File

mod_auto_moved/README.markdown @ 5623:59d5fc50f602

mod_http_oauth2: Implement refresh token rotation Makes refresh tokens one-time-use, handing out a new refresh token with each access token. Thus if a refresh token is stolen and used by an attacker, the next time the legitimate client tries to use the previous refresh token, it will not work and the attack will be noticed. If the attacker does not use the refresh token, it becomes invalid after the legitimate client uses it. This behavior is recommended by draft-ietf-oauth-security-topics
author Kim Alvefur <zash@zash.se>
date Sun, 23 Jul 2023 02:56:08 +0200
parent 4680:59fdda04b87e
line wrap: on
line source

---
summary: "XEP-0283: Moved"
labels:
- 'Stage-Alpha'
...

Introduction
============

This module implements [XEP-0283: Moved](http://xmpp.org/extensions/xep-0283.html),
a way for contacts to notify you that they have moved to a new address.

This module is not necessary to generate such notifications - that can be done
by clients, for example. What this module does is automatically verify such
notifications and, if verification is successful, automatically update your
roster (contact list).

Configuration
=============

There is no configuration for this module, just add it to
modules\_enabled as normal.

Compatibility
=============

  ----- -------
  0.11  Does not work
  ----- -------
  trunk Works
  ----- -------