File

mod_http_admin_api/README.md @ 6193:e977174082ee

mod_invites_register_api: Use set_password() for password resets Previously the code relied on the (weird) behaviour of create_user(), which would update the password for a user account if it already existed. This has several issues, and we plan to deprecate this behaviour of create_user(). The larger issue is that this route does not trigger the user-password-changed event, which can be a security problem. For example, it did not disconnect existing user sessions (this occurs in mod_c2s in response to the event). Switching to set_password() is the right thing to do
author Matthew Wild <mwild1@gmail.com>
date Thu, 06 Feb 2025 10:24:30 +0000
parent 6024:fc607d79765a
child 6211:750d64c47ec6
line wrap: on
line source

---
summary: "admin api from the snikket projects web portal"
labels:
- 'Stage-Beta'
rockspec:
  dependencies:
	- mod_cloud_notify
	- mod_lastlog2
	- mod_groups_internal
...

Introduction
============

...to be done...

Configuration
=============
There is no configuration for this module, just add it to
modules\_enabled as normal.

# Compatibility

Depends on community modules:

 * [mod_cloud_notify] 
 * [mod_lastlog2] 
 * [mod_groups_internal] 

  Prosody Version   Support Status
  ----------------  ----------------
  trunk[^1]         Works
  0.12              unknown
  ----------------  ----------------

[^1]: as of 2024-10-23