Mercurial > prosody-modules
view mod_compat_dialback/mod_compat_dialback.lua @ 5796:93d6e9026c1b
mod_http_oauth2: Do not enforce PKCE on Device and OOB flows
PKCE does not appear to be used with the Device flow. I have found no
mention of any interaction between those standards. Since no data is
delivered via redirects in these cases, PKCE may not serve any purpose.
This is mostly a problem because we reuse the authorization code to
implement the Device and OOB flows.
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Fri, 15 Dec 2023 12:10:07 +0100 |
| parents | 56f6a642fc67 |
| children |
line wrap: on
line source
-- Prosody IM -- Copyright (C) 2008-2010 Matthew Wild -- Copyright (C) 2008-2010 Waqas Hussain -- -- This project is MIT/X11 licensed. Please see the -- COPYING file in the source package for more information. -- module:set_global(); module:hook("s2s-stream-features-legacy", function (data) if data.origin.type == "s2sin_unauthed" then data.features:tag("dialback", { xmlns='urn:xmpp:features:dialback' }):up(); end end);
