Mercurial > prosody-modules
view mod_audit_register/mod_audit_register.lua @ 5390:f2363e6d9a64
mod_http_oauth2: Advertise the currently supported id_token signing algorithm
This field is REQUIRED. The algorithm RS256 MUST be included, but isn't
because we don't implement it, as that would require implementing a pile
of additional cryptography and JWT stuff. Instead the id_token is
signed using the client secret, which allows verification by the client,
since it's a shared secret per OpenID Connect Core 1.0 ยง 10.1 under
Symmetric Signatures.
OpenID Connect Discovery 1.0 has a lot of REQUIRED and MUST clauses that
are not supported here, but that's okay because this is served from the
RFC 8414 OAuth 2.0 Authorization Server Metadata .well-known endpoint!
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Sun, 30 Apr 2023 16:13:40 +0200 |
| parents | 08dea42a302a |
| children | dde83f6043e6 |
line wrap: on
line source
module:depends("audit"); -- luacheck: read globals module.audit local st = require "util.stanza"; module:hook("user-registered", function(event) local session = event.session; local custom = {}; local invite = event.validated_invite or (event.session and event.session.validated_invite); if invite then table.insert(custom, st.stanza( "invite-used", { xmlns = "xmpp:prosody.im/audit", token = invite.token, } )) end module:audit(event.username, "user-registered", { session = session, custom = custom, }); end);
