Software /
code /
prosody-modules
File
mod_measure_message_e2ee/README.markdown @ 5819:93d6e9026c1b
mod_http_oauth2: Do not enforce PKCE on Device and OOB flows
PKCE does not appear to be used with the Device flow. I have found no
mention of any interaction between those standards. Since no data is
delivered via redirects in these cases, PKCE may not serve any purpose.
This is mostly a problem because we reuse the authorization code to
implement the Device and OOB flows.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Fri, 15 Dec 2023 12:10:07 +0100 |
parent | 4029:b9bd56790286 |
line wrap: on
line source
--- labels: - Statistics summary: Collect statistics on message encryption --- Description =========== This module measures the rate at which text messages are exchanged, and their encryption status. ::: {.alert .alert-warning} This module can leak information about your users’ behaviour to anyone who can access these statistics, so avoid enabling it on a server with few users. :::