mod_xhtmlim/README.markdown
author Kim Alvefur <zash@zash.se>
Sun, 23 Jul 2023 02:56:08 +0200
changeset 5620 59d5fc50f602
parent 3703 1f68287138e3
permissions -rw-r--r--
mod_http_oauth2: Implement refresh token rotation Makes refresh tokens one-time-use, handing out a new refresh token with each access token. Thus if a refresh token is stolen and used by an attacker, the next time the legitimate client tries to use the previous refresh token, it will not work and the attack will be noticed. If the attacker does not use the refresh token, it becomes invalid after the legitimate client uses it. This behavior is recommended by draft-ietf-oauth-security-topics
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
2869
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
     1
Introduction
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
     2
============
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
     3
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
     4
This module attempts to sanitize XHTML-IM messages.
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
     5
3703
1f68287138e3 mod_xhtmlim: Default to stripping @style attribute by default
Kim Alvefur <zash@zash.se>
parents: 2869
diff changeset
     6
It does **not** attempt to sanitize any CSS embedded in `style`
1f68287138e3 mod_xhtmlim: Default to stripping @style attribute by default
Kim Alvefur <zash@zash.se>
parents: 2869
diff changeset
     7
attributes, these are instead stripped by default.
1f68287138e3 mod_xhtmlim: Default to stripping @style attribute by default
Kim Alvefur <zash@zash.se>
parents: 2869
diff changeset
     8
2869
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
     9
Configuration
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
    10
=============
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
    11
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
    12
  Option                   Type      Default
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
    13
  ------------------------ --------- ---------
3703
1f68287138e3 mod_xhtmlim: Default to stripping @style attribute by default
Kim Alvefur <zash@zash.se>
parents: 2869
diff changeset
    14
  `strip_xhtml_style`      boolean   `true`
2869
f6ed4421167d mod_xhtmlim: Attempts to sanitize XMTML-IM messages
Kim Alvefur <zash@zash.se>
parents:
diff changeset
    15
  `bounce_invalid_xhtml`   boolean   `false`