File

mod_fallback_vcard/mod_fallback_vcard.lua @ 5390:f2363e6d9a64

mod_http_oauth2: Advertise the currently supported id_token signing algorithm This field is REQUIRED. The algorithm RS256 MUST be included, but isn't because we don't implement it, as that would require implementing a pile of additional cryptography and JWT stuff. Instead the id_token is signed using the client secret, which allows verification by the client, since it's a shared secret per OpenID Connect Core 1.0 § 10.1 under Symmetric Signatures. OpenID Connect Discovery 1.0 has a lot of REQUIRED and MUST clauses that are not supported here, but that's okay because this is served from the RFC 8414 OAuth 2.0 Authorization Server Metadata .well-known endpoint!
author Kim Alvefur <zash@zash.se>
date Sun, 30 Apr 2023 16:13:40 +0200
parent 1899:ceb594a14a18
line wrap: on
line source

local datamanager = require "util.datamanager";
local usermanager = require "core.usermanager";
local st = require "util.stanza";
local host = module.host;
local jid_split = require "util.jid".split;

local orgname = module:get_option_string("default_vcard_orgname");
local orgmail = module:get_option_boolean("default_vcard_orgmail");

module:hook("iq/bare/vcard-temp:vCard", function(event)
	local session, stanza = event.origin, event.stanza;
	local to = stanza.attr.to;
	local username = jid_split(to);
	if not username then return end

	local vcard = datamanager.load(username, host, "vcard");
	local data = datamanager.load(username, host, "account_details");
	local exists = usermanager.user_exists(username, host);
	module:log("debug", "has %s: %s", "vcard", tostring(vcard));
	module:log("debug", "has %s: %s", "data", tostring(data));
	module:log("debug", "has %s: %s", "exists", tostring(exists));
	data = data or {};

	if not(vcard) and data and exists then
		-- MAYBE
		-- first .. " " .. last
		-- first, last = name:match("^(%w+) (%w+)$")
		local vcard = st.reply(stanza):tag("vCard", { xmlns = "vcard-temp" })
			:tag("VERSION"):text("3.0"):up()
			:tag("N")
				:tag("FAMILY"):text(data.last or ""):up()
				:tag("GIVEN"):text(data.first or ""):up()
			:up()
			:tag("FN"):text(data.name or ""):up()
			:tag("NICKNAME"):text(data.nick or username):up()
			:tag("JABBERID"):text(username.."@"..host):up();
		if orgmail then
			vcard:tag("EMAIL"):tag("USERID"):text(username.."@"..host):up():up();
		elseif data.email then
			vcard:tag("EMAIL"):tag("USERID"):text(data.email):up():up();
		end
		if orgname then
			vcard:tag("ORG"):tag("ORGNAME"):text(orgname):up():up();
		end
		session.send(vcard);
		return true;
	end
end, 1);