We do it this way round so that only the "owner" can delete the access token (i.e. `/logout/all` by the "owner" also deletes that token, but `/logout/all` by the "target user" doesn't).
A future PR will add an API for creating such a token.
When the target user and authenticated entity are different the `Processed request` log line will be logged with a: `{@admin:server as @bob:server} ...`. I'm not convinced by that format (especially since it adds spaces in there, making it harder to use `cut -d ' '` to chop off the start of log lines). Suggestions welcome.
|
||
|---|---|---|
| .. | ||
| __init__.py | ||
| auth.py | ||
| auth_blocking.py | ||
| constants.py | ||
| errors.py | ||
| filtering.py | ||
| presence.py | ||
| ratelimiting.py | ||
| room_versions.py | ||
| urls.py | ||