Software /
code /
prosody-modules
File
mod_sasl2_fast/README.md @ 5824:73887dcb2129
mod_pubsub_serverinfo: New module that uses pub/sub to make accessible server info
This first implemetnation is laughably simple: it only adds a disco#info
feature. This flags 'opt-in' for inclusion of local domain names in the
data exposed by other domains (per the domain), which will allow servers to
be listed in the XMPP Network Graph at https://xmppnetwork.goodbytes.im
Hopefully, this bare-boned implementation acts as a stepping stone for
future improvements.
author | Guus der Kinderen <guus.der.kinderen@gmail.com> |
---|---|
date | Thu, 28 Dec 2023 11:02:35 +0100 |
parent | 5095:745c7f4cca40 |
child | 5901:70fa3f8de249 |
line wrap: on
line source
--- labels: - Stage-Beta summary: "Fast Authentication Streamlining Tokens" rockspec: dependencies: - mod_sasl2 --- This module implements a mechanism via which clients can exchange a password for a secure token, improving security and streamlining future reconnections. At the time of writing, the XEP that describes the FAST protocol is still working its way through the XSF standards process. You can [view the FAST XEP proposal here](https://xmpp.org/extensions/inbox/xep-fast.html). This module depends on [mod_sasl2]. ## Configuration | Name | Description | Default | |---------------------------|--------------------------------------------------------|-----------------------| | sasl2_fast_token_ttl | Default token expiry (seconds) | `86400*21` (21 days) | | sasl2_fast_token_min_ttl | Time before tokens are eligible for rotation (seconds) | `86400` (1 day) | The `sasl2_fast_token_ttl` option determines the length of time a client can remain disconnected before being "logged out" and needing to authenticate with a password. Clients must perform at least one FAST authentication within this period to remain active. The `sasl2_fast_token_min_ttl` option defines how long before a token will be rotated by the server. By default a token is rotated if it is older than 24 hours. This value should be less than `sasl2_fast_token_ttl` to prevent clients being logged out unexpectedly.