Software /
code /
prosody-modules
File
mod_compact_resource/mod_compact_resource.lua @ 5559:d7fb8b266663
mod_http_oauth2: Strip unknown client metadata
Per RFC 7591
> The authorization server MUST ignore any client metadata sent by the
> client that it does not understand (for instance, by silently removing
> unknown metadata from the client's registration record during
> processing).
This was previously done but unintentionally removed in 90449babaa48
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Tue, 20 Jun 2023 01:11:34 +0200 |
parent | 1761:6f34e51a23f0 |
line wrap: on
line source
local base64_encode = require"util.encodings".base64.encode; local random_bytes = require"util.random".bytes; local b64url = { ["+"] = "-", ["/"] = "_", ["="] = "" }; local function random_resource() return base64_encode(random_bytes(8)):gsub("[+/=]", b64url); end module:hook("pre-resource-bind", function (event) event.resource = random_resource(); end);