log

age author description
22 months ago Matthew Wild mod_invites_adhoc: Fall back to generic allow_user_invites for role-less users
22 months ago Kim Alvefur mod_invites{,_adhoc,_register}: Recommend using version included with prosody
22 months ago Kim Alvefur mod_welcome_page: Remove dependency on mod_invites (included with Prosody)
22 months ago Kim Alvefur mod_http_oauth2: Allow CORS for browser clients
22 months ago Kim Alvefur mod_http_oauth2: Disable Referrer via header
22 months ago Kim Alvefur mod_http_oauth2: Always render errors as HTML for OOB redirect URI
22 months ago Kim Alvefur mod_http_oauth2: Use validated redirect URI when returning errors to client
22 months ago Kim Alvefur mod_http_oauth2: Return OAuth error for authz code store error
22 months ago Kim Alvefur mod_http_oauth2: Validate redirect_uri before using it for error redirects
22 months ago Kim Alvefur mod_http_oauth2: Don't return redirects or HTML from token endpoint
22 months ago Kim Alvefur mod_http_oauth2: Tweak formatting of log message
22 months ago Kim Alvefur mod_http_oauth2: Always show early errors to user
22 months ago Kim Alvefur mod_http_oauth2: Clarify some error messages
22 months ago Kim Alvefur mod_http_oauth2: Use error status code when rendering error page
22 months ago Kim Alvefur mod_http_oauth2: Add human-readable error messages
22 months ago Kim Alvefur mod_http_oauth2: Fix returning errors from response handlers
22 months ago Kim Alvefur mod_http_oauth2: Add a special "xmpp" scope that grants the users' default role
22 months ago Kim Alvefur mod_http_oauth2: Add support for the OpenID 'login_hint' parameter
22 months ago Kim Alvefur mod_http_oauth2: Note about partial OpenID Discovery implementation
22 months ago Kim Alvefur mod_http_oauth2: Split long list line in README
22 months ago Kim Alvefur mod_http_oauth2: Proper OAuth error for invalid redirect URI in implicit flow too
22 months ago Kim Alvefur mod_http_oauth2: Return proper OAuth error for invalid redirect URI
22 months ago Kim Alvefur mod_http_oauth2: Fix use of arbitrary ports in loopback redirect URIs
22 months ago Kim Alvefur mod_http_oauth2: Add FIXME about loopback redirect URIs
22 months ago Kim Alvefur mod_http_oauth2: Rename variables to improve clarity
22 months ago Kim Alvefur mod_http_oauth2: Do minimal validation of private-use URI schemes
22 months ago Kim Alvefur mod_http_oauth2: Reject relative redirect URIs
22 months ago Kim Alvefur mod_http_oauth2: Reject duplicate list items in client registration
22 months ago Kim Alvefur mod_http_oauth2: Require non-empty arrays in client registration
22 months ago Kim Alvefur mod_http_oauth2: Reject duplicate redirect URIs in registration
22 months ago Kim Alvefur mod_http_oauth2: Fix schema to enforce at least one redirect URI
22 months ago Kim Alvefur mod_http_oauth2: Show only roles the user can use in consent dialog
22 months ago Kim Alvefur mod_http_oauth2: Reference grant by id instead of value
22 months ago Kim Alvefur mod_http_oauth2: Scope FIXMEs
22 months ago Kim Alvefur mod_http_oauth2: Describe type signatures of scope handling functions
22 months ago Kim Alvefur mod_http_oauth2: Allow requesting a subset of scopes on token refresh
22 months ago Kim Alvefur mod_http_oauth2: Enforce client scope restrictions in authorization
22 months ago Kim Alvefur mod_http_oauth2: Fix inclusion of role in refreshed access tokens
22 months ago Kim Alvefur mod_http_oauth2: Fix unintentional persistence
23 months ago Kim Alvefur mod_auth_oauth_external: Update compatibility section with unknowns
23 months ago Kim Alvefur mod_auth_oauth_external: Also do XEP-0106 escaping in SASL OAUTHBEARER
23 months ago Kim Alvefur mod_auth_oauth_external: Stub not implemented auth module methods
23 months ago Kim Alvefur mod_auth_oauth_external: Add Mastodon to README
23 months ago Kim Alvefur mod_auth_oauth_external: Allow different username in PLAIN vs final JID
23 months ago Kim Alvefur mod_auth_oauth_external: Remove untested JID mapping
23 months ago Kim Alvefur mod_auth_oauth_external: Remove untested role mapping
23 months ago Kim Alvefur mod_auth_oauth_external: Expect XEP-0106 escaped username in PLAIN
23 months ago Kim Alvefur mod_auth_oauth_external: Make 'scope' configurable in password grant request
23 months ago Kim Alvefur mod_auth_oauth_external: Add setting for client_secret
