Software /
code /
prosody-modules
File
mod_mamsub/mod_mamsub.lua @ 5705:527c747711f3
mod_http_oauth2: Limit revocation to clients own tokens in strict mode
RFC 7009 section 2.1 states:
> The authorization server first validates the client credentials (in
> case of a confidential client) and then verifies whether the token was
> issued to the client making the revocation request. If this
> validation fails, the request is refused and the client is informed of
> the error by the authorization server as described below.
The first part was already covered (in strict mode). This adds the later
part using the hash of client_id recorded in 0860497152af
It still seems weird to me that revoking a leaked token should not be
allowed whoever might have discovered it, as that seems the responsible
thing to do.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 29 Oct 2023 11:30:49 +0100 |
parent | 1748:0697fbef9134 |
line wrap: on
line source
-- MAM Subscriptions prototype -- Copyright (C) 2015 Kim Alvefur -- -- This file is MIT/X11 licensed. local mt = require"util.multitable"; local st = require"util.stanza"; local xmlns_mamsub = "http://prosody.im/protocol/mamsub"; module:add_feature(xmlns_mamsub); local host_sessions = prosody.hosts[module.host].sessions; local weak = { __mode = "k" }; module:hook("iq-set/self/"..xmlns_mamsub..":subscribe", function (event) local origin, stanza = event.origin, event.stanza; if origin.mamsub ~= nil then origin.send(st.error_reply(stanza, "modify", "conflict")); return true; end origin.mamsub = xmlns_mamsub; local mamsub_sessions = host_sessions[origin.username].mamsub_sessions; if not mamsub_sessions then mamsub_sessions = setmetatable({}, weak); host_sessions[origin.username].mamsub_sessions = mamsub_sessions; end mamsub_sessions[origin] = true; origin.send(st.reply(stanza)); return true; end); module:hook("iq-set/self/"..xmlns_mamsub..":unsubscribe", function (event) local origin, stanza = event.origin, event.stanza; if origin.mamsub ~= xmlns_mamsub then origin.send(st.error_reply(stanza, "modify", "conflict")); return true; end origin.mamsub = nil; local mamsub_sessions = host_sessions[origin.username].mamsub_sessions; if mamsub_sessions then mamsub_sessions[origin] = nil; end origin.send(st.reply(stanza)); return true; end); module:hook("archive-message-added", function (event) local user_session = host_sessions[event.for_user]; local mamsub_sessions = user_session and user_session.mamsub_sessions; if not mamsub_sessions then return end; local for_broadcast = st.message():tag("mamsub", { xmlns = xmlns_mamsub }) :tag("forwarded", { xmlns = "urn:xmpp:forward:0" }) :add_child(event.stanza); for session in pairs(mamsub_sessions) do if session.mamsub == xmlns_mamsub then for_broadcast.attr.to = session.full_jid; session.send(for_broadcast); end end end);