Files
synapse/tests/appservice/test_appservice.py
T
Johannes Marbach 57d6da409c Add experimental support for letting application services proxy namespaces in the C-S and S-S API as per MSC4512 (#19972)
This implements the proxying part of
[MSC4512](https://github.com/matrix-org/matrix-spec-proposals/pull/4512)
and is a stopgap towards
https://github.com/element-hq/voip-internal/issues/641. It introduces a
new configuration property `io.element.msc4512.proxy` that allows
application services to claim namespaces in the C-S and S-S API. For
requests underneath a claimed namespace, Synapse first authorizes the
request and then reverse-proxies it to the application services. For
now, the only allowed namespace that can be claimed is
`unstable/io.element.msc4195/rtc/livekit`.

This pull request can be reviewed by commits.

### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [x] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))

---------

Signed-off-by: Johannes Marbach <n0-0ne+github@mailbox.org>
2026-08-28 13:45:54 +01:00

360 lines
13 KiB
Python

#
# This file is licensed under the Affero General Public License (AGPL) version 3.
#
# Copyright 2015, 2016 OpenMarket Ltd
# Copyright (C) 2023 New Vector, Ltd
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# See the GNU Affero General Public License for more details:
# <https://www.gnu.org/licenses/agpl-3.0.html>.
#
# Originally licensed under the Apache License, Version 2.0:
# <http://www.apache.org/licenses/LICENSE-2.0>.
#
# [This file includes modifications made by New Vector Limited]
#
#
import re
from typing import Any, Generator
from unittest.mock import AsyncMock, Mock
from twisted.internet import defer
from synapse.appservice import (
ApplicationService,
Namespace,
Scopes,
)
from synapse.types import UserID
from tests import unittest
def _regex(regex: str, exclusive: bool = True) -> Namespace:
return Namespace(exclusive, re.compile(regex))
class ApplicationServiceTestCase(unittest.TestCase):
def setUp(self) -> None:
self.service = ApplicationService(
id="unique_identifier",
sender=UserID.from_string("@as:test"),
url="some_url",
token="some_token",
)
self.event = Mock(
event_id="$abc:xyz",
type="m.something",
room_id="!foo:bar",
sender="@someone:somewhere",
)
self.store = Mock()
self.store.get_aliases_for_room = AsyncMock(return_value=[])
self.store.get_local_users_in_room = AsyncMock(return_value=[])
@defer.inlineCallbacks
def test_regex_user_id_prefix_match(
self,
) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_USERS].append(_regex("@irc_.*"))
self.event.sender = "@irc_foobar:matrix.org"
self.assertTrue(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
@defer.inlineCallbacks
def test_regex_user_id_prefix_no_match(
self,
) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_USERS].append(_regex("@irc_.*"))
self.event.sender = "@someone_else:matrix.org"
self.assertFalse(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
@defer.inlineCallbacks
def test_regex_room_member_is_checked(
self,
) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_USERS].append(_regex("@irc_.*"))
self.event.sender = "@someone_else:matrix.org"
self.event.type = "m.room.member"
self.event.state_key = "@irc_foobar:matrix.org"
self.assertTrue(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
@defer.inlineCallbacks
def test_regex_room_id_match(
self,
) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_ROOMS].append(
_regex("!some_prefix.*some_suffix:matrix.org")
)
self.event.room_id = "!some_prefixs0m3th1nGsome_suffix:matrix.org"
self.assertTrue(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
@defer.inlineCallbacks
def test_regex_room_id_no_match(
self,
) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_ROOMS].append(
_regex("!some_prefix.*some_suffix:matrix.org")
)
self.event.room_id = "!XqBunHwQIXUiqCaoxq:matrix.org"
self.assertFalse(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
@defer.inlineCallbacks
def test_regex_alias_match(self) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_ALIASES].append(
_regex("#irc_.*:matrix.org")
)
self.store.get_aliases_for_room = AsyncMock(
return_value=["#irc_foobar:matrix.org", "#athing:matrix.org"]
)
self.store.get_local_users_in_room = AsyncMock(return_value=[])
self.assertTrue(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
def test_non_exclusive_alias(self) -> None:
self.service.namespaces[ApplicationService.NS_ALIASES].append(
_regex("#irc_.*:matrix.org", exclusive=False)
)
self.assertFalse(self.service.is_exclusive_alias("#irc_foobar:matrix.org"))
def test_non_exclusive_room(self) -> None:
self.service.namespaces[ApplicationService.NS_ROOMS].append(
_regex("!irc_.*:matrix.org", exclusive=False)
)
self.assertFalse(self.service.is_exclusive_room("!irc_foobar:matrix.org"))
def test_non_exclusive_user(self) -> None:
self.service.namespaces[ApplicationService.NS_USERS].append(
_regex("@irc_.*:matrix.org", exclusive=False)
)
self.assertFalse(self.service.is_exclusive_user("@irc_foobar:matrix.org"))
def test_exclusive_alias(self) -> None:
self.service.namespaces[ApplicationService.NS_ALIASES].append(
_regex("#irc_.*:matrix.org", exclusive=True)
)
self.assertTrue(self.service.is_exclusive_alias("#irc_foobar:matrix.org"))
def test_exclusive_user(self) -> None:
self.service.namespaces[ApplicationService.NS_USERS].append(
_regex("@irc_.*:matrix.org", exclusive=True)
)
self.assertTrue(self.service.is_exclusive_user("@irc_foobar:matrix.org"))
