view mod_tlsfail/mod_tlsfail.lua @ 6232:2505542c6c50

mod_http_oauth2: Deduplicate client authentication Since it is always performed by each grant_type_handler, it can now be done earlier before dispatching to them. A note on 4f0ed0e3ad5a: Requiring a client in the password grant broke use without registering a client, e.g. the Snikket Web Portal.
author Kim Alvefur <zash@zash.se>
date Sat, 31 May 2025 13:36:39 +0200
parents 7009e16192fa
children
line wrap: on
line source

local st = require "util.stanza";

local xmlns_starttls = 'urn:ietf:params:xml:ns:xmpp-tls';
local starttls_attr = { xmlns = xmlns_starttls };
local s2s_feature = st.stanza("starttls", starttls_attr);
local starttls_failure = st.stanza("failure", starttls_attr);

module:hook("stream-features", function(event)
	local features = event.features;
	features:add_child(s2s_feature);
end);

module:hook("s2s-stream-features", function(event)
	local features = event.features;
	features:add_child(s2s_feature);
end);

-- Hook <starttls/>
module:hook("stanza/urn:ietf:params:xml:ns:xmpp-tls:starttls", function(event)
	local origin = event.origin;
	(origin.sends2s or origin.send)(starttls_failure);
	origin:close();
	return true;
end);