: Log warning when used on Lua 5.1
2023-03-06 Kim Alvefur mod_http_oauth2: Remove authorization codes after use
2023-03-06 Kim Alvefur mod_http_oauth2: Fix authorization code logic
2023-03-06 Kim Alvefur mod_http_oauth2: Include html templates in package for plugin installer
2023-02-22 Kim Alvefur mod_conversejs: This one weird trick updates options on reload
2023-03-06 Matthew Wild mod_http_oauth2: Switch to '303 See Other' redirects
2023-03-06 Matthew Wild mod_http_oauth2: Allow non-HTTPS on localhost URLs
2023-03-06 Matthew Wild mod_http_oauth2: Add authentication, consent and error pages
2023-03-06 Matthew Wild mod_http_oauth: Factor out issuer URL calculation to a helper function
2023-03-05 Kim Alvefur mod_http_oauth2: Clarify comment referencing mod_http_errors (thanks MattJ)
2023-03-04 Kim Alvefur mod_http_oauth2: Specify host for which to retrieve list of roles
2023-03-04 Kim Alvefur mod_http_oauth2: Return list of active roles in discovery
2023-03-04 Kim Alvefur mod_http_oauth2: Return actually enabled response types in discovery
2023-03-04 Kim Alvefur mod_http_oauth2: Calculate client secret expiry in registration response
2023-03-04 Matthew Wild mod_http_oauth2: Strip trailing '/' from issuer URL
2023-03-03 Kim Alvefur mod_http_oauth2: Advertise endpoints that are enabled
2023-03-03 Kim Alvefur mod_http_oauth2: Separate client_secret verification key from JWT key
2023-03-03 Kim Alvefur mod_http_oauth2: Fix response type config
2023-03-03 Kim Alvefur mod_http_oauth2/README: Document config options
2023-03-03 Kim Alvefur mod_http_oauth2: Remove error message
2023-03-03 Kim Alvefur mod_http_oauth2: Mention name of client when giving out OOB authorization code
2023-03-03 Kim Alvefur mod_http_oauth2: Comment on mutation by other module
2023-03-03 Kim Alvefur mod_http_oauth2: Implement stateless dynamic client registration
2023-03-03 Matthew Wild mod_http_oauth2: Add support for 'iss' authz response parameter (RFC 9207)
2023-03-03 Kim Alvefur mod_http_oauth2: Derive scope from correct user details
2023-03-03 Kim Alvefur mod_http_oauth2: Fix to actually return OOB response
2023-03-03 Matthew Wild mod_http_oauth2: Add OIDC discovery endpoint (thanks Zash)
2023-03-02 Kim Alvefur mod_http_oauth2: Implement OOB special redirect URI in code flow
2023-03-02 Kim Alvefur mod_http_oauth2: Add settings for allowed grant and response types
2023-03-02 Kim Alvefur mod_http_oauth2: Implement the Implicit flow
2023-03-02 Kim Alvefur mod_http_oauth2: Fix treatment of 'redirect_uri' parameter in code flow
2023-03-02 Kim Alvefur mod_s2s_whitelist/README: Show inclusion in modules_enabled in example
2023-03-02 Kim Alvefur mod_s2s_blacklist/README: Show inclusion in modules_enabled in example
2023-03-01 Kim Alvefur mod_http_oauth2: Issue tokens for the purpose of 'oauth2'
2023-03-01 Kim Alvefur mod_http_oauth2: Fix removal of consumed authorization codes
2023-03-01 Matthew Wild mod_sasl2_bind2: Support for SASL handlers forcing a specific resource
2023-02-28 Kim Alvefur mod_rest: Remove confusing oauth2 tokens from examples
2023-02-23 Kim Alvefur mod_register_apps: Detect 0.12+ when called from prosodyctl
2023-02-22 Jonas Schäfer mod_muc_rtbl: fix more incorrect more references to "event"
2023-02-22 Jonas Schäfer mod_muc_rtbl: ignore blocklist for affiliated users for messages
2023-02-22 Jonas Schäfer mod_muc_rtbl: fix traceback because of scoping error
2023-02-21 Jonas Schäfer mod_muc_rtbl: move use of "private" attributes to single function
