Mercurial > prosody-modules
view mod_s2s_auth_compat/mod_s2s_auth_compat.lua @ 5458:813fe4f76286
mod_http_oauth2: Do minimal validation of private-use URI schemes
Per draft-ietf-oauth-v2-1-08#section-2.3.1
> At a minimum, any private-use URI scheme that doesn't contain a period
> character (.) SHOULD be rejected.
Since this would rule out the OOB URI, which is useful for CLI tools and
such without a built-in http server, it is explicitly allowed.
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Tue, 16 May 2023 22:18:12 +0200 |
| parents | 21e81fcb8896 |
| children |
line wrap: on
line source
-- COMPAT for Openfire sending stream headers without to or from. module:set_global(); module:hook("s2s-check-certificate", function(event) local session, host = event.session, event.host; if not event.host then (session.log or module._log)("warn", "Invalid stream header, certificate will not be trusted") session.cert_chain_status = "invalid" return true end end, 100);
