Software /
code /
prosody-modules
File
mod_nooffline_noerror/README.md @ 6193:e977174082ee
mod_invites_register_api: Use set_password() for password resets
Previously the code relied on the (weird) behaviour of create_user(), which
would update the password for a user account if it already existed. This has
several issues, and we plan to deprecate this behaviour of create_user().
The larger issue is that this route does not trigger the user-password-changed
event, which can be a security problem. For example, it did not disconnect
existing user sessions (this occurs in mod_c2s in response to the event).
Switching to set_password() is the right thing to do
author | Matthew Wild <mwild1@gmail.com> |
---|---|
date | Thu, 06 Feb 2025 10:24:30 +0000 |
parent | 6003:fe081789f7b5 |
line wrap: on
line source
--- labels: - 'Stage-Alpha' summary: Discard offline stanzas instead of generating stanza errors if mod_offline is not loaded ... Introduction ============ By default without mod_offline stanzas that would go to offline storage trigger error stanzas sent back to the sender to inform him of undeliverable stanzas. But if you use MAM on your server and are certain, all of your clients are using it, you can use this module to disable the error stanzas. If mod_offline is loaded, this module will do nothing. Warning ======= You most certainly *should not* use this module if you cannot be certain that *all* your clients support and use MAM! Compatibility ============= ----- ------------------------------------------------------------------- trunk Works 0.10 Works 0.9 Untested but should work ----- -------------------------------------------------------------------