prose-im / prose-app-web

Prose Web application. XMPP client for team messaging.
https://prose.org/downloads
Mozilla Public License 2.0
20 stars 2 forks source link

Do not store account password in clear text #14

Open nesium opened 10 months ago

nesium commented 10 months ago

Related: https://github.com/prose-im/prose-core-client/issues/2

valeriansaliou commented 5 months ago

We should probably support https://xmpp.org/extensions/inbox/auth-tokens.html and avoid storing password altogether.

valeriansaliou commented 5 months ago

Some ideas: https://blog.prosody.im/modern-xmpp-auth/

mwild1 commented 4 months ago

An update to that Prosody post - the project was implemented, the announcement is here: https://blog.prosody.im/fast-auth/

I also gave a talk at FOSDEM that overlaps with the post: https://archive.fosdem.org/2023/schedule/event/modern_xmpp_auth/