avdb
e0054552ea
Merge branch 'rate-limiting' into 'next'
...
Draft: feat: rate limiting
Closes #4
See merge request famedly/conduit!693
2024-07-20 21:04:46 +00:00
Matthias Ahouansou
44dd21f432
Merge branch 'TheDidek1-next-patch-00204' into 'next'
...
Update docs to point at new Synapse location
See merge request famedly/conduit!715
2024-07-19 08:58:05 +00:00
Dawid Rejowski
75a0f68349
Update docs to point at new Synapse location
2024-07-18 19:58:27 +00:00
Matthias Ahouansou
619ea68405
a lot more endpoints
2024-07-12 13:15:24 +01:00
Matthias Ahouansou
e3cfe360a1
simplify conversion to restriction
2024-07-11 13:24:06 +01:00
Matthias Ahouansou
3bf113d920
don't take ownership of limitation
2024-07-11 13:15:45 +01:00
Matthias Ahouansou
613107e7cf
add rate limiting for registration token validity
2024-07-11 13:14:10 +01:00
Matthias Ahouansou
499548321f
enforce maximum capacity
2024-07-10 11:17:38 +01:00
Matthias Ahouansou
1e76cc5cee
don't rate limit appservices if the registration file says they shouldn't be
2024-07-10 10:40:33 +01:00
Matthias Ahouansou
6a3b194567
fmt
2024-07-10 09:51:23 +01:00
Matthias Ahouansou
ab21c5dbef
simplify
2024-07-10 09:44:44 +01:00
Matthias Ahouansou
8abab8c8a0
Merge branch 'Crftbt-next-patch-43247' into 'next'
...
Update docker.md specifying port so that others don't also run into trying to...
See merge request famedly/conduit!712
2024-07-10 08:36:34 +00:00
Craft
324e1beabf
Update docker.md specifying port so that others don't also run into trying to figure this out when following this md.
2024-07-09 21:49:55 +00:00
Matthias Ahouansou
bf902f1607
use ::MIN
2024-07-09 13:38:36 +01:00
Matthias Ahouansou
00c9ef7b56
Merge branch 'send-invalid-pdu-correction' into 'next'
...
fix: don't fail the entire request if any PDU's format is invalid
See merge request famedly/conduit!709
2024-07-07 21:13:38 +00:00
Matthias Ahouansou
6455e918be
fix: don't always assume ruma can generate reference hashes
2024-07-07 21:40:56 +01:00
Matthias Ahouansou
ea3e7045b4
fix: don't fail the entire transaction if any PDU's format is invalid
2024-07-07 21:40:37 +01:00
Matthias Ahouansou
b8a1b4fee5
Merge branch 'remove-tls-override-when-no-srv-response' into 'next'
...
fix: remove TLS name override when no SRV record is present (but properly)
See merge request famedly/conduit!708
2024-07-06 16:49:38 +00:00
Matthias Ahouansou
d95345377b
fix: remove TLS name override when no SRV record is present (but properly)
...
The previous attempt only did so when no IP could be resolved, which isn't enough
2024-07-06 17:31:31 +01:00
Matthias Ahouansou
75322af8c7
Merge branch 'remove-tls-override-when-no-srv-response' into 'next'
...
fix: remove TLS name override when no SRV record is present
See merge request famedly/conduit!707
2024-07-06 16:24:32 +00:00
Matthias Ahouansou
e20fcb029a
fix nano gap
2024-07-06 17:06:39 +01:00
Matthias Ahouansou
024f910bf9
allow for different timeframes for configuration
2024-07-06 17:06:39 +01:00
Matthias Ahouansou
bdf12c2bbd
use into_iter
2024-07-06 17:06:39 +01:00
Matthias Ahouansou
d6abf5472b
more rate limit targets
2024-07-06 17:06:39 +01:00
mikoto
02cea0bb93
PoC
2024-07-06 17:06:39 +01:00
Matthias Ahouansou
11187b3fad
fix: remove TLS name override when no SRV record is present
...
this could have been an issue in cases where there was previously a SRV record, but later got removed
2024-07-06 17:06:11 +01:00
Matthias Ahouansou
1f313c6807
Merge branch 'finite-servername-cache' into 'next'
...
fix: don't cache server name lookups indefinitely
See merge request famedly/conduit!702
2024-07-01 09:52:18 +00:00
Matthias Ahouansou
e70d27af98
Merge branch 'timestamped-messaging' into 'next'
...
