mirror of
https://github.com/matrix-org/matrix-spec
synced 2026-04-26 20:44:10 +02:00
Compare commits
9 commits
07859e3009
...
37b03641bd
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
37b03641bd | ||
|
|
cbff6790c3 | ||
|
|
8b7187927d | ||
|
|
6264b34caf | ||
|
|
917f1dd8c1 | ||
|
|
909395ab3c | ||
|
|
b6198973e0 | ||
|
|
b09d59bd37 | ||
|
|
68d92cf254 |
1
changelogs/appendices/newsfragments/2307.clarification
Normal file
1
changelogs/appendices/newsfragments/2307.clarification
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
Add identifier pronunciation guidelines. Contributed by @HarHarLinks.
|
||||||
1
changelogs/client_server/newsfragments/2305.feature
Normal file
1
changelogs/client_server/newsfragments/2305.feature
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
Add invite blocking, as per [MSC4380](https://github.com/matrix-org/matrix-spec-proposals/pull/4380).
|
||||||
|
|
@ -0,0 +1 @@
|
||||||
|
Clarify meaning of floating-point powerlevels.
|
||||||
|
|
@ -533,6 +533,11 @@ where `domain` is the [server name](#server-name) of the homeserver
|
||||||
which allocated the identifier, and `localpart` is an identifier
|
which allocated the identifier, and `localpart` is an identifier
|
||||||
allocated by that homeserver.
|
allocated by that homeserver.
|
||||||
|
|
||||||
|
Because the domain part identifies the server on which the ID resolves,
|
||||||
|
the canonical pronunciation of the separating `:` is "on".
|
||||||
|
For example, `@user:matrix.org` would be pronounced as "at user on matrix dot
|
||||||
|
org".
|
||||||
|
|
||||||
The precise grammar defining the allowable format of an identifier
|
The precise grammar defining the allowable format of an identifier
|
||||||
depends on the type of identifier. For example, event IDs can sometimes
|
depends on the type of identifier. For example, event IDs can sometimes
|
||||||
be represented with a `domain` component under some conditions - see the
|
be represented with a `domain` component under some conditions - see the
|
||||||
|
|
|
||||||
|
|
@ -4071,6 +4071,7 @@ that profile.
|
||||||
| [Sticker Messages](#sticker-messages) | Optional | Optional | Optional | Optional | Optional |
|
| [Sticker Messages](#sticker-messages) | Optional | Optional | Optional | Optional | Optional |
|
||||||
| [Third-party Networks](#third-party-networks) | Optional | Optional | Optional | Optional | Optional |
|
| [Third-party Networks](#third-party-networks) | Optional | Optional | Optional | Optional | Optional |
|
||||||
| [Threading](#threading) | Optional | Optional | Optional | Optional | Optional |
|
| [Threading](#threading) | Optional | Optional | Optional | Optional | Optional |
|
||||||
|
| [Invite permission](#invite-permission) | Optional | Optional | Optional | Optional | Optional |
|
||||||
|
|
||||||
*Please see each module for more details on what clients need to
|
*Please see each module for more details on what clients need to
|
||||||
implement.*
|
implement.*
|
||||||
|
|
@ -4144,6 +4145,7 @@ systems.
|
||||||
{{% cs-module name="SSO client login/authentication" filename="sso_login" %}}
|
{{% cs-module name="SSO client login/authentication" filename="sso_login" %}}
|
||||||
{{% cs-module name="Direct Messaging" filename="dm" %}}
|
{{% cs-module name="Direct Messaging" filename="dm" %}}
|
||||||
{{% cs-module name="Ignoring Users" filename="ignore_users" %}}
|
{{% cs-module name="Ignoring Users" filename="ignore_users" %}}
|
||||||
|
{{% cs-module name="Invite permission" filename="invite_permission" %}}
|
||||||
{{% cs-module name="Sticker Messages" filename="stickers" %}}
|
{{% cs-module name="Sticker Messages" filename="stickers" %}}
|
||||||
{{% cs-module name="Reporting Content" filename="report_content" %}}
|
{{% cs-module name="Reporting Content" filename="report_content" %}}
|
||||||
{{% cs-module name="Third-party Networks" filename="third_party_networks" %}}
|
{{% cs-module name="Third-party Networks" filename="third_party_networks" %}}
|
||||||
|
|
|
||||||
51
content/client-server-api/modules/invite_permission.md
Normal file
51
content/client-server-api/modules/invite_permission.md
Normal file
|
|
@ -0,0 +1,51 @@
|
||||||
|
|
||||||
|
### Invite permission
|
||||||
|
|
||||||
|
{{% added-in v="1.18" %}}
|
||||||
|
|
||||||
|
Users may want to control who is allowed to invite them to new rooms. This module defines how
|
||||||
|
clients and servers can implement invite permission.
