mod_http_oauth2: Strip unknown client metadata
Per RFC 7591
> The authorization server MUST ignore any client metadata sent by the
> client that it does not understand (for instance, by silently removing
> unknown metadata from the client's registration record during
> processing).
This was previously done but unintentionally removed in 90449babaa48
---
labels:
- 'Stage-Alpha'
summary: 'Require MUC occupant nicknames to no match some patterns'
---
Introduction
============
This checks the nickname of a joining user against a configurable list of
[Lua patterns](https://www.lua.org/manual/5.2/manual.html#6.4.1), and prevents
them from joining if it matches any of them.
Configuration
=============
There is a single configuration option, `muc_reserve_nick_patterns` and the
default is `{}` - i.e. allow everything.
Compatibility
=============
Requires Prosody 0.11 or higher.