aboutsummaryrefslogtreecommitdiffstats
path: root/plugins/mod_tokenauth.lua
diff options
context:
space:
mode:
authorMatthew Wild <mwild1@gmail.com>2023-03-25 19:38:41 +0000
committerMatthew Wild <mwild1@gmail.com>2023-03-25 19:38:41 +0000
commit6b2d191b939099b598e7edaf972994c94a24ff0e (patch)
tree5b79bd87f2885f301bde92d85928ee99ec9a8c02 /plugins/mod_tokenauth.lua
parente53ef27a1c6e620cc79bb8a4ef0a12dbe9cd0eb7 (diff)
downloadprosody-6b2d191b939099b598e7edaf972994c94a24ff0e.tar.gz
prosody-6b2d191b939099b598e7edaf972994c94a24ff0e.zip
moduleapi: may: Fail early if a local session has no role assigned
We expect every session to explicitly have a role assigned. Falling back to any kind of "default" role (even the user's default role) in the absence of an explicit role could open up the possibility of accidental privilege escalation.
Diffstat (limited to 'plugins/mod_tokenauth.lua')
0 files changed, 0 insertions, 0 deletions