mirror of
https://github.com/element-hq/matrix-authentication-service.git
synced 2026-08-14 11:19:57 +00:00
Rather than one lowest-common-denominator policy, each kind of route gets the strictest policy it can bear: the server-rendered pages, the account SPA shell, the Swagger UI, and a locked-down catch-all for everything else. They are computed once at startup from the site configuration and the `UrlBuilder` — the captcha provider origins, the plan-management iframe origin and a possible cross-origin assets host are the only dynamic inputs — and stored as prebuilt `HeaderValue`s. The `form_post` authorization response is the one per-response case, as its `form-action` names the redirect URI of the grant being completed.
About this documentation
This documentation is intended to give an overview of how the matrix-authentication-service (MAS) works, both from an admin perspective and from a developer perspective.
MAS is an OAuth 2.0 and OpenID Provider server for Matrix. It has been created to support the migration of Matrix to an OpenID Connect (OIDC) based authentication layer as per MSC3861.
The documentation itself is built using mdBook. A hosted version is available at https://element-hq.github.io/matrix-authentication-service/.
How the documentation is organized
This documentation has four main sections:
- The installation guide will guide you through the process of setting up the
matrix-authentication-serviceon your own infrastructure. - The topics sections goes into more details about how the service works, like the policy engine and how authorization sessions are managed.
- The reference documentation covers configuration options, the Admin API, the scopes supported by the service, and the command line interface.
- The developer documentation is intended for people who want to contribute to the project. Developers may also be interested in: