-
Notifications
You must be signed in to change notification settings - Fork 404
Ignore received EDUs if origin server in room ACL #18475
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: develop
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| Make ACLs apply to EDUs per [MSC4163](https://github.com/matrix-org/matrix-spec-proposals/pull/4163). |
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -551,6 +551,53 @@ async def _process_edu(edu_dict: JsonDict) -> None: | |||||
| edu_type=edu_dict["edu_type"], | ||||||
| content=edu_dict["content"], | ||||||
| ) | ||||||
|
|
||||||
| # Server ACL's apply to `EduTypes.TYPING` per MSC4163: | ||||||
| # | ||||||
| # > For typing notifications (m.typing), the room_id field inside | ||||||
| # > content should be checked, with the typing notification ignored if | ||||||
| # > the origin of the request is a server which is forbidden by the | ||||||
| # > room's ACL. Ignoring the typing notification means that the EDU | ||||||
| # > MUST be dropped upon receipt. | ||||||
| if edu.edu_type == EduTypes.TYPING: | ||||||
| origin_host, _ = parse_server_name(origin) | ||||||
| room_id = edu.content["room_id"] | ||||||
| try: | ||||||
| await self.check_server_matches_acl(origin_host, room_id) | ||||||
| except AuthError: | ||||||
| logger.warning( | ||||||
| "Ignoring typing EDU for room %s from banned server", room_id | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
| ) | ||||||
| return | ||||||
|
|
||||||
| # Server ACL's apply to `EduTypes.RECEIPT` per MSC4163: | ||||||
| # | ||||||
| # > For read receipts (m.receipt), all receipts inside a room_id | ||||||
| # > inside content should be ignored if the origin of the request is | ||||||
| # > forbidden by the room's ACL. | ||||||
| if edu.edu_type == EduTypes.RECEIPT: | ||||||
| origin_host, _ = parse_server_name(origin) | ||||||
| to_remove = set() | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
| for room_id in edu.content.keys(): | ||||||
| try: | ||||||
| await self.check_server_matches_acl(origin_host, room_id) | ||||||
| except AuthError: | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Feels like we should also have a general Perhaps we should just nest everything under that single |
||||||
| to_remove.add(room_id) | ||||||
|
|
||||||
| if to_remove: | ||||||
| logger.warning( | ||||||
| "Ignoring receipts in EDU for rooms %s from banned server %s", | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
| to_remove, | ||||||
| origin_host, | ||||||
| ) | ||||||
|
|
||||||
| for room_id in to_remove: | ||||||
| edu.content.pop(room_id) | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Mutating the Maybe one day we can lint for this kind thing (python/mypy#11076) |
||||||
|
|
||||||
| if not edu.content: | ||||||
| # If we've removed all the rooms, we can just ignore the whole EDU | ||||||
| return | ||||||
|
|
||||||
| try: | ||||||
| await self.registry.on_edu(edu.edu_type, origin, edu.content) | ||||||
| except Exception: | ||||||
|
|
||||||
Uh oh!
There was an error while loading. Please reload this page.