Commit Graph
7578 Commits
Author SHA1 Message Date
timedout 88d5446987 feat(meta): Add issue template 2026-08-19 19:07:11 +01:00
Erwan Leboucher 1ecfb21aea fix(spaces): Correct hierarchy traversal 2026-08-19 03:33:41 +00:00
Erwan Leboucher 39b08f73f7 fix(state-res): Derive sender power from the create event when sorting 2026-08-18 20:22:38 +00:00
Erwan Leboucher 3efb66c76c fix: Do not make late-arriving events forward extremities 2026-08-18 16:55:47 +00:00
timedout 7b3e3a26bb fix: Don't panic when receiving PDUs with illegal auth events
Apparently some servers do this??
2026-08-18 17:50:18 +01:00
Erwan Leboucher 1cdf369a80 fix(sync): Populate sliding sync num_live 2026-08-18 15:44:52 +00:00
Erwan Leboucher 1d655fda53 fix(timeline): Keep extremities a local event did not reference 2026-08-18 15:38:43 +00:00
stratself a1c51adb04 fix(docs): Correct docker network name in caddy labels compose 2026-08-18 09:06:28 +00:00
Renovate Bot 3f250032f0 chore(deps): update https://github.com/taiki-e/install-action digest to b6b84cf 2026-08-18 05:02:53 +00:00
ginger b502f74c34 fix: Remove mystery additional admin room notice 2026-08-17 17:55:59 +00:00
Jade Ellis e1d7974dbb chore: Delete archived element web deployment 2026-08-16 19:11:51 +00:00
stratself 2a714d3e37 docs: Add quick redirs to /dns, /livekit and /source(_code) 2026-08-16 12:45:02 +00:00
timedout a148174c59 style: Rephrase error message 2026-08-15 16:10:39 +00:00
timedout 75e857dffe chore: Add newsfrag 2026-08-15 16:10:39 +00:00
timedout 2dc6051d67 fix(federation): Make transactions infallible
Previously, a transaction panicking in the handle() call would cause the
transaction to be indefinitely logged as "running" in the transaction
handler. This means subsequent transactions from the sending server
would be met with the "You're still sending me a txn!" 429 response,
forever, effectively causing defederation between the two servers, until
continuwuity is fully restarted.

I could just fix the known panics in the handle function and internal
calls, however there's so many subsystems that could reasonably panic
that it is just better to have a safer approach and ensure that the
handle call is infallible.
2026-08-15 16:10:39 +00:00
stratself 3c07f46451 docs(livekit): Link file for nginx conf and do UI codeblock folding 2026-08-15 15:08:18 +00:00
stratself 65b32b8610 docs(turn): Coturn --> coturn 2026-08-15 15:08:18 +00:00
stratself 200a75dfb0 docs(livekit): Fix wordings according to PR comments
- Use proper capitalization to match software brandings
- websocket -> WebSocket
- resolve other wording issues
2026-08-15 15:08:18 +00:00
stratself aa417aa0f8 chore: Add changelog for Livekit Docker loopback changes 2026-08-15 15:08:18 +00:00
stratself 68f4b71cb2 docs(livekit): Use "official" Docker method of host loopbacking
As lk-jwt-service is hosted in a bridge network, the previous
`extra_hosts` using 127.0.0.1 would just loop back to the container
itself. Using `network_mode: host` is unnecessary, and the
`host-gateway` approach works well for both Podman and Docker

