mod_http_file_share: Switch to the new authz API (BC)

Behavior change: It becomes up to the authorization module whether to
allow requests. The default, mod_authz_internal, will allow users on the
*parent* host only, breaking use by some components.

Remaining question is whether to deprecate the `http_file_share_access`
setting or leave as a way to complement/bypass access control?
This commit is contained in:
Kim Alvefur 2023-09-16 14:23:08 +02:00
parent eeaa713fda
commit df4bde023b
2 changed files with 4 additions and 1 deletions

View file

@ -51,6 +51,7 @@ TRUNK
- mod_blocklist: New option 'migrate_legacy_blocking' to disable migration from mod_privacy
- Moved all modules into the Lua namespace `prosody.`
- Forwarded header from RFC 7239 supported, disabled by default
- mod_http_file_share now uses roles framework, affecting access from e.g. components
## Removed