|
||||||
|
|
||||||
|
#### Account data
|
||||||
|
|
||||||
|
{{% event event="m.invite_permission_config" %}}
|
||||||
|
|
||||||
|
#### Client behaviour
|
||||||
|
|
||||||
|
To reject invites from all users automatically, clients MAY add an [`m.invite_permission_config`](#minvite_permission_config)
|
||||||
|
event in the user's [account data](#client-config) with the `default_action` property set to
|
||||||
|
`block`. To stop rejecting all invites, the same event without the `default_action` property MUST be
|
||||||
|
added to the account data.
|
||||||
|
|
||||||
|
When the `default_action` field is unset, other parts of the specification might still have effects
|
||||||
|
on invites seen by clients, like [ignoring users](#ignoring-users).
|
||||||
|
|
||||||
|
Attempting to send an invite to a user that blocks invites will result in an error response with the
|
||||||
|
`M_INVITE_BLOCKED` error code.
|
||||||
|
|
||||||
|
#### Server behaviour
|
||||||
|
|
||||||
|
When invites to a given user are blocked, the user's homeserver MUST respond to the following
|
||||||
|
endpoints with an HTTP 403 status code, with the Matrix error code `M_INVITE_BLOCKED`, if the user
|
||||||
|
is invited:
|
||||||
|
|
||||||
|
* [`PUT /_matrix/federation/v1/invite/{roomId}/{eventId}`](/server-server-api/#put_matrixfederationv1inviteroomideventid)
|
||||||
|
* [`PUT /_matrix/federation/v2/invite/{roomId}/{eventId}`](/server-server-api/#put_matrixfederationv2inviteroomideventid)
|
||||||
|
* [`POST /_matrix/client/v3/rooms/{roomId}/invite`](#post_matrixclientv3roomsroomidinvite)
|
||||||
|
* [`POST /_matrix/client/v3/createRoom`](#post_matrixclientv3createroom), due to a user in the
|
||||||
|
`invite` list. It is possible for one of the invited users to be rejected whilst the room creation
|
||||||
|
as a whole succeeds.
|
||||||
|
* [`PUT /_matrix/client/v3/rooms/{roomId}/state/m.room.member/{stateKey}`](#put_matrixclientv3roomsroomidstateeventtypestatekey),
|
||||||
|
when the `membership` is set to `invite`.
|
||||||
|
|
||||||
|
In addition, invite events for this user already in the database, or received over federation, MUST
|
||||||
|
NOT be served over client synchronisation endpoints such as [`GET /sync`](#get_matrixclientv3sync).
|
||||||
|
|
||||||
|
Servers MAY return any suppressed invite events over `GET /sync` if invite blocking is later
|
||||||
|
disabled.
|
||||||
|
|
||||||
|
Other endpoints, such as [`GET /rooms/{roomId}/state`](#get_matrixclientv3roomsroomidstate), are not
|
||||||
|
affected by invite blocking: invite events are returned as normal.
|
||||||
|
|
||||||
|
The Application Services API is also unaffected by invite blocking: invite events are sent over
|
||||||
|
[`PUT /_matrix/app/v1/transactions/{txnId}`](/application-service-api/#put_matrixappv1transactionstxnid).
|
||||||
40
content/rooms/fragments/v1-floaty-power-levels.md
Normal file
40
content/rooms/fragments/v1-floaty-power-levels.md
Normal file
|
|
@ -0,0 +1,40 @@
|
||||||
|
|
||||||
|
##### `m.room.power_levels` events accept values as floats
|
||||||
|
|
||||||
|
When the value is a float, anything after the decimal point is removed,
|
||||||
|
making e.g. `5.17`, `5.42`, and `5` functionally identical.