23 months ago Kim Alvefur mod_auth_oauth_external: Work without token validation endpoint
23 months ago Kim Alvefur mod_auth_oauth_external: Fix missing import of util.jid
23 months ago Kim Alvefur mod_rest/rest.sh: Trim trailing whitespace
23 months ago Kim Alvefur mod_rest/rest.sh: Add --logout to revoke token
23 months ago Kim Alvefur mod_rest/rest.sh: Make scopes to request configurable in restrc
23 months ago Kim Alvefur mod_http_oauth2: Strip unknown scopes from consent page
23 months ago Kim Alvefur mod_http_oauth2: Simplify code with the power of first class functions
23 months ago Kim Alvefur mod_http_oauth2: More functional functions
23 months ago Kim Alvefur mod_http_oauth2: Add function for filtering roles
23 months ago Kim Alvefur mod_http_oauth2: Support granting zero role-scopes
23 months ago Kim Alvefur mod_http_oauth2: Revert role selector, going to try something else
23 months ago Kim Alvefur mod_http_oauth2: Include all granted roles in scopes
23 months ago Kim Alvefur mod_block_registrations: Refresh Compatibility section
23 months ago Kim Alvefur mod_block_registrations: Update description expansion of default list
23 months ago Kim Alvefur mod_http_oauth2: Bail out of implicit flow on invalid or missing redirect
23 months ago Kim Alvefur mod_http_oauth2: Fix error if no scopes requested
23 months ago Kim Alvefur mod_http_oauth2: Add role selector to consent page
23 months ago Kim Alvefur mod_http_oauth2: Refactor scope handling into smaller functions
23 months ago Kim Alvefur mod_http_oauth2: Add option for specifying TTL of registered clients
23 months ago Kim Alvefur mod_strict_https: Add way to disable redirect
23 months ago Kim Alvefur mod_strict_https: Refresh README
23 months ago Kim Alvefur mod_prometheus: Wrap pointer to mod_http_openmetrics in a box
23 months ago Kim Alvefur mod_listusers: Obsolete, suggest prosodyctl shell instead
23 months ago Kim Alvefur mod_strict_https: Update to use modern APIs instead of monkey patching
23 months ago Kim Alvefur mod_http_oauth2: Link to RFC 7009: OAuth 2.0 Token Revocation
23 months ago Kim Alvefur mod_http_oauth2: Add service documentation URL to metadata
23 months ago Kim Alvefur mod_http_oauth2: Allow configuring links to policy and terms in metadata
23 months ago Kim Alvefur mod_http_oauth2: Don't issue client_secret when not using authentication
23 months ago Kim Alvefur mod_http_oauth2: Validate consistency of response and grant types
23 months ago Kim Alvefur mod_http_oauth2: Enforce response type encoded in client_id
23 months ago Kim Alvefur mod_http_oauth2: Strip unknown extra fields from client registration
23 months ago Kim Alvefur mod_http_oauth2: Simplify validation of various URIs
23 months ago Kim Alvefur mod_http_oauth2: More appropriate error conditions in client validation
23 months ago Kim Alvefur mod_http_oauth2: Reject loopback URIs as client_uri
23 months ago Kim Alvefur mod_http_oauth2: Reduce line count of metadata construction
23 months ago Kim Alvefur mod_http_oauth2: Advertise response modes
23 months ago Kim Alvefur mod_http_oauth2: Advertise supported grant types
23 months ago Kim Alvefur mod_http_oauth2: Advertise revocation endpoint in metadata
23 months ago Kim Alvefur mod_http_oauth2: Return status 405 for GET to endpoints without GET handler
23 months ago Kim Alvefur mod_inotify_reload: Update to use FD watching method
23 months ago Kim Alvefur mod_http_oauth2: Allow loopback IP literals in redirect URIs
23 months ago Kim Alvefur mod_http_oauth2: Add way to retrieve registration schema
23 months ago Kim Alvefur mod_http_oauth2: Fix missing base64 part of base64url (Thanks KeyCloak)
23 months ago Kim Alvefur mod_http_oauth2: Fix accidental uppercase in invocation of hash function
23 months ago Kim Alvefur mod_http_oauth2: Advertise the currently supported id_token signing algorithm
23 months ago Kim Alvefur mod_http_oauth2: Specify that 'contacts' items are emails in client registration
23 months ago Kim Alvefur Back out 6f13200c9fc1: Confused request URI with redirect URI
23 months ago Kim Alvefur mod_rest/rest.sh: Implement RFC 7636 PKCE with the 'plain' method
23 months ago Kim Alvefur mod_http_oauth2: Advertise required registration of redirect URIs
23 months ago Kim Alvefur mod_http_oauth2: Advertise supported token endpoint auth methods
23 months ago Kim Alvefur mod_http_oauth2: Allow configuring PKCE challenge methods
23 months ago Kim Alvefur mod_http_oauth2: Implement RFC 7628 Proof Key for Code Exchange
23 months ago Kim Alvefur mod_http_oauth2: Reorder routes into order they happen in OAuth 2.0
23 months ago Matthew Wild mod_firewall: Initialize compiled chunk just once for all handlers
23 months ago Kim Alvefur mod_rest/rest.sh: Set software_id in client registration to something
23 months ago Kim Alvefur mod_rest/rest.sh: Include .sh suffix in client registration
23 months ago Kim Alvefur mod_http_oauth2: Record OAuth software id and version attached to tokens
23 months ago Kim Alvefur mod_http_oauth2: Fix misplaced 'default' on wrong side of } in client registration schema
23 months ago Matthew Wild mod_remote_roster: Set id on generated iq stanzas (thanks @agwa)
23 months ago Kim Alvefur mod_http_oauth2: Fix to include "openid" scope in discovery metadata
23 months ago Kim Alvefur mod_client_management: Show time for recent timestamps in shell command
23 months ago Kim Alvefur mod_client_management: Fix changed column cell "key"
23 months ago Kim Alvefur mod_client_management: Fix error when called against host without this module
23 months ago Kim Alvefur mod_client_management: Move table cell formatting into column specification
23 months ago Kim Alvefur mod_client_management: Fix type confusion
23 months ago Kim Alvefur mod_client_management: Fix error when last password change is unknown (or never)
23 months ago Kim Alvefur mod_rest/rest.sh: Register as native application
23 months ago Kim Alvefur mod_http_oauth2: Validate redirect URI depending on application type
23 months ago Kim Alvefur mod_http_oauth2: Fill in some client metadata defaults
23 months ago Kim Alvefur mod_http_oauth2: Allow only l10n variants of name in client metadata
23 months ago Kim Alvefur mod_http_oauth2: Normalize whitespace in client metadata schema
23 months ago Matthew Wild mod_log_ringbuffer: Fix description and examples of level configuration
23 months ago Matthew Wild mod_log_ringbuffer: Fix example config
23 months ago Kim Alvefur mod_oidc_userinfo_vcard4: Fix phone number claim
23 months ago Kim Alvefur mod_oidc_userinfo_vcard4: Unpack <vcard> from PubSub <item>
23 months ago Kim Alvefur mod_http_oauth2: Use new Lua pattern schema properties
23 months ago Kim Alvefur mod_http_oauth2: Include additional OpenID scopes in metadata
23 months ago Kim Alvefur mod_http_oauth2: Validate (unused at this point) localized URIs
23 months ago Kim Alvefur mod_http_oauth2: Declare https as required of URIs in schema
23 months ago Kim Alvefur mod_http_oauth2: Enforce https requirement on TOS URI
23 months ago Kim Alvefur mod_http_oauth2: Use new mod_cron API for periodic cleanup
23 months ago Kim Alvefur mod_audit_status: Fix error on first start
23 months ago Matthew Wild mod_muc_rtbl: Use correct occupant object
23 months ago Kim Alvefur mod_audit: Move underscore to avoid luacheck warning
23 months ago Kim Alvefur mod_oidc_userinfo_vcard4: Provide profile details in mod_http_oauth2
23 months ago Kim Alvefur mod_auth_oauth_external: Add configuration example
23 months ago Kim Alvefur mod_auth_oauth_external: Linkify password grant
23 months ago Kim Alvefur mod_auth_oauth_external: Some notes in README
2023-03-16 Kim Alvefur mod_auth_oauth_external: Allow setting identity instead of discovery URL
2023-03-16 Kim Alvefur mod_auth_oauth_external: Support PLAIN via resource owner password grant
2023-03-16 Kim Alvefur mod_auth_oauth_external: Authenticate against an OAuth 2 provider
23 months ago Kim Alvefur mod_client_management: Fix import of util.error (not errors)
23 months ago Kim Alvefur mod_rest: Implement use of refresh tokens in rest.sh example
23 months ago Kim Alvefur mod_http_oauth2: Fix error due to reference loop when using refresh token
23 months ago Kim Alvefur mod_http_oauth2: Fix table index error when using refresh token
23 months ago Maxime “pep” Buquet mod_muc_http_defaults: Use the new set_subject API. Thanks John Livingston
24 months ago Kim Alvefur mod_service_outage_status: XEP-0455: Service Outage Status
24 months ago Kim Alvefur mod_http_oauth2: Support OpenID UserInfo claims
24 months ago Kim Alvefur mod_http_oauth2: Add some debug logging for UserInfo endpoint
24 months ago Kim Alvefur mod_http_oauth2: Correct error code when missing credentials for userinfo