Host loopback issues are prevalent in non-Livekit scenarios too: push
gateways is another example. Considering moving these to a dedicated
Docker section of the troubleshooting page.
2026-08-15 15:08:18 +00:00
stratself 0471f8c24c docs(livekit): Use tabs and move caddy label compose to own file 2026-08-15 15:08:18 +00:00
stratself 19662f389b docs(livekit,turn): Standardize wording of TURN-over-TLS (on 443) 2026-08-15 15:08:18 +00:00
stratself 4d44f74235 fix: Trailing whitespaces 2026-08-15 15:08:18 +00:00
stratself 7a4b1bf407 fix(docs): Use official "Caddy-L4" name 2026-08-15 15:08:18 +00:00
stratself 7494d32f35 fix(docs): Address wording suggestions on PR comments 2026-08-15 15:08:18 +00:00
stratself 48d2c373e7 docs(livekit,turn): Various sweepfixes from #1740 comments 2026-08-15 15:08:18 +00:00
Erwan Leboucher 918070c512 fix(spaces): Expose restricted children over federation 2026-08-14 12:51:09 +02:00
timedout 5c59acc380 feat(meta): Publish linkification script 2026-08-14 00:38:44 +01:00
timedout df26ab4cda style: Re-run linkifier on changelog 2026-08-14 00:22:27 +01:00
timedout cefb2edb55 chore: Release v26.8.0-alpha.1 v26.8.0-alpha.1 2026-08-14 00:12:40 +01:00
timedout 08d3d8445f chore: Merge branch 'nex/feat/registration-messages' 2026-08-12 14:25:15 +01:00
nex b4a8d2095e chore: Update admin announcement 2026-08-12 00:24:39 +00:00
Ginger ad182417da fix: SEC26
Reviewed-By: timedout <git@nexy7574.co.uk>
Reviewed-By: Ginger <ginger@gingershaped.computer>
2026-08-11 17:56:29 -04:00
Ginger 7377074f6d fix: SEC28 2026-08-11 17:56:29 -04:00
Ginger 973aeed0a2 chore: Release 2026-08-11 17:56:29 -04:00
Ginger e4d35e7121 chore: Update changelog 2026-08-11 17:56:29 -04:00
Erwan Leboucher 7472faa096 fix(sync): Remove sync wake before membership commit point 2026-08-11 14:10:23 +00:00
Erwan Leboucher 2998dc9b40 fix(sync): Deliver left rooms missing from timeline index 2026-08-11 14:10:23 +00:00
Renovate Bot e335cde0dd chore(deps): update github-actions-digest 2026-08-11 05:01:27 +00:00
Erwan Leboucher 18139ea891 feat(sync): Add MSC4508 typing extension 2026-08-08 14:07:08 +00:00
Renovate Bot 9080494464 chore(deps): update rust crate validator to 0.21.0 2026-08-08 12:25:34 +00:00
Renovate Bot e13c6990d2 chore(deps): update node-patch-updates to v2.0.19 2026-08-08 12:24:11 +00:00
Renovate Bot 26d5c03a0d chore(deps): update rust-non-major 2026-08-08 12:23:54 +00:00
stratself 9c8c38496d chore: Add changelog because it seems important 2026-08-08 05:44:06 +00:00
stratself 534ff1fe07 fix(docs): Use canonical Caddyfile location 2026-08-08 05:35:35 +00:00
Michel-Marie MAUDET f0493a7ba8 fix(oauth): Use unauthorized_client for unregistered grant types
The token endpoint already refused grant types the client had not
registered, but reported it as `invalid_grant`. RFC 6749 section 5.2
reserves `invalid_grant` for an authorization grant which is "invalid,
expired, revoked, does not match the redirection URI used in the
authorization request, or was issued to another client", and defines
`unauthorized_client` for a client which "is not authorized to use this
authorization grant type".

Report the condition with the error code the specification assigns to it,
matching the device authorization endpoint.
2026-08-07 08:52:20 +00:00
Michel-Marie MAUDET 8c1bbf3d1a fix(oauth): Reject device code requests from unauthorised clients
The device authorization endpoint issued a device code to any registered
client, without checking that the client had registered the
`urn:ietf:params:oauth:grant-type:device_code` grant type. Such a client
could therefore start a device authorization flow and have the server
show an approval prompt to a user, even though the subsequent token
request was always going to be refused.

RFC 8628 section 3.2 states that, in the event of an error such as an
invalidly configured client, the device authorization endpoint responds
in the same way as the token endpoint specified in RFC 6749 section 5.2,
which defines `unauthorized_client` as "the authenticated client is not
authorized to use this authorization grant type".

Apply the same grant type check the token endpoint already performs, and
add the `unauthorized_client` error code it requires.
2026-08-07 08:52:20 +00:00
renegadespork 02bee2e898 docs: Reference latest version of matrix spec 2026-08-06 15:34:46 -07:00
renegadespork 1c23cf3a93 docs: Fix servernameevent_data_cache_capacity default description. 2026-08-06 14:18:32 +00:00
renegadespork 30be07fe8f chore: Fix changelog news fragment formatting 2026-08-06 14:18:32 +00:00