File

mod_s2s_auth_monkeysphere/README.md @ 6191:94399ad6b5ab

mod_invites_register_api: Use set_password() for password resets Previously the code relied on the (weird) behaviour of create_user(), which would update the password for a user account if it already existed. This has several issues, and we plan to deprecate this behaviour of create_user(). The larger issue is that this route does not trigger the user-password-changed event, which can be a security problem. For example, it did not disconnect existing user sessions (this occurs in mod_c2s in response to the event). Switching to set_password() is the right thing to do.
author Matthew Wild <mwild1@gmail.com>
date Thu, 06 Feb 2025 10:13:39 +0000
parent 6003:fe081789f7b5
line wrap: on
line source

---
labels:
- 'Stage-Alpha'
- 'Type-S2SAuth'
summary: Monkeysphere certificate checking for s2s
---

## Introduction

[Monkeysphere](http://web.monkeysphere.info/) is a project aiming to
introduce PGP's web of trust to protocols such as SSH and TLS (which
XMPP uses).

## Details

This module is currently just a prototype, it has numerous issues and is
**not** suitable for production use.

## Compatibility

  ------- -----------------------------
  trunk   Works (not tested recently)
  0.11    Works (not tested)
  0.10    Does not work
  0.9     Does not work
  ------- -----------------------------