Mercurial > prosody-modules
view mod_s2s_auth_compat/mod_s2s_auth_compat.lua @ 6281:17d9533f7596
mod_http_oauth2: Reject invalid attempt to register client without credentials
The implicit flow works without a client_secret since the token is
delivered directly, but all other currently supported grant types
require client to authenticate using credentials, so it makes no sense
to not issue credentials then.
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Thu, 03 Jul 2025 15:45:00 +0200 |
| parents | 21e81fcb8896 |
| children |
line wrap: on
line source
-- COMPAT for Openfire sending stream headers without to or from. module:set_global(); module:hook("s2s-check-certificate", function(event) local session, host = event.session, event.host; if not event.host then (session.log or module._log)("warn", "Invalid stream header, certificate will not be trusted") session.cert_chain_status = "invalid" return true end end, 100);
