Software /
code /
prosody-modules
File
mod_sasl2_sm/README.md @ 5624:d8622797e315
mod_http_oauth2: Shorten default token validity periods
With refresh tokens, short lifetime for access tokens is not a problem.
The arbitrary choice of one hour seems reasonable. RFC 6749 has it as
example value.
One week for refresh tokens matching the default archive retention
period. This means that a client that remains unused for one week will
have to sign in again. An actively used client will continually push
that forward with each used refresh token.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Mon, 24 Jul 2023 01:30:14 +0200 |
parent | 5094:c92c87daa09e |
line wrap: on
line source
--- labels: - Stage-Beta summary: "XEP-0198 integration with SASL2" rockspec: dependencies: - mod_sasl2 --- Add support for inlining stream management negotiation into the SASL2 process. **Note: At the time of writing (November 2022), this module implements a version of XEP-0198 that is still working its way through the XSF standards process. For more information and current status, see [PR #1215](https://github.com/xsf/xeps/pull/1215).** This module depends on [mod_sasl2] and [mod_sasl2_bind2]. It exposes no configuration options.