Replace outdated statement that messages are not encrypted

Signed-off-by: Kévin Commaille <zecakeh@tedomum.fr>
This commit is contained in:
Kévin Commaille 2026-05-01 09:09:24 +02:00
parent 160339e580
commit 018d5bbab3
No known key found for this signature in database
GPG key ID: F26F4BE20A08255B

View file

@ -454,8 +454,7 @@ status code of 400.
#### Security considerations
Messages sent using this module are not encrypted, although end to end
encryption is in development (see [E2E module](#end-to-end-encryption)).
Messages sent using this module MAY be encrypted, see [End-to-End Encryption](#end-to-end-encryption).
Clients should sanitise **all displayed keys** for unsafe HTML to
prevent Cross-Site Scripting (XSS) attacks. This includes room names and