76 Commits

Author SHA1 Message Date
Olivier 'reivilibre
20c68d4e76 Explain the purpose of signing keys in the config documentation. (#5286) 2025-12-03 13:02:04 +00:00
Olivier 'reivilibre
262e235c75 Convert use case list to bullet points and note the niche private_key_jwt method 2025-12-02 12:22:33 +00:00
Quentin Gliech
df14076dd0 Merge branch 'quenting/upstream-oauth/better-conflict-options' into quenting/upstream-oauth/skip-interactive 2025-11-28 18:08:09 +01:00
Quentin Gliech
47d411f641 Option to skip confirmation when registering through an upstream OAuth provider 2025-11-28 15:51:43 +01:00
Quentin Gliech
f0d84a4b47 Document the new conflict options 2025-11-28 11:57:46 +01:00
Quentin Gliech
7587637943 Add Shibboleth sample configuration to SSO documentation (#5294) 2025-11-27 18:02:28 +01:00
copilot-swe-agent[bot]
af15767135 Remove deprecated set_email_verification option from docs
Co-authored-by: sandhose <1549952+sandhose@users.noreply.github.com>
2025-11-27 15:47:37 +00:00
Olivier 'reivilibre
f662b0b132 drive-by: Singing -> Signing 2025-11-25 17:06:38 +00:00
Olivier 'reivilibre
039cb09815 Add a little bit of explanation to the documentation about keys 2025-11-25 17:06:38 +00:00
Olivier 'reivilibre
a89eb28a37 cli docs: Fix --usage-limit and --unlimited 2025-11-25 12:05:32 +00:00
reivilibre
4753aa811b templates check: Add --stabilise flag to make renders reproducible (#5214) 2025-11-24 16:16:11 +00:00
Kai A. Hiller
a93fa72477 Merge branch 'main' into keys_dir 2025-11-18 18:12:14 +01:00
networkException
b5a0834faa Add upstream_oauth2.providers.[].client_secret_file config option
This patch factors out the previously introduced config
wrapper for client secrets to also use it for upstream oauth
providers.

See a7e7c3caa1
2025-11-08 16:10:19 +01:00
Olivier 'reivilibre
4793f534e6 Add rest of documentation on templates check 2025-10-30 16:33:50 +00:00
Olivier 'reivilibre
eba9c5e1e1 document new options on templates check 2025-10-30 15:14:49 +00:00
teutat3s
163357a85e docs: add missing --reactivate option 2025-10-17 19:39:34 +02:00
Quentin Gliech
e4844968d3 Add a configuration option to make email optional for password registration 2025-10-07 17:28:01 +02:00
Quentin Gliech
815ce17cc5 Simple CLI commands to manage server admins 2025-09-16 12:42:32 +02:00
Kai A. Hiller
6a28950d8e Add secrets.keys_dir config option 2025-09-08 16:02:38 +02:00
Quentin Gliech
6eac7ed2d7 Automatically derive the kid from the key fingerprint if missing (#4876) 2025-09-02 17:04:35 +02:00
Patrick Maier
cf997048e4 Add missing branding config to docs (#4577) 2025-08-15 12:22:07 +02:00
Kai A. Hiller
1b7b43b559 Auto-generate kid if not given 2025-08-08 11:38:45 +02:00
Quentin Gliech
884c66891a Merge branch 'main' into secret_file 2025-08-05 11:17:39 +02:00
Quentin Gliech
c6ae5c7557 Add clients.[].client_secret_file config option (#4857) 2025-08-05 11:17:00 +02:00
Kai A. Hiller
a7e7c3caa1 Add clients.[].client_secret_file config option 2025-08-04 19:32:39 +02:00
Quentin Gliech
7e018a06aa Merge remote-tracking branch 'origin/main' into quenting/stable-api 2025-08-04 16:38:49 +02:00
Kai A. Hiller
d4a318a8ae Add matrix.secret_file config option 2025-07-29 19:46:07 +02:00
Quentin Gliech
97cd5d86ba docs: Remove requirement for arbitrary KIDs (#4807) 2025-07-23 12:38:47 +02:00
Kai A. Hiller
858b388eec KIDs must be stable across restarts 2025-07-23 12:31:38 +02:00
Kai A. Hiller
da94650706 Fix wording 2025-07-23 09:43:43 +02:00
Kai A. Hiller
2ecc502b05 Adapt markdown formatting 2025-07-23 09:39:52 +02:00
Kai A. Hiller
5587dd37e3 docs: Remove requirement for arbitrary KIDs 2025-07-21 18:37:03 +02:00
mcalinghee
98912f4ada allow importing existing users when the localpart matches in upstream OAuth 2.0 logins 2025-07-21 09:52:24 +02:00
Quentin Gliech
3bc3db1527 Add documentation for backchannel logout 2025-07-04 16:27:10 +02:00
Quentin Gliech
d27f7e3cd9 Mention the stable scopes in the doc, remove the guest scope 2025-06-13 15:56:13 +02:00
Quentin Gliech
50b41a6613 Add secrets.encryption_file config option (#4617) 2025-06-05 15:14:55 +02:00
Kai A. Hiller
187838802d Update encryption secret warning in docs 2025-06-04 14:50:54 +02:00
Kai A. Hiller
fbee4bfe8c Document secrets.encryption_file
Signed-off-by: Kai A. Hiller <git@kaialexhiller.de>
2025-06-04 11:42:51 +02:00
Quentin Gliech
5d13691acd CLI tool to issue user registration tokens 2025-06-03 17:42:55 +02:00
Quentin Gliech
685f4761cd Add config flag to require registration tokens for password registrations 2025-06-03 17:42:53 +02:00
Jason Robinson
f3ef263e11 Add missing branding config to docs
Mostly copied from the code, with some additions from https://github.com/matrix-org/matrix-authentication-service/pull/2325
2025-05-20 15:21:13 +03:00
Doug
e3c7b8054c Update upstream_oauth2.providers docs. 2025-05-07 11:14:10 +01:00
Quentin Gliech
114ae7dd48 Document the new migration tool 2025-04-23 18:50:15 +02:00
Quentin Gliech
5e30d50f38 Fix headings in config doc (#4419) 2025-04-23 14:11:33 +02:00
Hugh Nimmo-Smith
2414e147fb Remove reference to unsupported aws_ses email transport 2025-04-22 13:21:07 +01:00
Kai A. Hiller
54a8e1194c Fix headings in config doc
Signed-off-by: Kai A. Hiller <git@kaialexhiller.de>
2025-04-16 15:05:36 +02:00
mcalinghee
f2a47f9a88 add login by email + feature flag 2025-04-10 17:57:58 +02:00
Quentin Gliech
3543b4048f Change the default value of account_deactivation_allowed to true. 2025-03-13 12:04:57 +01:00
Quentin Gliech
25b4784803 Add the new configuration option to the configuration reference 2025-03-12 16:02:52 +01:00
Quentin Gliech
6e881d60f2 Document the new username ban/allow policy 2025-03-03 10:35:44 +01:00