Software / code / prosody-modules
File
mod_auth_pam/mod_auth_pam.lua @ 6323:4f9b42c53d0f
mod_http_oauth2: Check grant type before issuing refresh token
This prevents even issuing a refresh token to a client that has not
registered the corresponding grant type.
The grant type dispatcher also checks before invoking the refresh token
grant type handler.
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Thu, 03 Jul 2025 15:34:42 +0200 |
| parent | 1538:57bb2497fadc |
line wrap: on
line source
-- PAM authentication for Prosody -- Copyright (C) 2013 Kim Alvefur -- -- Requires https://github.com/devurandom/lua-pam -- and LuaPosix local posix = require "posix"; local pam = require "pam"; local new_sasl = require "util.sasl".new; function user_exists(username) return not not posix.getpasswd(username); end function test_password(username, password) local h, err = pam.start("xmpp", username, { function (t) if #t == 1 and t[1][1] == pam.PROMPT_ECHO_OFF then return { { password, 0} }; end end }); if h and h:authenticate() and h:endx(pam.SUCCESS) then return user_exists(username), true; end return nil, true; end function get_sasl_handler() return new_sasl(module.host, { plain_test = function(sasl, ...) return test_password(...) end }); end module:provides"auth";