Commit Graph
74 Commits
Author SHA1 Message Date
Quentin Gliech efc98a48d2 Add a builder for per-route Content-Security-Policy headers
Rather than one lowest-common-denominator policy, each kind of route gets
the strictest policy it can bear: the server-rendered pages, the account
SPA shell, the Swagger UI, and a locked-down catch-all for everything
else. They are computed once at startup from the site configuration and
the `UrlBuilder` — the captcha provider origins, the plan-management
iframe origin and a possible cross-origin assets host are the only
dynamic inputs — and stored as prebuilt `HeaderValue`s.

The `form_post` authorization response is the one per-response case, as
its `form-action` names the redirect URI of the grant being completed.
2026-08-10 14:39:36 +02:00
Quentin Gliech c3b5fa3b0c Remove the GraphQL playground
The interactive playground page and its route/config option are gone; the GraphQL API itself (POST /graphql) is unaffected. External GraphQL usage is deprecated anyway in favour of the REST admin API.
2026-08-07 12:26:42 +02:00
Quentin GliechandGitHub 7abe147ba0 Expose a logged_out variable to upstream authorization parameter templates (#5859) 2026-07-29 17:57:55 +02:00
Quentin Gliech cd78f82f9c Replace Unix socket on startup & allow setting permissions
Fixes #5572
Fixes #2424

This makes it so that MAS binds on a temporary path on startup, sets
permissions and then moves it to the configured path. This means that we don't
error out anymore if there is a stale socket file, and that it is safe to
rollout a new process without killing the old one first, without breaking
connections.
2026-07-13 13:46:47 +02:00
Quentin Gliech e7c57e013a Expose a logged_out variable to upstream authorization parameter templates
When a browser signs out (or discovers its session was ended), the
session cookie now remembers when that happened; the flag is cleared by
the next successful login. The `additional_authorization_parameters`
templates can read it as `logged_out`, so operators can force a fresh
prompt at the upstream provider after sign-out, e.g.:

    additional_authorization_parameters:
      prompt: "{% if logged_out %}login{% endif %}"

This addresses the "sign out signs me back in" loop with upstream SSO
providers that still hold a live session.

Fixes #1569
2026-07-10 15:55:14 +02:00
Quentin Gliech f948dec457 config: remove the unused branding.logo_uri option
branding.logo_uri was accepted and validated by the config layer but never
plumbed through to SiteConfig or any template, so it had no effect. Remove the
field and regenerate the committed config schema to remove the confusion.
2026-06-25 19:04:19 +02:00
Quentin Gliech a22b71d7d9 docs: document missing configuration options
This was done by auditing what's in the `mas-config` crate (and resulting
config JSON schema) and comparing it to the current configuration options
documentation.
2026-06-25 19:04:18 +02:00
Quentin GliechandGitHub eb0ef6380c Merge branch 'main' into quenting/upstream-pass-parameters 2026-06-17 14:54:37 +02:00
Quentin GliechandGitHub db58127117 Merge branch 'main' into patch-1 2026-06-10 10:11:00 +02:00
Quentin Gliech 3025708520 Add a configuration option to disable device code auto-fill 2026-05-28 13:30:25 +02:00
Quentin GliechandGitHub 11d68cc8c9 Merge branch 'main' into quenting/upstream-pass-parameters 2026-05-20 10:14:00 +02:00
Quentin Gliech 6b8decf609 Document MiniJinja templating for additional_authorization_parameters
Updates the field doc-comment to describe the new templating semantics
and adds a deprecation note on `forward_login_hint` pointing to the
recommended replacement. Regenerates the JSON schema.

The runtime behavior (template rendering, forward_login_hint
soft-deprecation) is wired up in follow-up commits.
2026-05-13 17:44:15 +02:00
c-bgandGitHub 47aa94c465 fix typo: client_secret_jwk-> client_secret_jwt 2026-05-05 11:40:53 +02:00
Hugh Nimmo-Smith 53e6d05f40 Add oauth.device_code_grant_enabled configuration option 2026-04-07 11:13:56 +01:00
Olivier 'reivilibreandGitHub 20c68d4e76 Explain the purpose of signing keys in the config documentation. (#5286) 2025-12-03 13:02:04 +00:00
Olivier 'reivilibre 262e235c75 Convert use case list to bullet points and note the niche private_key_jwt method 2025-12-02 12:22:33 +00:00
Quentin Gliech df14076dd0 Merge branch 'quenting/upstream-oauth/better-conflict-options' into quenting/upstream-oauth/skip-interactive 2025-11-28 18:08:09 +01:00
Quentin Gliech 47d411f641 Option to skip confirmation when registering through an upstream OAuth provider 2025-11-28 15:51:43 +01:00
Quentin Gliech f0d84a4b47 Document the new conflict options 2025-11-28 11:57:46 +01:00
copilot-swe-agent[bot]andsandhose af15767135 Remove deprecated set_email_verification option from docs
Co-authored-by: sandhose <1549952+sandhose@users.noreply.github.com>
2025-11-27 15:47:37 +00:00
Olivier 'reivilibre f662b0b132 drive-by: Singing -> Signing 2025-11-25 17:06:38 +00:00
Olivier 'reivilibre 039cb09815 Add a little bit of explanation to the documentation about keys 2025-11-25 17:06:38 +00:00
Kai A. Hiller a93fa72477 Merge branch 'main' into keys_dir 2025-11-18 18:12:14 +01:00
networkException b5a0834faa Add upstream_oauth2.providers.[].client_secret_file config option
This patch factors out the previously introduced config
wrapper for client secrets to also use it for upstream oauth
providers.

