Skip to content

Login with cookie #290

Description

@robotnic

My client uses xmpp and maybe will also use rest.

How to login?

For xmpp at the moment I need username and password.
To have passwords in cookies is not really state of the art.

After rest login I have a "credentials" cookie and I would like to use this cookie for xmpp login.
Does that kind of auth already exist?

It would be easy to send the sessionid as password.

The implementation should be easy using json_http
https://github.com/scastillo/prosody-mod_auth_json_http

socket.send(
'xmpp.login',
{
"jid": "test@evilprofessor.co.uk",
"password": "sessionid"
}
)

Any suggestions on that?

Activity

  1. imaginator commented on Jan 29, 2015

    @imaginator
    Member

    This is an interesting suggestion and something that I've been worried about for a while.

    Would you see it as:

    • login with username password
    • get back string
    • write string to cookie
    • use string to reauthenticate

    Would any of the oauth2 bits (https://developers.google.com/talk/jep_extensions/oauth) help us here?

  2. robotnic commented on Jan 29, 2015

    @robotnic
    Author

    That looks good.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions