Annotate

mod_log_sasl_mech/mod_log_sasl_mech.lua @ 5549:01a0b67a9afd

mod_http_oauth2: Add TODO about disabling password grant Per recommendation in draft-ietf-oauth-security-topics-23 it should at the very least be disabled by default. However since this is used by the Snikket web portal some care needs to be taken not to break this, unless it's already broken by other changes to this module.
author Kim Alvefur <zash@zash.se>
date Fri, 16 Jun 2023 00:06:53 +0200
parent 1393:4baaa5a66a5a
child 5795:5ff8022466ab
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
1292
2d061333d0c2 mod_log_sasl_mech: Logs authentication mechanism used
Kim Alvefur <zash@zash.se>
parents:
diff changeset
1
2d061333d0c2 mod_log_sasl_mech: Logs authentication mechanism used
Kim Alvefur <zash@zash.se>
parents:
diff changeset
2 module:hook("authentication-success", function (event)
1393
4baaa5a66a5a mod_log_sasl_mech: Log SASL mechanism attached to session
Kim Alvefur <zash@zash.se>
parents: 1292
diff changeset
3 local session = event.session;
4baaa5a66a5a mod_log_sasl_mech: Log SASL mechanism attached to session
Kim Alvefur <zash@zash.se>
parents: 1292
diff changeset
4 local sasl_handler = session.sasl_handler;
4baaa5a66a5a mod_log_sasl_mech: Log SASL mechanism attached to session
Kim Alvefur <zash@zash.se>
parents: 1292
diff changeset
5 session.log("info", "Authenticated with %s", sasl_handler and sasl_handler.selected or "legacy auth");
1292
2d061333d0c2 mod_log_sasl_mech: Logs authentication mechanism used
Kim Alvefur <zash@zash.se>
parents:
diff changeset
6 end);