See a7e7c3caa1
2025-11-08 16:10:19 +01:00
Quentin Gliech e4844968d3 Add a configuration option to make email optional for password registration 2025-10-07 17:28:01 +02:00
Kai A. Hiller 6a28950d8e Add secrets.keys_dir config option 2025-09-08 16:02:38 +02:00
Quentin GliechandGitHub 6eac7ed2d7 Automatically derive the kid from the key fingerprint if missing (#4876) 2025-09-02 17:04:35 +02:00
Patrick MaierandGitHub cf997048e4 Add missing branding config to docs (#4577) 2025-08-15 12:22:07 +02:00
Kai A. Hiller 1b7b43b559 Auto-generate kid if not given 2025-08-08 11:38:45 +02:00
Quentin GliechandGitHub 884c66891a Merge branch 'main' into secret_file 2025-08-05 11:17:39 +02:00
Kai A. Hiller a7e7c3caa1 Add clients.[].client_secret_file config option 2025-08-04 19:32:39 +02:00
Kai A. Hiller d4a318a8ae Add matrix.secret_file config option 2025-07-29 19:46:07 +02:00
Quentin GliechandGitHub 97cd5d86ba docs: Remove requirement for arbitrary KIDs (#4807) 2025-07-23 12:38:47 +02:00
Kai A. Hiller 858b388eec KIDs must be stable across restarts 2025-07-23 12:31:38 +02:00
Kai A. Hiller da94650706 Fix wording 2025-07-23 09:43:43 +02:00
Kai A. Hiller 2ecc502b05 Adapt markdown formatting 2025-07-23 09:39:52 +02:00
Kai A. Hiller 5587dd37e3 docs: Remove requirement for arbitrary KIDs 2025-07-21 18:37:03 +02:00
mcalingheeandOlivier D 98912f4ada allow importing existing users when the localpart matches in upstream OAuth 2.0 logins 2025-07-21 09:52:24 +02:00
Quentin Gliech 3bc3db1527 Add documentation for backchannel logout 2025-07-04 16:27:10 +02:00
Quentin GliechandGitHub 50b41a6613 Add secrets.encryption_file config option (#4617) 2025-06-05 15:14:55 +02:00
Kai A. Hiller 187838802d Update encryption secret warning in docs 2025-06-04 14:50:54 +02:00
Kai A. Hiller fbee4bfe8c Document secrets.encryption_file
Signed-off-by: Kai A. Hiller <git@kaialexhiller.de>
2025-06-04 11:42:51 +02:00
Quentin Gliech 685f4761cd Add config flag to require registration tokens for password registrations 2025-06-03 17:42:53 +02:00
Jason Robinson f3ef263e11 Add missing branding config to docs
Mostly copied from the code, with some additions from https://github.com/matrix-org/matrix-authentication-service/pull/2325
2025-05-20 15:21:13 +03:00
Doug e3c7b8054c Update upstream_oauth2.providers docs. 2025-05-07 11:14:10 +01:00
Quentin GliechandGitHub 5e30d50f38 Fix headings in config doc (#4419) 2025-04-23 14:11:33 +02:00
Hugh Nimmo-Smith 2414e147fb Remove reference to unsupported aws_ses email transport 2025-04-22 13:21:07 +01:00
Kai A. Hiller 54a8e1194c Fix headings in config doc
Signed-off-by: Kai A. Hiller <git@kaialexhiller.de>
2025-04-16 15:05:36 +02:00
mcalinghee f2a47f9a88 add login by email + feature flag 2025-04-10 17:57:58 +02:00
Quentin Gliech 3543b4048f Change the default value of account_deactivation_allowed to true. 2025-03-13 12:04:57 +01:00