24 months ago Kim Alvefur mod_rest: Get correct type from config
24 months ago Kim Alvefur mod_http_debug: Module that echos back HTTP request info for debugging
24 months ago Kim Alvefur mod_rest: Allow passing configuring a timeout for <iq> responses
24 months ago Matthew Wild mod_audit: Add expiration of entries, and handling of full archive stores
24 months ago Kim Alvefur mod_rest/rest.sh: Update 'client_uri' to module page
24 months ago Kim Alvefur mod_rest/rest.sh: List dependencies in comment
24 months ago Kim Alvefur mod_http_oauth2/README: Add rest.sh to known implementations
24 months ago Matthew Wild mod_audit: Add 'note' column
24 months ago Matthew Wild mod_audit: Improve filtering options and add documentation to README
24 months ago Matthew Wild mod_audit: Add some control over output columns via command-line flags
24 months ago Matthew Wild mod_audit_status: Include shutdown reason in log entry
24 months ago Matthew Wild mod_audit: Let util.human.io pick a suitable default width
24 months ago Matthew Wild mod_audit: Use proportional columns in table output
24 months ago Matthew Wild mod_audit: Fix iteration of custom payloads to use ipairs
24 months ago Matthew Wild mod_audit_status: New module to log server status to audit log
24 months ago Matthew Wild mod_audit: Display most recent entries first, rather than showing oldest
24 months ago Matthew Wild mod_audit: Minor style nit
24 months ago Matthew Wild mod_audit: Allow caller to specify time of the event
24 months ago Kim Alvefur mod_http_oauth2/README: Link to mod_rest
24 months ago Kim Alvefur mod_http_oauth2/README: Link to OAuth and OIDC sites
24 months ago Matthew Wild mod_client_management: README: Update docs to detail shell and XMPP interfaces
24 months ago Matthew Wild mod_http_oauth2: README: Updated documentation to reflect module status
24 months ago Matthew Wild mod_client_management: Add list-clients + manage-clients permissions to users
24 months ago Matthew Wild mod_client_management: Add support for revoking client access via XMPP
24 months ago Matthew Wild mod_client_management: Improve representation of authentication methods
24 months ago Matthew Wild mod_client_management: Improve table output
24 months ago Matthew Wild mod_client_management: Fix user:clients() shell command to take a JID
24 months ago Matthew Wild mod_client_management: Use grant id from key
24 months ago Matthew Wild mod_client_management: Fail to revoke clients that have used passwords
24 months ago Matthew Wild mod_client_management: Add support for revocation of clients (when possible)
24 months ago Matthew Wild mod_client_management: Include client type in XML response listing
24 months ago Matthew Wild mod_sasl2_fast: Add API method to revoke FAST tokens for a given client
24 months ago Matthew Wild mod_cloud_notify_filters: Fix traceback when invalid JIDs are submitted
24 months ago Matthew Wild mod_client_management: Add XMPP and shell interfaces to fetch client list
24 months ago Matthew Wild .luacheckrc: Add module.once
24 months ago Matthew Wild mod_audit: Add a command to print the audit log on the command-line
24 months ago Matthew Wild mod_audit: Support for adding location (GeoIP) to audit events
24 months ago Jonas Schäfer mod_isolate_host: potentially pedantic optimization
24 months ago Jonas Schäfer mod_isolate_host: handle server-generated stanzas
2023-03-31 Jonas Schäfer mod_authz_delegate: make resistant against startup order issues
2023-03-30 Matthew Wild mod_client_management: New module for users to view/manage permitted clients
2023-03-30 Kim Alvefur mod_http_admin_api: Add roles to user schema in openapi
2023-03-30 Kim Alvefur mod_http_admin_api: Fix types of numbers in openapi spec
2023-03-29 Kim Alvefur Merge accidental extra head
2023-03-29 Jonas Schäfer mod_vcard_muc: take roles into account for access check
2023-03-29 Jonas Schäfer mod_authz_delegate: introduce module to "link" authorization of hosts
2023-03-29 Jonas Schäfer mod_authz_delegate: introduce module to "link" authorization of hosts
2023-03-29 Matthew Wild mod_sasl2_fast: Add an API that allows modules to check if a client has FAST
2023-03-29 Matthew Wild mod_sasl2_fast: Add flag to FAST sasl_handler for easier identification
2023-03-29 Matthew Wild mod_sasl2_fast: Fix harmless off-by-one error (invalidates existing tokens!)
