Mercurial > prosody-hg
annotate plugins/muc/config_form_sections.lib.lua @ 12659:c0eea4f6c739
usermanager: Add back temporary is_admin to warn about deprecated API usage
Goal: Introduce role-auth with minimal disruption
is_admin() is unsafe in a system with per-session permissions, so it has been
deprecated.
Roll-out approach:
1) First, log a warning when is_admin() is used. It should continue to
function normally, backed by the new role API. Nothing is really using
per-session authz yet, so there is minimal security concern.
The 'strict_deprecate_is_admin' global setting can be set to 'true' to
force a hard failure of is_admin() attempts (it will log an error and
always return false).
2) In some time (at least 1 week), but possibly longer depending on the number
of affected deployments: switch 'strict_deprecate_is_admin' to 'true' by
default. It can still be disabled for systems that need it.
3) Further in the future, before the next release, the option will be removed
and is_admin() will be permanently disabled.
| author | Matthew Wild <mwild1@gmail.com> |
|---|---|
| date | Mon, 15 Aug 2022 15:25:07 +0100 |
| parents | bb4dcc555091 |
| children |
| rev | line source |
|---|---|
| 9036 | 1 module:hook("muc-config-form", function(event) |
| 2 table.insert(event.form, { | |
| 3 type = "fixed"; | |
| 4 value = "Room information"; | |
| 5 }); | |
| 6 end, 100); | |
| 7 | |
| 8 module:hook("muc-config-form", function(event) | |
| 9 table.insert(event.form, { | |
| 10 type = "fixed"; | |
| 11 value = "Access to the room"; | |
| 12 }); | |
| 13 end, 90); | |
| 14 | |
| 15 module:hook("muc-config-form", function(event) | |
| 16 table.insert(event.form, { | |
| 17 type = "fixed"; | |
| 18 value = "Permissions in the room"; | |
| 19 }); | |
| 20 end, 80); | |
| 21 | |
| 22 module:hook("muc-config-form", function(event) | |
| 23 table.insert(event.form, { | |
| 24 type = "fixed"; | |
| 25 value = "Other options"; | |
| 26 }); | |
| 27 end, 70); |
