view mod_auth_http_async/README.md @ 6514:668b1f0a4dc6

mod_c2s_limit_sessions: Fix check when it's the first connection Creation of the sessions[username] entry happens after the "pre-resource-bind" event, before the "resource-bind" event. Thus, for a users first connection, it may not exist. This led to an 'attempt to index a nil value' error, fixed here.
author Kim Alvefur <zash@zash.se>
date Wed, 08 Apr 2026 15:56:38 +0200
parents 7b693a5539ad
children
line wrap: on
line source

---
labels:
- Stage-Alpha
...

Introduction
============

This is an authentication module that does an asynchronous
HTTP call to verify username and password.

Details
=======

When a user attempts to authenticate to Prosody, this module takes the
username and password and does a HTTP GET request with [Basic
authentication][rfc7617] to the configured `http_auth_url`.

Configuration
=============

After installing, enable the module by setting `authentication` to `"http_async"`.

The only setting is `http_auth_url` which should contain the URL endpoint where the authentication query is sent to. It can contain `$host` and
`$user` which are substituted for the current VirtualHost and the authenticating username, respectively.

``` lua
VirtualHost "example.com"
authentication = "http_async"
http_auth_url = "http://example.com/auth"
```

Compatibility
=============

Should work with Prosody 0.10.x and later.