Mercurial > prosody-modules
annotate mod_s2s_auth_samecert/README.md @ 6281:17d9533f7596
mod_http_oauth2: Reject invalid attempt to register client without credentials
The implicit flow works without a client_secret since the token is
delivered directly, but all other currently supported grant types
require client to authenticate using credentials, so it makes no sense
to not issue credentials then.
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Thu, 03 Jul 2025 15:45:00 +0200 |
| parents | 021b2686c19b |
| children | 7bca4f5935d6 |
| rev | line source |
|---|---|
|
6249
021b2686c19b
mod_s2s_auth_samecert: Add brief README
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
1 This module authenticates server-to-server connections by looking for an already established connection that uses the exact same certificate, reusing |
|
021b2686c19b
mod_s2s_auth_samecert: Add brief README
Kim Alvefur <zash@zash.se>
parents:
diff
changeset
|
2 the earlier validation results and letting Prosody skip performing slower validation methods such as [POSH][mod_s2s_auth_posh] twice. |