2023-02-21 Jonas Schäfer mod_muc_rtbl: also filter messages
2023-02-20 Stephen Paul Weber New module, mod_muc_reserve_nick_pattern
2023-02-20 Stephen Paul Weber Strip images from XHTML-IM as well
2023-02-19 Kim Alvefur mod_muc_moderation: Derive role from reserved nickname if occupant
2023-02-19 Kim Alvefur mod_muc_moderation: Refactor to prepare for new version of XEP-0425
2023-02-19 Kim Alvefur mod_unsubscriber: Revoke roster subscriptions of unreachable hosts
2023-02-16 Kim Alvefur mod_jsxc: Correct description of resources setting (thanks ham5urg)
2023-02-16 Kim Alvefur mod_jsxc: Words about jQuery
2023-02-16 Kim Alvefur mod_jsxc: Add plugin installer metadata
2023-02-16 Kim Alvefur mod_jsxc: Document config options
2023-02-10 Matthew Wild mod_bob: Fix traceback when iq has no payload (thanks meaz)
2023-01-30 Matthew Wild mod_muc_auto_member: New module to automatically make MUC participants members
2023-01-29 Kim Alvefur mod_http_status: Report module statuses
2023-01-27 Kim Alvefur mod_firewall: Fix 'is_admin' internal dependency rule #1797 (thanks diane)
2023-01-25 Kim Alvefur mod_rest/README: Words about bearer tokens
2023-01-16 Kim Alvefur mod_inject_ecaps2: Mention and link to XEP-0390 in text
2023-01-14 Matthew Wild mod_unified_push: Update docs to recommend loading on normal hosts
2023-01-14 Matthew Wild mod_unified_push: README: Update docs
2023-01-14 Matthew Wild mod_unified_push: Make unified_push_secret only required for jwt backend
2023-01-14 Matthew Wild mod_unified_push: Improved error handling and reporting
2023-01-14 Matthew Wild mod_unified_push: fix return values for paseto backend
2023-01-14 Matthew Wild mod_unified_push: Fix storage backend error behaviours and return values
2023-01-14 Matthew Wild mod_unified_push: Fix default ACL in component mode
2023-01-14 Matthew Wild mod_unified_push: Fixes for paseto backend initialization
2023-01-14 Matthew Wild mod_unified_push: Add support for multiple token backends, including stoage
2023-01-13 Matthew Wild mod_unified_push: Refactor in anticipation of other registration backends
2023-01-13 Matthew Wild mod_unified_push: Add ACL option to restrict access
2023-01-13 Matthew Wild mod_unified_push: Fix JWT method parameter order (fixes #1791)
2023-01-13 Kim Alvefur mod_http_dir_listing: Update Compatibility section
2023-01-13 Kim Alvefur mod_http_dir_listing: Add metadata to fix plugin package build
2023-01-11 Matthew Wild mod_invites_api: Fix traceback when no query params (thanks Menel)
2023-01-11 Matthew Wild mod_invites_api: Fix traceback on list command with no entries (thanks mirux)
2023-01-10 Kim Alvefur Remove reverse dependencies on mod_invites (for plugin installer)
2023-01-10 Kim Alvefur mod_pubsub_summary: Mention HTML to Message Styling conversion
2023-01-10 Matthew Wild mod_unified_push: Remove dependency on trunk util.jwt (0.12 compat)
2023-01-10 Matthew Wild mod_unified_push: README: Documentation updates (example, etc.)
2023-01-10 Matthew Wild mod_sasl2_fast: Add some comments
2023-01-10 Matthew Wild mod_unified_push: Various fixes, now working with Conversations
2023-01-10 Kim Alvefur mod_pubsub_summary: Trim preceding and trailing whitespace from title
2023-01-08 Kim Alvefur mod_pubsub_text_interface: Try to clarify help message wrt node arguments
2023-01-08 Kim Alvefur mod_pubsub_text_interface: Improve error messages
2023-01-08 Martin Dosch mod_onions: Fix URL and linkify it.
2023-01-08 Kim Alvefur mod_pubsub_summary: Render geo:-URI from OASIS emergency broadcasts
2023-01-07 Kim Alvefur mod_ping_muc: Error out if loaded on Components
2023-01-07 Kim Alvefur mod_pubsub_summary: Hide link relation when value is "alternate"
2023-01-05 Matthew Wild mod_unified_push: Experimenal Unified Push provider
2023-01-03 Kim Alvefur mod_muc_moderation/README: Simplify Compatibility section
2022-12-31 Kim Alvefur mod_rest: Fix reference in OpenAPI
2022-12-31 Kim Alvefur mod_rest: Add XEP-0461 to OpenAPI
2022-12-31 Kim Alvefur mod_rest: Add missing message properties to OpenAPI documentation
2022-12-31 Kim Alvefur mod_rest: Add some GET-mapped iq-queries to OpenAPI documentation
2022-12-31 Kim Alvefur mod_rest/README: Fix XML well-formedness in example (thanks drsnuggles)
2022-12-30 Kim Alvefur mod_auth_dovecot: Fix plugin package (hopefully) (thanks nw)
2022-12-25 Kim Alvefur mod_s2s_auth_dane: Update Compatibility chart (doesn't work anymore)
2022-12-20 Kim Alvefur mod_rest: Remove manual reference expansion in schema
2022-12-18 Kim Alvefur Merge
2022-12-17 Jonas Schäfer Backed out changeset 85882735fd33
2022-12-17 Jonas Schäfer mod_http_muc_log: make default presence visibility configurable
2022-04-28 Jonas Schäfer mod_audit: remove event hook
2022-12-16 Matthew Wild mod_pubsub_mqtt: Switch to MQTT 3.1.1
2022-12-16 Matthew Wild mod_pubsub_mqtt: Support atom_title payload type
2022-12-16 Matthew Wild mod_pubsub_mqtt: Fix some inappropriate log levels
2022-12-16 Matthew Wild mod_pubsub_mqtt: Add XEP-0060 <item> wrapper to payloads
2022-12-09 Kim Alvefur mod_pubsub_feeds: Include feeds library in plugin package
2022-12-04 Kim Alvefur mod_http_muc_log: Fix syntax error in timestamp adjusting script
2022-12-04 Kim Alvefur mod_http_muc_log: Move language attribute onto body itself
2022-12-04 Kim Alvefur mod_http_muc_log: Tweak style towards the "modern"
2022-12-04 Kim Alvefur mod_http_muc_log: Fix error in js when displaying presence is disabled
2022-12-04 Kim Alvefur mod_http_muc_log: Include static resources (css & js) in plugin package
2022-12-04 Kim Alvefur mod_http_muc_log: Move CSS and JS out of template
2022-12-02 Kim Alvefur mod_s2soutinjection: Use session logger where it makes sense
2022-12-02 Kim Alvefur mod_s2soutinjection: Use module logging API
2022-12-02 Kim Alvefur mod_s2soutinjection: Remove undefined global (thanks Damian)
2022-12-02 Kim Alvefur mod_s2soutinjection: Remove unused variables [luacheck]
2022-11-29 Matthew Wild mod_compat_roles: Add support for role inheritance (built-in roles only)
2022-11-29 Matthew Wild mod_compat_roles: Fix permission checks/roles to be per-host as intended
2022-11-29 Matthew Wild mod_compat_roles: Fix traceback when no host roles are defined (thanks cc)
2022-11-29 Matthew Wild mod_isolate_host: Pass context to module:may() (thanks cc)
2022-11-28 Kim Alvefur mod_sasl2_fast: Add explicit dependency on mod_sasl2
2022-11-28 Kim Alvefur mod_sasl2_sm: Add explicit dependency on mod_sasl2
2022-11-28 Kim Alvefur mod_sasl2_bind2: Add explicit dependency on mod_sasl2
2022-11-28 Matthew Wild mod_sasl2_fast: Add README
2022-11-28 Matthew Wild mod_sasl2_sm: Update README with current information