2023-03-28 Kim Alvefur mod_http_admin_api: Fix missing import
2023-03-28 Kim Alvefur mod_http_admin_api: Tweak token session to please module:may()
2023-03-28 Matthew Wild mod_sasl2_fast: Invalidate tokens issued prior to last password change
2023-03-27 Kim Alvefur mod_rest: Add an example bash script for using mod_rest
2023-03-27 Matthew Wild mod_http_oauth2: Update to use new API of Prosody mod_tokenauth @ 601d9a375b86
2023-03-24 Matthew Wild mod_http_oauth2: Add support for refresh tokens
2023-03-26 Kim Alvefur mod_http_oauth2: Declare additional client registration fields as strings
2023-03-26 Kim Alvefur mod_http_oauth2: Stricten check of urlencoded form data
2023-03-26 Kim Alvefur mod_http_oauth2: Pedantic optimization
2023-03-25 Kim Alvefur mod_pubsub_feeds: Fix packaging of support library for installer
2023-03-17 Kim Alvefur mod_muc_rtbl: Handle node purge
2023-03-23 Kim Alvefur mod_http_oauth2: Fix traceback on missing 'scope' parameter
2023-03-23 Kim Alvefur mod_http_oauth2: Focus username field automatically
2023-03-23 Kim Alvefur mod_http_oauth2: Allow user to decide which requested scopes to grant
2023-03-23 Kim Alvefur mod_http_oauth2: Use <fieldset> in templates because it looks nice
2023-03-23 Kim Alvefur mod_rest: Update prosody_oauth.py example to non-legacy OAuth2
2023-03-21 Kim Alvefur mod_http_oauth2: Remove another reference to obsolete function
2023-03-21 Kim Alvefur mod_http_oauth2: Relax payload content type checking in revocation
2023-03-21 Kim Alvefur mod_http_oauth2: Remove now unused code
2023-03-21 Kim Alvefur mod_http_oauth2: Allow revoking a token without OAuth client credentials
2023-03-21 Kim Alvefur mod_http_oauth2: Correctly verify OAuth client credentials on revocation
2023-03-21 Kim Alvefur mod_http_oauth2: Group metadata section into OAuth and OpenID
2023-03-21 Kim Alvefur mod_http_oauth2: Rename oauth client credential related functions
2023-03-21 Matthew Wild mod_sasl2: Pull user-agent info into sasl_handler for later reference
2023-03-19 Kim Alvefur mod_adhoc_oauth2_client: Update to call into mod_http_oauth2
2023-03-19 Kim Alvefur mod_http_oauth2: Refactor to allow reuse of OAuth client creation
2023-03-16 Kim Alvefur mod_http_oauth2: Fix userinfo status code off-by-one
2023-03-16 Kim Alvefur mod_http_oauth2: Implement and return ID Token in authorization code flow
2023-03-16 Kim Alvefur mod_http_oauth2: Reject non-local hosts in more code paths
2023-03-16 Kim Alvefur mod_http_oauth2: Add support for the "openid" scope
2023-03-16 Kim Alvefur mod_http_oauth2: Prepare to handle multiple e.g. non-role scopes
2023-03-16 Kim Alvefur mod_adhoc_oauth2_client: Make note in README about current broken state
2023-03-15 Kim Alvefur mod_http_oauth2: Fix attempt to index a boolean value
2023-03-14 Matthew Wild mod_audit: Allow disabling IP logging, or limiting it to a prefix
2023-03-14 Matthew Wild mod_audit: Include client id in audit log entries (if known)
2023-03-14 Matthew Wild mod_sasl2: Fire authentication-{success,failure} events like mod_saslauth
2023-03-14 Kim Alvefur mod_http_oauth2: Record details of OAuth client a token is issued to
2023-03-12 Kim Alvefur mod_http_oauth2: Invoke mod_http_errors to render error on invalid redirect
2023-03-12 Kim Alvefur mod_http_oauth2: Validate all URIs against client_uri in client registration
2023-03-12 Kim Alvefur mod_http_oauth2: Organize HTTP routes with comments
2023-03-11 Kim Alvefur mod_http_oauth2: Fix validation of informative URIs