Software /
code /
prosody-modules
File
mod_invite/README.md @ 6191:94399ad6b5ab
mod_invites_register_api: Use set_password() for password resets
Previously the code relied on the (weird) behaviour of create_user(), which
would update the password for a user account if it already existed. This has
several issues, and we plan to deprecate this behaviour of create_user().
The larger issue is that this route does not trigger the user-password-changed
event, which can be a security problem. For example, it did not disconnect
existing user sessions (this occurs in mod_c2s in response to the event).
Switching to set_password() is the right thing to do.
author | Matthew Wild <mwild1@gmail.com> |
---|---|
date | Thu, 06 Feb 2025 10:13:39 +0000 (6 weeks ago) |
parent | 6003:fe081789f7b5 |
line wrap: on
line source
--- labels: - 'Stage-Deprecated' summary: 'Allows users to invite new users' ... **NOTE:** This module has been deprecated. Its functionality has been moved to other modules, see the mod_invites documentation for details. Introduction ============ This module allows users with an account to generate single-use invite URLs using an ad-hoc command. The invite URLs allow new users to create an account even if public registration is disabled. After the account is created, the inviter and the invitee are automatically added to the other's roster. The inviter of a user is stored, so can be used later (for example, for detecting spammers). This module depends on Prosody's internal webserver. Compatibility ============= ----- ------- 0.9 Works ----- -------