Update changelog, add to room version 10 event auth rules

This commit is contained in:
Neil Alexander 2022-06-14 16:49:26 +01:00
parent 5a58eafd7e
commit 21f7dfe21a
No known key found for this signature in database
GPG key ID: A02A2019A2BB0944
2 changed files with 11 additions and 8 deletions

View file

@ -1 +1 @@
Auth rules: Clarify behaviour around the `m.federate` field in `m.room.create` events. For all room versions: Add `m.federate` to the authorization rules, as originally intended.

View file

@ -114,7 +114,10 @@ The rules are as follows:
algorithm described in the server specification. algorithm described in the server specification.
3. If event does not have a `m.room.create` in its `auth_events`, 3. If event does not have a `m.room.create` in its `auth_events`,
reject. reject.
4. If type is `m.room.member`: 4. If the create event content has the field `m.federate` set to `false`
and the sender domain of the event does not match the sender domain of
the create event, reject.
5. If type is `m.room.member`:
1. If no `state_key` key or `membership` key in `content`, reject. 1. If no `state_key` key or `membership` key in `content`, reject.
2. If `content` has a `join_authorised_via_users_server` 2. If `content` has a `join_authorised_via_users_server`
key: key:
@ -191,15 +194,15 @@ The rules are as follows:
or `join`, allow. or `join`, allow.
4. Otherwise, reject. 4. Otherwise, reject.
8. Otherwise, the membership is unknown. Reject. 8. Otherwise, the membership is unknown. Reject.
5. If the `sender`'s current membership state is not `join`, reject. 6. If the `sender`'s current membership state is not `join`, reject.
6. If type is `m.room.third_party_invite`: 7. If type is `m.room.third_party_invite`:
1. Allow if and only if `sender`'s current power level is greater 1. Allow if and only if `sender`'s current power level is greater
than or equal to the *invite level*. than or equal to the *invite level*.
7. If the event type's *required power level* is greater than the 8. If the event type's *required power level* is greater than the
`sender`'s power level, reject. `sender`'s power level, reject.
8. If the event has a `state_key` that starts with an `@` and does not 9. If the event has a `state_key` that starts with an `@` and does not
match the `sender`, reject. match the `sender`, reject.
9. If type is `m.room.power_levels`: 10. If type is `m.room.power_levels`:
1. {{< added-in this="true" >}} 1. {{< added-in this="true" >}}
If any of the keys `users_default`, `events_default`, `state_default`, If any of the keys `users_default`, `events_default`, `state_default`,
`ban`, `redact`, `kick`, or `invite` in `content` are present and `ban`, `redact`, `kick`, or `invite` in `content` are present and
@ -230,7 +233,7 @@ The rules are as follows:
1. If the current value is equal to the `sender`'s current 1. If the current value is equal to the `sender`'s current
power level, reject. power level, reject.
6. Otherwise, allow. 6. Otherwise, allow.
10. Otherwise, allow. 11. Otherwise, allow.
{{% boxes/note %}} {{% boxes/note %}}
Some consequences of these rules: Some consequences of these rules: