view mod_authz_delegate/README.md @ 6497:3b0cfef7fabe

mod_report_affiliations: Don't report 0 trust when we just didn't calculate it Absent 'trust' means "I don't have it" or "I don't want to expose it" trust='0' means "I don't trust this account at all"
author Matthew Wild <mwild1@gmail.com>
date Wed, 25 Mar 2026 10:23:52 +0000
parents 6ebda1e5b4f3
children
line wrap: on
line source

---
summary: Authorization delegation
rockspec: {}
...

This module allows delegating authorization questions (role assignment and
role policies) to another host within prosody.

The primary use of this is for a group of virtual hosts to use a common
authorization database, for example to allow a MUC component to grant
administrative access to an admin on a corresponding user virtual host.

## Configuration

The following example will make all role assignments for local and remote JIDs
from domain.example effective on groups.domain.example:

```
VirtualHost "domain.example"

Component "groups.domain.example" "muc"
    authorization = "delegate"
    authz_delegate_to = "domain.example"
```

The setting `authz_delegate_to` defaults to the hostname with the
left-most subdomain removed, or the `parent_host` setting like
[mod_authz_internal][doc:modules:mod_authz_internal].