echo/modules/protocol
Jean f2fd80694d
All checks were successful
CI / check (push) Successful in 3m52s
Redeem website login keycards over SASL
A member already authenticated on tchatou.fr connects with a single-use kc_…
keycard instead of their password (the m_apiauth module that used to validate it
was retired in the Anope->echo cutover, so these logins had started failing as
"wrong password"). The SASL PLAIN handler now recognises a kc_-prefixed
credential and emits NetAction::DeferKeycard; the link layer redeems it off the
engine lock — a localhost round-trip to Django's login-token endpoint via
keycard::redeem — and completes the login exactly like a password auth. Config:
[keycard] url + api_key; absent, kc_ credentials are simply not honoured.
2026-07-16 22:27:59 +00:00
..
inspircd Redeem website login keycards over SASL 2026-07-16 22:27:59 +00:00