Commit Graph
84 Commits
Author SHA1 Message Date
Paul Chobert 6a105cc52c Merge remote-tracking branch 'upstream/main' into docs-msc4190-appservice-devices
# Conflicts:
#	docs/as-login.md
2026-09-30 10:11:57 +02:00
Paul Chobert 52dfde42e8 docs: Refer to the spec rather than MSC4190 for appservice device management
The device management endpoints are part of the Application Service API
since Matrix 1.17, so point at the spec instead of the proposal.
2026-09-30 10:08:56 +02:00
Quentin Gliech dbbb93915e Declare the Node.js version in devEngines.runtime
`pnpm/setup` reads the runtime version from `package.json` and ignores `.node-version`. With `onFail: download`, pnpm records Node 24.15.0 in the lockfile and downloads it on every install unless `--no-runtime` is passed. The Dockerfile and the docs build pass it, since they already run a pinned Node. `.node-version` stays for the Cloudflare Pages build, which reads it to pick the Node that bootstraps corepack.
2026-09-07 16:04:48 +02:00
Quentin Gliech 04fdf83b11 Merge branch 'main' into docs-msc4190-appservice-devices 2026-09-03 19:54:58 +02:00
Paul Chobert d3cf92fd24 docs: Remove the appservice login warning page
The page said encrypted bridges cannot work with MAS and that a solution
was being worked on. That solution is MSC4190, stable since Matrix 1.17
and enabled for every application service in Synapse 1.141.0, so the
limitation no longer exists.

Replace the page with a readiness item on the migration page, which is
where the original warning was aimed, and redirect the old URL there.
2026-09-03 15:48:38 +02:00
Quentin Gliech 66e73f9910 Pin the Rust toolchain with a rust-toolchain.toml
Until now only the clippy CI job and the Dockerfile named a Rust version (kept in sync by hand), while every other CI job, the release binaries and the docs build ran on whatever `stable` happened to be that day. Rust 1.98.0 landing on 2026-08-20 broke `build-binaries` overnight because of that (#5935).

`rust-toolchain.toml` pins 1.96.0 with the `minimal` profile plus clippy, and every `rustup toolchain install stable ...` in CI becomes a bare `rustup toolchain install`, which reads the file. Starting at 1.96.0 (the version clippy is already clean against) keeps this change free of lint churn; catching up to 1.98.0 is a follow-up.

rustfmt stays on nightly because `.rustfmt.toml` uses nightly-only options, so that job now invokes `cargo +nightly fmt` explicitly instead of setting a rustup directory override, which would silently take precedence over the toolchain file.

The file does not list the linux cross-compilation targets on purpose: that would make every developer and CI job download `rust-std` they never use. The two consumers that cross-compile add the targets themselves.
2026-08-26 12:01:34 +02:00
Quentin GliechandAndrew Morgan cae99ccef3 Adapt punctionation in docs
Co-Authored-By: Andrew Morgan <andrewm@element.io>
2026-07-29 14:52:02 +02:00
Quentin Gliech e7c57e013a Expose a logged_out variable to upstream authorization parameter templates
When a browser signs out (or discovers its session was ended), the
session cookie now remembers when that happened; the flag is cleared by
the next successful login. The `additional_authorization_parameters`
templates can read it as `logged_out`, so operators can force a fresh
prompt at the upstream provider after sign-out, e.g.:

    additional_authorization_parameters:
      prompt: "{% if logged_out %}login{% endif %}"

This addresses the "sign out signs me back in" loop with upstream SSO
providers that still hold a live session.

Fixes #1569
2026-07-10 15:55:14 +02:00
Quentin Gliech 670cdce15e docs: fix stale config references in setup and CLI docs
This is a pass on the whole setup guide to make sure all the configuration
options are correctly referenced.
2026-06-25 19:04:18 +02:00
Quentin Gliech 9815902e9b Allow passing arbitrary values from clients down to upstream OAuth providers (#5677) 2026-06-17 16:28:57 +02:00
Olivier 'reivilibre e856e19638 Update Authelia Sample for OIDC upstream (#5672) 2026-06-17 14:41:03 +01:00
Quentin Gliech eb0ef6380c Merge branch 'main' into quenting/upstream-pass-parameters 2026-06-17 14:54:37 +02:00
TuxCoder f3cd388316 Update homeserver.md
fix synapse config name
ref: https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html#matrix_authentication_service
2026-06-04 22:52:35 +02:00
Quentin Gliech 6b8decf609 Document MiniJinja templating for additional_authorization_parameters
Updates the field doc-comment to describe the new templating semantics
and adds a deprecation note on `forward_login_hint` pointing to the
recommended replacement. Regenerates the JSON schema.

The runtime behavior (template rendering, forward_login_hint
soft-deprecation) is wired up in follow-up commits.
2026-05-13 17:44:15 +02:00
Quentin Gliech d82fa2d691 docs: update build instructions to use pnpm
Replaces the `cd frontend && npm ci` setup steps with a pnpm-flavoured
one: enable corepack (one-time), `pnpm install` from the repo root, then
`cd frontend && pnpm run <script>` for frontend scripts. misc/update.sh
also moves to `pnpm --filter mas-frontend run …`
2026-05-12 12:51:21 +02:00
André Pinto 493b2589ba Update sso.md
adding authelia configuration fix so that preferred_username is populated accordingly.
2026-05-10 22:15:08 -03:00
Olivier 'reivilibre ba582081a2 Fix doc reference: policy.path -> policy.wasm_module 2026-04-27 17:31:40 +01:00
CEbbinghaus fbc6cd0783 Added signing alg setting to provider yaml 2026-01-28 11:08:35 +11:00
CEbbinghaus 0dff4d628f Added Kanidm Sample configuration 2026-01-23 21:41:45 +11:00
Quentin Gliech 8384a5af4c Merge branch 'main' into quenting/upstream-oauth/better-conflict-options 2025-11-28 18:10:22 +01:00
Quentin Gliech c5ba1f610d Check for the new on_conflict options & update docs 2025-11-28 16:10:07 +01:00
copilot-swe-agent[bot]andsandhose b2fb289c37 Add complete Shibboleth metadata file example
Co-authored-by: sandhose <1549952+sandhose@users.noreply.github.com>
2025-11-27 16:48:00 +00:00
copilot-swe-agent[bot]andsandhose af15767135 Remove deprecated set_email_verification option from docs
Co-authored-by: sandhose <1549952+sandhose@users.noreply.github.com>
2025-11-27 15:47:37 +00:00
copilot-swe-agent[bot]andsandhose fc7e2e3f57 Remove unnecessary userinfo_endpoint from Shibboleth config
Co-authored-by: sandhose <1549952+sandhose@users.noreply.github.com>
2025-11-27 15:38:21 +00:00
copilot-swe-agent[bot]andsandhose 0d10e148a7 Add Shibboleth sample configuration to SSO documentation
Co-authored-by: sandhose <1549952+sandhose@users.noreply.github.com>
2025-11-27 15:31:20 +00:00
Olivier 'reivilibre 723a948c87 Update docs/setup/reverse-proxy.md 2025-11-27 12:31:48 +00:00
May 90748a37c8 Modify Nginx compatibility-layer location block to forward not just client stuff to matrix-synapse
Before the change, it did just just forward `/_matrix` & `/_synapse/client` to synapse.
2025-11-14 11:36:18 +01:00
Quentin GliechandCopilot 6a2d341657 Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-08-18 13:44:10 +02:00
Quentin Gliech ef50efe9e6 Document Synapse integration with the stable feature 2025-08-18 13:38:35 +02:00
mcalinghee 98912f4ada allow importing existing users when the localpart matches in upstream OAuth 2.0 logins 2025-07-21 09:52:24 +02:00
Quentin Gliech 3bc3db1527 Add documentation for backchannel logout 2025-07-04 16:27:10 +02:00
Quentin Gliech 40cb052d1f Allow applying unicode normalisation to passwords before hashing 2025-05-30 15:42:32 +02:00
Quentin GliechandWill Lewis 6c0c110503 Apply suggestions from code review
Co-authored-by: Will Lewis <1543626+wrjlewis@users.noreply.github.com>
2025-04-30 11:49:29 +02:00
Quentin Gliech e3d1b8abfa docs: stop talking about the .well-known/matrix/client changes
These were relevant on an old version of the specs, and just confuses people.
2025-04-23 18:52:34 +02:00
Quentin Gliech 114ae7dd48 Document the new migration tool 2025-04-23 18:50:15 +02:00
Olivier 'reivilibre ff06b5ed5a syn2mas: document new tool 2025-04-23 17:52:09 +02:00
Adis Veletanlic f8114be322 Merge branch 'element-hq:main' into main 2025-04-16 08:40:03 +02:00
Quentin Gliech 117590c1bc fix(docs): add token_endpoint_auth_method in Authentik SSO example (#4387) 2025-04-15 22:37:41 +02:00
Adis Veletanlic a27ccba9c3 Merge branch 'element-hq:main' into main 2025-04-14 12:22:51 +02:00
Adis Veletanlic 0e50c44605 Add private_key_file option for apple sso and edit docs 2025-04-14 12:21:00 +02:00
Quentin Gliech a3202a690a Document how to migrate passwords from Synapse with a pepper set (#4353) 2025-04-11 16:40:14 +02:00
Quentin Gliech da9fc3ce65 Minor rewording 2025-04-11 16:33:14 +02:00
Samuel Lorch c9bca2be70 Document password scheme secret field for migrations
Signed-off-by: Samuel Lorch sam@soontm.de
2025-04-11 11:45:28 +02:00
Przemysław Romanik d32c9a8b70 fix(docs): add token_endpoint_auth_method in Authentik SSO example 2025-04-11 00:17:02 +02:00
hummingbard 9f925e6f09 Added upstream sample config for Discord, brand logo in templates 2025-03-30 15:53:56 +06:00
hummingbard ecef762e9e Missing token_endpoint_auth_method field in upstream sample config for Github 2025-03-30 14:08:14 +06:00
Kieran Lane 5996cac327 Disable Verification for Microsoft Azure AD OIDC
Required to avoid `token_endpoint missing auth signing algorithm values` error.
2025-03-18 10:44:45 +00:00
Strac Consulting Engineers Pty Ltd da944ccde7 Update README.md
Amended issuer.
2025-02-13 18:03:51 +11:00
Strac Consulting Engineers Pty Ltd ee9eeea648 Update README.md 2025-02-09 13:07:31 +11:00
Quentin Gliech a8e7749a07 Clarify why one would override the introspection_endpoint 2025-01-28 10:02:06 +01:00