Software /
code /
prosody-modules
File
mod_devices/README.markdown @ 5512:1fbc8718bed6
mod_http_oauth2: Bind refresh tokens to client
Prevent one OAuth client from using the refresh tokens issued to another
client as required by RFC 6819 section 5.2.2.2
See also draft-ietf-oauth-security-topics-22 section 2.2.2
Thanks to OAuch for pointing out this issue
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Fri, 02 Jun 2023 10:40:48 +0200 |
parent | 3397:4cf65afd90f4 |
line wrap: on
line source
--- labels: - 'Stage-Alpha' summary: 'Device identification' ... Description ============ This is an experimental module that aims to identify the different devices (technically clients) that a user uses with their account. It is expected that at some point this will be backed by a nicer protocol, but it currently uses a variety of hacky methods to track devices between sessions. Usage ===== ``` {.lua} modules_enabled = { -- ... "devices", -- ... } ``` Configuration ============= Option summary -------------- option type default ------------------------------ ----------------------- ----------- max\_user\_devices number `5` Compatibility ============= ------- ----------------------- trunk Works 0.11 Works 0.10 Does not work ------- -----------------------