Mercurial > prosody-modules
view mod_report_affiliations/traits.lib.lua @ 6165:e977174082ee
mod_invites_register_api: Use set_password() for password resets
Previously the code relied on the (weird) behaviour of create_user(), which
would update the password for a user account if it already existed. This has
several issues, and we plan to deprecate this behaviour of create_user().
The larger issue is that this route does not trigger the user-password-changed
event, which can be a security problem. For example, it did not disconnect
existing user sessions (this occurs in mod_c2s in response to the event).
Switching to set_password() is the right thing to do
| author | Matthew Wild <mwild1@gmail.com> |
|---|---|
| date | Thu, 06 Feb 2025 10:24:30 +0000 |
| parents | e905ef16efb7 |
| children |
line wrap: on
line source
local known_traits = {}; local function trait_added(event) local trait = event.item; local name = trait.name; if known_traits[name] then return; end known_traits[name] = trait.probabilities; end local function trait_removed(event) local trait = event.item; known_traits[trait.name] = nil; end module:handle_items("account-trait", trait_added, trait_removed); local function bayes_probability(prior, prob_given_true, prob_given_false) local numerator = prob_given_true * prior; local denominator = numerator + prob_given_false * (1 - prior); return numerator / denominator; end local function prob_is_bad(traits, prior) prior = prior or 0.50; for trait, state in pairs(traits) do local probabilities = known_traits[trait]; if probabilities then if state then prior = bayes_probability( prior, probabilities.prob_bad_true, probabilities.prob_bad_false ); else prior = bayes_probability( prior, 1 - probabilities.prob_bad_true, 1 - probabilities.prob_bad_false ); end end end return prior; end local function get_probability_bad(username, prior) local user_traits = {}; module:fire_event("get-account-traits", { username = username, host = module.host, traits = user_traits }); local result = prob_is_bad(user_traits, prior); return result; end return { get_probability_bad = get_probability_bad; };
