view mod_captcha_registration/install.lua @ 5682:527c747711f3

mod_http_oauth2: Limit revocation to clients own tokens in strict mode RFC 7009 section 2.1 states: > The authorization server first validates the client credentials (in > case of a confidential client) and then verifies whether the token was > issued to the client making the revocation request. If this > validation fails, the request is refused and the client is informed of > the error by the authorization server as described below. The first part was already covered (in strict mode). This adds the later part using the hash of client_id recorded in 0860497152af It still seems weird to me that revoking a leaked token should not be allowed whoever might have discovered it, as that seems the responsible thing to do.
author Kim Alvefur <zash@zash.se>
date Sun, 29 Oct 2023 11:30:49 +0100
parents 985bfc6e8cad
children
line wrap: on
line source

-- simple installer for mod_register with dependicies

files = {"util/dataforms.lua", "modules/mod_register.lua", "FiraSans-Regular.ttf"}

default_path = "/usr/lib/prosody"


function exists(name)
	if type(name) ~= "string" then return false end
	return os.rename(name, name) and true or false
end

function copy_file(name, target)
	local file = io.open(name)
	local data = file:read("*all")
	file:close()
	local file = io.open(target, "w")
	file:write(data)
	file:close()
end

function copy_files(path)
	for index = 1, #files do
		local filename = files[index]
		os.remove(default_path.."/"..filename)
		copy_file(filename, default_path.."/"..filename)
		print("copied: "..default_path.."/"..filename)
	end
end

if not exists(default_path) then
	io.write("\nEnter prosody path [/usr/lib/prosody]: ")
	path = io.read("*line")
end

copy_files(path or default_path)