Compare commits

...
5 changed files with 47 additions and 26 deletions
Generated
+12 -12
View File
@@ -816,7 +816,7 @@ dependencies = [
[[package]]
name = "conduwuit"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"aws-lc-rs",
"clap",
@@ -854,7 +854,7 @@ dependencies = [
[[package]]
name = "conduwuit_admin"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"assign",
"clap",
@@ -880,7 +880,7 @@ dependencies = [
[[package]]
name = "conduwuit_api"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"assign",
"async-trait",
@@ -918,7 +918,7 @@ dependencies = [
[[package]]
name = "conduwuit_build_metadata"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"built",
"cargo_metadata",
@@ -926,7 +926,7 @@ dependencies = [
[[package]]
name = "conduwuit_core"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"argon2",
"arrayvec",
@@ -994,7 +994,7 @@ dependencies = [
[[package]]
name = "conduwuit_database"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"async-channel",
"conduwuit_core",
@@ -1015,7 +1015,7 @@ dependencies = [
[[package]]
name = "conduwuit_macros"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"cargo_toml",
"itertools 0.15.0",
@@ -1026,7 +1026,7 @@ dependencies = [
[[package]]
name = "conduwuit_router"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"assign",
"axum",
@@ -1063,7 +1063,7 @@ dependencies = [
[[package]]
name = "conduwuit_service"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"askama",
"assign",
@@ -1115,7 +1115,7 @@ dependencies = [
[[package]]
name = "conduwuit_web"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"askama",
"assign",
@@ -4765,7 +4765,7 @@ dependencies = [
[[package]]
name = "ruminuwuity"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"assign",
"ruma",
@@ -6874,7 +6874,7 @@ dependencies = [
[[package]]
name = "xtask"
version = "26.7.1"
version = "26.7.2"
dependencies = [
"askama",
"cargo_metadata",
+1 -1
View File
@@ -12,7 +12,7 @@ license = "Apache-2.0"
# See also `rust-toolchain.toml`
readme = "README.md"
repository = "https://forgejo.ellis.link/continuwuation/continuwuity"
version = "26.7.1"
version = "26.7.2"
[workspace.metadata.crane]
name = "conduwuit"
@@ -7,7 +7,7 @@
Err, Event, Result, debug, debug_error, debug_warn, defer, matrix::PartialPdu, trace,
utils::time::jitter,
};
use futures::{FutureExt, StreamExt, future::try_join3};
use futures::{FutureExt, StreamExt, future::try_join4};
use ruma::{CanonicalJsonValue, EventId, RoomId, ServerName, UserId};
use tokio::sync::mpsc;
@@ -69,9 +69,13 @@ pub async fn handle_incoming_pdu<'a>(
.and_then(|s| UserId::parse(s).ok())
.is_some_and(|u| self.services.globals.user_is_local(&u));
let (room_exists, is_disabled, ()) = try_join3(
let (room_exists, is_disabled, is_resident, ()) = try_join4(
self.services.metadata.exists(room_id).map(Ok),
self.services.metadata.is_disabled(room_id).map(Ok),
self.services
.state_cache
.server_in_room(self.services.globals.server_name(), room_id)
.map(Ok),
self.acl_check(origin, room_id),
)
.await
@@ -85,12 +89,20 @@ pub async fn handle_incoming_pdu<'a>(
)));
}
// If the room doesn't exist (we don't have the create event), there's nothing
// we can do.
if !room_exists {
return Err!(Request(NotFound("Room is unknown to this server")));
}
// If the room does exist, but we aren't a resident of it, we might be
// interested in an out-of-band membership (for example, an inviter rescinding
// their invite).
if !is_resident {
if is_interesting_member_event {
// TODO: handle interesting membership events where we aren't in
// the room
}
return Err!(Request(NotFound("Room is unknown to this server")));
return Err!(Request(NotFound("This server does not have any members this room")));
}
// Fetch create event
@@ -104,24 +104,24 @@ pub(super) async fn upgrade_outlier_to_timeline_pdu(
// Determine whether this PDU should be soft-failed.
// If the auth check failed, invariably yes. Otherwise, only if the user isn't
// allowed to redact the target event (if any).
let mut should_soft_fail =
match (passes_current_state, incoming_pdu.redacts_id(&room_version_rules)) {
| (false, _) => true,
| (true, None) => false,
| (true, Some(redact_id)) => self
.services
let redaction_permitted =
if let Some(redacted_id) = incoming_pdu.redacts_id(&room_version_rules) {
self.services
.state_accessor
.user_can_redact(&redact_id, incoming_pdu.sender(), room_id, true)
.user_can_redact(&redacted_id, incoming_pdu.sender(), room_id, true)
.await
.is_ok_and(is_true!()),
.is_ok_and(is_true!())
} else {
true
};
let mut should_soft_fail = !redaction_permitted || !passes_current_state;
if !should_soft_fail {
// Now we can perform check 7, which is ensuring the event passes policy server
// checks.
// We explicitly only do this if we aren't already going to soft-fail the event,
// since the policy server refusing this event also soft-fails it.
debug!(event_id = %incoming_pdu.event_id, "Checking policy server for event");
debug!("Checking policy server for event");
should_soft_fail = !self
.policy_server_check_7(&incoming_pdu, &mut val, &room_version_rules)
.await
@@ -153,6 +153,12 @@ pub(super) async fn upgrade_outlier_to_timeline_pdu(
should_soft_fail = true;
}
}
} else {
debug!(
%redaction_permitted,
%passes_current_state,
"Intending to soft-fail event (skipping further PDU checks)"
);
}
// The PDU has now passed all checks! We can now promote it (or soft-fail it if
+4 -1
View File
@@ -1,4 +1,4 @@
use conduwuit::{Err, Result, matrix::Event, pdu::PartialPdu};
use conduwuit::{Err, Result, matrix::Event, pdu::PartialPdu, trace};
use ruma::{
EventId, RoomId, UserId,
events::{
@@ -46,6 +46,7 @@ pub async fn user_can_redact(
let power_levels = self.get_room_power_levels(room_id).await;
if power_levels.user_can_redact_event_of_other(sender) {
trace!(%sender, "Sender is allowed to redact other users' events");
return Ok(true);
}
@@ -59,10 +60,12 @@ pub async fn user_can_redact(
},
| _ => false,
};
trace!(%is_own_event, "User can redact own event");
return Ok(is_own_event);
}
trace!("User is not permitted to redact their own event nor others' events");
Ok(false)
}