def test_exclusive_room(self) -> None:
self.service.namespaces[ApplicationService.NS_ROOMS].append(
_regex("!irc_.*:matrix.org", exclusive=True)
)
self.assertTrue(self.service.is_exclusive_room("!irc_foobar:matrix.org"))
@defer.inlineCallbacks
def test_regex_alias_no_match(
self,
) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_ALIASES].append(
_regex("#irc_.*:matrix.org")
)
self.store.get_aliases_for_room = AsyncMock(
return_value=["#xmpp_foobar:matrix.org", "#athing:matrix.org"]
)
self.store.get_local_users_in_room = AsyncMock(return_value=[])
self.assertFalse(
(
yield defer.ensureDeferred(
self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
)
@defer.inlineCallbacks
def test_regex_multiple_matches(
self,
) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_ALIASES].append(
_regex("#irc_.*:matrix.org")
)
self.service.namespaces[ApplicationService.NS_USERS].append(_regex("@irc_.*"))
self.event.sender = "@irc_foobar:matrix.org"
self.store.get_aliases_for_room = AsyncMock(
return_value=["#irc_barfoo:matrix.org"]
)
self.store.get_local_users_in_room = AsyncMock(return_value=[])
self.assertTrue(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
@defer.inlineCallbacks
def test_interested_in_self(self) -> Generator["defer.Deferred[Any]", object, None]:
# make sure invites get through
self.service.sender = UserID.from_string("@appservice:name")
self.service.namespaces[ApplicationService.NS_USERS].append(_regex("@irc_.*"))
self.event.type = "m.room.member"
self.event.content = {"membership": "invite"}
self.event.state_key = self.service.sender.to_string()
self.assertTrue(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
@defer.inlineCallbacks
def test_member_list_match(self) -> Generator["defer.Deferred[Any]", object, None]:
self.service.namespaces[ApplicationService.NS_USERS].append(_regex("@irc_.*"))
# Note that @irc_fo:here is the AS user.
self.store.get_local_users_in_room = AsyncMock(
return_value=["@alice:here", "@irc_fo:here", "@bob:here"]
)
self.store.get_aliases_for_room = AsyncMock(return_value=[])
self.event.sender = "@xmpp_foobar:matrix.org"
self.assertTrue(
(
yield self.service.is_interested_in_event(
self.event.event_id, self.event, self.store
)
)
)
class ApplicationServiceScopesTestCase(unittest.TestCase):
def test_has_no_scopes_by_default(self) -> None:
service = ApplicationService(
id="unique_identifier",
sender=UserID.from_string("@as:test"),
token="some_token",
)
self.assertEqual(len(service.scopes), 0)
self.assertFalse(service.has_scope(Scopes.QUERY_ROOM_MEMBERSHIP))
def test_has_valid_scope_if_specified(self) -> None:
service = ApplicationService(
id="unique_identifier",
sender=UserID.from_string("@as:test"),
token="some_token",
scopes=[Scopes.QUERY_ROOM_MEMBERSHIP],
)
self.assertEqual(len(service.scopes), 1)
self.assertTrue(service.has_scope(Scopes.QUERY_ROOM_MEMBERSHIP))
def test_unknown_scope_raises(self) -> None:
with self.assertRaises(ValueError):
ApplicationService(
id="unique_identifier",
sender=UserID.from_string("@as:test"),
token="some_token",
scopes=["does:not:exist"],
)
class ApplicationServiceProxyPrefixTestCase(unittest.TestCase):
"""Tests the proxying configuration for application services from MSC4512."""
def _make_service(self, **kwargs: Any) -> ApplicationService:
kwargs.setdefault("id", "unique_identifier")
kwargs.setdefault("sender", UserID.from_string("@as:test"))
kwargs.setdefault("token", "some_token")
return ApplicationService(**kwargs)
def test_proxy_prefix_without_proxy_url_raises(self) -> None:
with self.assertRaises(KeyError):
self._make_service(proxy_url=None, proxy_prefix="rtc/livekit")
def test_proxy_prefix_with_empty_proxy_url_raises(self) -> None:
with self.assertRaises(ValueError):
self._make_service(proxy_url="", proxy_prefix="rtc/livekit")
def test_proxy_url_without_proxy_prefix_raises(self) -> None:
with self.assertRaises(KeyError):
self._make_service(proxy_url="http://proxy.example.com")
def test_proxy_url_with_empty_proxy_prefix_raises(self) -> None:
with self.assertRaises(ValueError):
self._make_service(proxy_url="http://proxy.example.com", proxy_prefix="")
def test_proxy_prefix_with_proxy_url_is_stored(self) -> None:
service = self._make_service(
proxy_url="http://proxy.example.com",
proxy_prefix="rtc/livekit",
)
self.assertEqual(service.proxy_prefix, "rtc/livekit")
self.assertEqual(service.proxy_url, "http://proxy.example.com")
def test_proxy_url_trailing_slash_is_stripped(self) -> None:
service = self._make_service(
proxy_url="http://proxy.example.com/",
proxy_prefix="rtc/livekit",
)
self.assertEqual(service.proxy_url, "http://proxy.example.com")
def test_nested_proxy_prefix_is_allowed(self) -> None:
service = self._make_service(
proxy_url="http://proxy.example.com",
proxy_prefix="rtc/livekit/foo",
)
self.assertEqual(service.proxy_prefix, "rtc/livekit/foo")
def test_disallowed_proxy_prefix_raises(self) -> None:
with self.assertRaises(ValueError):
self._make_service(
proxy_url="http://proxy.example.com", proxy_prefix="not/allowed"
)
def test_no_proxy_prefix_defaults_to_none(self) -> None:
service = self._make_service()
self.assertIsNone(service.proxy_prefix)
self.assertIsNone(service.proxy_url)
def test_trailing_slash_on_proxy_prefix_is_stripped(self) -> None:
service = self._make_service(
proxy_url="http://proxy.example.com",
proxy_prefix="rtc/livekit/foo/",
)
self.assertEqual(service.proxy_prefix, "rtc/livekit/foo")