Commit Graph
1504 Commits
Author SHA1 Message Date
Erwan Leboucher 82149397b0 fix(admin): Complete MSC4323 suspend and lock endpoints 2026-08-20 00:58:30 +00:00
timedout f1a77e0404 fix: Address review comments 2026-08-20 00:57:11 +00:00
timedout 785db0bdba chore: Move health tracking to federation service
Otherwise federation would have to depend on sender
2026-08-20 00:57:11 +00:00
timedout 077338792f feat: Mark servers as healthy when they successfully make an inbound request 2026-08-20 00:57:11 +00:00
Erwan Leboucher 1cdf369a80 fix(sync): Populate sliding sync num_live 2026-08-18 15:44:52 +00:00
timedout 2dc6051d67 fix(federation): Make transactions infallible
Previously, a transaction panicking in the handle() call would cause the
transaction to be indefinitely logged as "running" in the transaction
handler. This means subsequent transactions from the sending server
would be met with the "You're still sending me a txn!" 429 response,
forever, effectively causing defederation between the two servers, until
continuwuity is fully restarted.

I could just fix the known panics in the handle function and internal
calls, however there's so many subsystems that could reasonably panic
that it is just better to have a safer approach and ensure that the
handle call is infallible.
2026-08-15 16:10:39 +00:00
timedout 08d3d8445f chore: Merge branch 'nex/feat/registration-messages' 2026-08-12 14:25:15 +01:00
Ginger ad182417da fix: SEC26
Reviewed-By: timedout <git@nexy7574.co.uk>
Reviewed-By: Ginger <ginger@gingershaped.computer>
2026-08-11 17:56:29 -04:00
Erwan Leboucher 2998dc9b40 fix(sync): Deliver left rooms missing from timeline index 2026-08-11 14:10:23 +00:00
Erwan Leboucher 18139ea891 feat(sync): Add MSC4508 typing extension 2026-08-08 14:07:08 +00:00
Erwan Leboucher aa884fad6b feat(sync): Add MSC4480 sticky events 2026-08-03 14:35:53 +00:00
Erwan Leboucher 43197f695c feat(sync): Add MSC4354 sticky events 2026-08-02 17:28:00 +00:00
Erwan Leboucher 7789399ba5 fix(sync): Apply MSC4186 room filters 2026-08-02 18:33:57 +02:00
Erwan Leboucher 27a559a751 fix(sync): Wake sync loops on typing updates 2026-08-02 18:05:27 +02:00
Erwan Leboucher 74591d24e5 fix(sync): Avoid missed long-poll wake-ups 2026-08-02 15:22:18 +00:00
timedoutandErwan Leboucher 71016a0d7f fix: SEC20
Reviewed-By: Ginger <ginger@gingershaped.computer>
Co-Authored-By: Erwan Leboucher <erwanleboucher@gmail.com>
2026-07-29 16:41:59 +01:00
Ginger 4e001abe92 feat: Add stable mutual rooms endpoint 2026-07-27 19:28:15 +00:00
timedout 399005abc6 chore: Move registration notice logic 2026-07-27 16:46:36 +01:00
timedout 7fdc7f9216 fix: Ensure client IP is logged in all registration alert paths 2026-07-27 15:20:07 +00:00
timedout 795cdd3740 fix: Re-introduce registration alerts 2026-07-27 15:20:07 +00:00
timedout 0c96170063 fix: Ensure client IP is logged in all registration alert paths 2026-07-27 16:07:32 +01:00
timedout 9a80f1c2a1 fix: Re-introduce registration alerts 2026-07-27 15:33:38 +01:00
Ginger 9a3496ae70 feat: Add admin command to issue access tokens 2026-07-27 14:21:38 +00:00
Erwan Leboucher a0fa4cf0fe fix: Deliver simplified sliding sync account data without hanging 2026-07-26 14:17:21 +00:00
timedout a7892b296f chore: Resolve clippy lints post-rebase 2026-07-26 15:09:52 +01:00
new-years-eve 7f8c2aedc8 refactor: Use a shared helper function for submitting state events at room creation
On room creation, A list of initial state events may be provided that
should be submitted to the room after creation. These events
should be treated as any other state event and submitted to
the same checks.

With this change, state events submitted on room creation will be
submitted through the same helper as those through the usual endpoint.

The submission helper is moved to the timeline service to make it
available everywhere. This will be useful for implementing MSC4140
(issue #903).
2026-07-26 15:06:38 +01:00
Ginger 7cc5e44093 fix: Exclude deactivated users and AS puppets from user count 2026-07-25 14:16:34 +00:00
reaster a838d59cfc make clippy happy again 2026-07-25 13:55:30 +00:00
reaster fb7a378d63 deduplicate rooms in hierarchy traversal 2026-07-25 13:55:30 +00:00
Erwan Leboucher b144b18aef fix(sync): Verify state for newly-left rooms is in incremental sync 2026-07-21 18:32:34 +00:00
Omar Pakker b9c6d5956f feat: Introduce accepted_ip_sources as a multiple options variant of request_ip_source
The current `request_ip_source` setting only allows a single option.
While it does fall back to the peer IP if the header is missing as of !2003,
which likely covers a lot of regular use, only allowing a single option limits
the deployment options available to more advanced deployments.
Setups where internal and external traffic use different reverse proxies will
end up with the wrong IP and the implicitness of the fallback allows for
situations where the used IP is not the IP expected.

By introducing a setting that allows multiple options to be set,
this limitation is resolved and it becomes possible to have client IP resolution
behind different reverse proxies and also making it possible to decide if and/or
what the fallback should be.

If set, options are evaluated in order. If all fail, the request fails.
2026-07-21 14:35:55 +00:00
Logan Devine 480e975877 chore: clean up unused imports of ClientIp 2026-07-21 14:31:16 +00:00
Ginger 4c9426a13f feat: Add support for OAuth2 device auth flow 2026-07-21 13:42:50 +00:00
Deniel9204 25264308ab fix: Use the requested device ID when an appservice creates a device
The appservice branch of update_device_route (MSC4190 device creation)
generated a random device ID instead of using the one from the request
path, and dropped the requested display name. The PUT returned 200, but
the device the appservice asked for never existed, so every subsequent
request masquerading as that device failed with M_FORBIDDEN and one
orphaned random-ID device was left behind per attempt.

This made encrypted mautrix (bridgev2) bridges unable to start on
OIDC-enabled servers, where MSC4190 is the only available device
creation mechanism: /keys/upload failed on first start and /keys/query
on every restart. Combined with the pre-1f5e178c3f behaviour (400
"Token conflicts with an existing appservice token"), MSC4190 device
creation has never worked end-to-end in any release.

Create the device under the requested ID and forward the requested
display name.
2026-07-21 08:21:09 +02:00
timedout 789589ef37 chore: Remove redundant client IP extractions on individual routes 2026-07-17 12:57:48 +00:00
Ginger 3e55d08488 fix: Only return create prompt if registration is enabled 2026-07-17 12:49:15 +00:00
Erwan Leboucher 3a74ce6151 fix(client-ip): Fall back to peer IP instead of returning 500 2026-07-17 12:46:11 +00:00
Erwan Leboucher eff454218c fix(sync): Send full state for newly-joined rooms in incremental sync 2026-07-17 02:48:28 +00:00
Erwan Leboucher 8945cc9e10 fix(federation): Sign restricted join events before verification 2026-07-16 19:46:42 +00:00
N00byKing 232ec3f620 fix: Return 201 instead of 200 on oauth registration
See RFC 7591 at 3.2.1: "The server responds with an HTTP 201 Created status code [...]"

Fixes a failure in matrix-dart-sdk
2026-07-14 11:00:34 +02:00
Ginger 24c6474bd1 fix: Allow unstable and stable device id query together 2026-07-13 20:38:10 +00:00
Ginger 1f5e178c3f fix: Properly handle appservice device creation 2026-07-13 08:50:48 -04:00
timedout 4001b99261 style: Make send_join's docstring more useful 2026-07-12 02:11:50 +00:00
timedout fbf81fcdeb fix: Opportunistically re-use room format rules when parsing incoming PDUs 2026-07-12 02:11:50 +00:00
timedout 87030a3a22 fix: Ensure PDU returned by create_hash_and_sign_event is itself signed 2026-07-12 02:11:50 +00:00
timedout 4f509fa113 fix: Convert room summary to federation format when sending invites 2026-07-12 02:11:50 +00:00
timedout aa7ed885c0 fix: Check correct field name when determining event type 2026-07-12 02:11:50 +00:00
timedout d5e6e617d1 fix: Remove redundant banned room server checks
These don't make sense here anyway
2026-07-12 02:11:50 +00:00
timedout 1f7680ad5f feat: Give send_join the invite treatment 2026-07-12 02:11:50 +00:00
timedout 0c37a542d4 feat: Give send_leave the invite treatment 2026-07-12 02:11:50 +00:00