feat(appservice): support timestamped messaging
See merge request famedly/conduit!703
2024-07-01 09:36:14 +00:00
Matthias Ahouansou
ba8429cafe
fix: don't cache server name lookups indefinitely
2024-07-01 10:17:01 +01:00
Matthias Ahouansou
7a4d0f6fe8
Merge branch 'acl-dont-have-empty-exception' into 'next'
...
fix: don't ignore ACLs when there is no content
See merge request famedly/conduit!705
2024-06-26 21:41:42 +00:00
Matthias Ahouansou
2f45a907f9
fix: don't ignore ACLs when there is no content
...
despite this being very bad behavior, it is required by the spec
2024-06-26 22:06:46 +01:00
Matthias Ahouansou
de0deda179
Merge branch 'bump-ruma' into 'next'
...
chore: bump ruma
Closes #447
See merge request famedly/conduit!704
2024-06-25 09:43:15 +00:00
Matthias Ahouansou
62f1da053f
feat(appservice): support timestamped messaging
2024-06-25 10:25:58 +01:00
Matthias Ahouansou
602c56cae9
chore: bump ruma
2024-06-25 10:10:53 +01:00
Matthias Ahouansou
4b9520b5ad
Merge branch 'bump-rust' into 'next'
...
chore: bump rust to 1.79.0 and apply new lints
See merge request famedly/conduit!700
2024-06-21 07:54:00 +00:00
Matthias Ahouansou
9014e43ce1
chore: bump rust to 1.79.0 and apply new lints
2024-06-21 08:29:33 +01:00
Matthias Ahouansou
ffc57f8997
Merge branch 'nightly-rustfmt' into 'next'
...
ci: use nightly rustfmt
See merge request famedly/conduit!699
2024-06-16 16:44:51 +00:00
Matthias Ahouansou
fd19dda5cb
ci: use nightly rustfmt
...
we were using this before, but it broke when refactoring the flake out into separate files
2024-06-16 17:28:05 +01:00
Matthias Ahouansou
dc0fa09a57
Merge branch 'bump' into 'next'
...
chore: bump version to 0.9.0-alpha
See merge request famedly/conduit!698
2024-06-14 12:02:56 +00:00
Matthias Ahouansou
ba1138aaa3
chore: bump version to 0.9.0-alpha
2024-06-14 12:33:40 +01:00
Matthias Ahouansou
6398136163
Merge branch 'debian-aarch64' into 'next'
...
ci: build for Debian aarch64
See merge request famedly/conduit!692
2024-06-14 11:10:59 +00:00
Matthias Ahouansou
16af8b58ae
ci: build for Debian aarch64
2024-06-13 09:32:09 +01:00
Timo Kösters
7a5b893013
Bump version
2024-06-12 19:43:18 +02:00
Matthias Ahouansou
c453d45598
fix(keys): only use keys valid at the time of PDU or transaction, and actually refresh keys
...
Previously, we only fetched keys once, only requesting them again if we have any missing, allowing for ancient keys to be used to sign PDUs and transactions
Now we refresh keys that either have or are about to expire, preventing attacks that make use of leaked private keys of a homeserver
We also ensure that when validating PDUs or transactions, that they are valid at the origin_server_ts or time of us receiving the transaction respectfully
As to not break event authorization for old rooms, we need to keep old keys around
We move verify_keys which we no longer see in direct requests to the origin to old_verify_keys
We keep old_verify_keys indefinitely as mentioned above, as to not break event authorization (at least until a future MSC addresses this)
2024-06-12 19:41:43 +02:00
Matthias Ahouansou
144d548ef7
fix: permission checks for aliases
2024-06-12 19:41:31 +02:00
Benjamin Lee
7b259272ce
fix: do not return redacted events from search
2024-06-12 19:41:02 +02:00
Matthias Ahouansou
48c1f3bdba
fix: userid checks for incoming EDUs
2024-06-12 19:39:27 +02:00
Timo Kösters
dd19877528
Merge branch 'bump-ruma' into 'next'
...
chore: bump all dependencies
See merge request famedly/conduit!627
2024-06-11 20:59:58 +00:00
Matthias Ahouansou
ba2a5a6115
chore: bump all dependencies
2024-06-11 20:35:56 +01:00
Matthias Ahouansou
a36ccff06a
Merge branch 'security-readme' into 'next'
...
docs: add security disclosure instructions
See merge request famedly/conduit!691
2024-06-06 21:21:07 +00:00