|
||||||
|
|
||||||
|
For example, this is a valid `m.room.power_levels` event in this room version:
|
||||||
|
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"content": {
|
||||||
|
"ban": 50,
|
||||||
|
"events": {
|
||||||
|
"m.room.power_levels": 100
|
||||||
|
},
|
||||||
|
"events_default": 0,
|
||||||
|
"state_default": 50,
|
||||||
|
"users": {
|
||||||
|
"@example:example.org": 100,
|
||||||
|
"@alice:localhost": 50,
|
||||||
|
"@bob:localhost": 50.57
|
||||||
|
},
|
||||||
|
"users_default": 0
|
||||||
|
},
|
||||||
|
"origin_server_ts": 1432735824653,
|
||||||
|
"room_id": "!jEsUZKDJdhlrceRyVU:example.org",
|
||||||
|
"sender": "@example:example.org",
|
||||||
|
"state_key": "",
|
||||||
|
"type": "m.room.power_levels"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
In this example, both `@bob:localhost` and `@alice:localhost` have the same effective
|
||||||
|
power level of `50`, even though the values are technically different.
|
||||||
|
|
||||||
|
When a float written in exponential notation is unpacked, the decimal portion is removed
|
||||||
|
afterward; for example, `5.114698E4` becomes `51146.98`, which is then truncated to `51146`.
|
||||||
|
|
||||||
|
Note that, since this room version does not enforce that events comply with the requirements
|
||||||
|
of [Canonical JSON](/appendices#canonical-json), power levels can be formatted as floats.
|
||||||
|
|
@ -59,6 +59,8 @@ Events in version 1 rooms have the following structure:
|
||||||
|
|
||||||
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
||||||
|
|
||||||
|
{{% rver-fragment name="v1-floaty-power-levels" %}}
|
||||||
|
|
||||||
### Authorization rules
|
### Authorization rules
|
||||||
|
|
||||||
{{% rver-fragment name="v1-auth-rules" %}}
|
{{% rver-fragment name="v1-auth-rules" %}}
|
||||||
|
|
|
||||||
|
|
@ -57,6 +57,8 @@ Events in rooms of this version have the following structure:
|
||||||
|
|
||||||
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
||||||
|
|
||||||
|
{{% rver-fragment name="v1-floaty-power-levels" %}}
|
||||||
|
|
||||||
### Authorization rules
|
### Authorization rules
|
||||||
|
|
||||||
{{% rver-fragment name="v1-auth-rules" %}}
|
{{% rver-fragment name="v1-auth-rules" %}}
|
||||||
|
|
|
||||||
|
|
@ -87,6 +87,8 @@ The complete structure of a event in a v3 room is shown below.
|
||||||
|
|
||||||
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
||||||
|
|
||||||
|
{{% rver-fragment name="v1-floaty-power-levels" %}}
|
||||||
|
|
||||||
### Authorization rules
|
### Authorization rules
|
||||||
|
|
||||||
{{% boxes/note %}}
|
{{% boxes/note %}}
|
||||||
|
|
|
||||||
|
|
@ -76,6 +76,8 @@ the changes in this room version.
|
||||||
|
|
||||||
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
||||||
|
|
||||||
|
{{% rver-fragment name="v1-floaty-power-levels" %}}
|
||||||
|
|
||||||
### Authorization rules
|
### Authorization rules
|
||||||
|
|
||||||
{{% rver-fragment name="v3-auth-rules" %}}
|
{{% rver-fragment name="v3-auth-rules" %}}
|
||||||
|
|
|
||||||
|
|
@ -58,6 +58,8 @@ completeness.
|
||||||
|
|
||||||
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
{{% rver-fragment name="v1-stringy-power-levels" %}}
|
||||||
|
|
||||||
|
{{% rver-fragment name="v1-floaty-power-levels" %}}
|
||||||
|
|
||||||
### Authorization rules
|
### Authorization rules
|
||||||
|
|
||||||
{{% rver-fragment name="v3-auth-rules" %}}
|
{{% rver-fragment name="v3-auth-rules" %}}
|
||||||
|
|
|
||||||
|
|
@ -250,7 +250,6 @@ paths:
|
||||||
}
|
}
|
||||||
"400":
|
"400":
|
||||||
description: |-
|
description: |-
|
||||||
|
|
||||||
The request is invalid. A meaningful `errcode` and description
|
The request is invalid. A meaningful `errcode` and description
|
||||||
error text will be returned. Example reasons for rejection include:
|
error text will be returned. Example reasons for rejection include:
|
||||||
|
|
||||||
|
|
@ -274,6 +273,17 @@ paths:
|
||||||
application/json:
|
application/json:
|
||||||
schema:
|
schema:
|
||||||
$ref: definitions/errors/error.yaml
|
$ref: definitions/errors/error.yaml
|
||||||
|
"403":
|
||||||
|
description: |-
|
||||||
|
Creating the room is not allowed.
|
||||||
|
|
||||||
|
{{% added-in v="1.18"%}} The `M_INVITE_BLOCKED` error code is used to
|
||||||
|
indicate that one of the homeservers of the invited users rejected
|
||||||
|
the invite due to [invite blocking](/client-server-api/#invite-permission).
|
||||||
|
content:
|
||||||
|
application/json:
|
||||||
|
schema:
|
||||||
|
$ref: definitions/errors/error.yaml
|
||||||
tags:
|
tags:
|
||||||
- Room creation
|
- Room creation
|
||||||
servers:
|
servers:
|
||||||
|
|
|
||||||
|
|
@ -83,7 +83,7 @@ paths:
|
||||||
value: {}
|
value: {}
|
||||||
"400":
|
"400":
|
||||||
description: |-
|
description: |-
|
||||||
|
|
||||||
The request is invalid. A meaningful `errcode` and description
|
The request is invalid. A meaningful `errcode` and description
|
||||||
error text will be returned. Example reasons for rejection include:
|
error text will be returned. Example reasons for rejection include:
|
||||||
|
|
||||||
|
|
@ -99,12 +99,18 @@ paths:
|
||||||
$ref: definitions/errors/error.yaml
|
$ref: definitions/errors/error.yaml
|
||||||
"403":
|
"403":
|
||||||
description: |-
|
description: |-
|
||||||
You do not have permission to invite the user to the room. A meaningful `errcode` and description error text will be returned. Example reasons for rejections are:
|
You do not have permission to invite the user to the room. A
|
||||||
|
meaningful `errcode` and description error text will be returned.
|
||||||
|
Example reasons for rejections are:
|
||||||
|
|
||||||
- The invitee has been banned from the room.
|
- The invitee has been banned from the room.
|
||||||
- The invitee is already a member of the room.
|
- The invitee is already a member of the room.
|
||||||
- The inviter is not currently in the room.
|
- The inviter is not currently in the room.
|
||||||
- The inviter's power level is insufficient to invite users to the room.
|
- The inviter's power level is insufficient to invite users to the room.
|
||||||
|
|
||||||
|
{{% added-in v="1.18"%}} The `M_INVITE_BLOCKED` error code is used to
|
||||||
|
indicate that the homeserver rejected the invite due to
|
||||||
|
[invite blocking](/client-server-api/#invite-permission).
|
||||||
content:
|
content:
|
||||||
application/json:
|
application/json:
|
||||||
schema:
|
schema:
|
||||||
|
|
|
||||||
|
|
@ -116,7 +116,13 @@ paths:
|
||||||
"error": "The alias '#hello:example.org' does not point to this room."
|
"error": "The alias '#hello:example.org' does not point to this room."
|
||||||
}
|
}
|
||||||
"403":
|
"403":
|
||||||
description: The sender doesn't have permission to send the event into the room.
|
description: |-
|
||||||
|
The sender doesn't have permission to send the event into the room.
|
||||||
|
|
||||||
|
{{% added-in v="1.18"%}} If the `eventType` is `m.room.member` and
|
||||||
|
the `membership` is `invite`, the `M_INVITE_BLOCKED` error code is
|
||||||
|
used to indicate that the homeserver rejected the invite due to
|
||||||
|
[invite blocking](/client-server-api/#invite-permission).
|
||||||
content:
|
content:
|
||||||
application/json:
|
application/json:
|
||||||
schema:
|
schema:
|
||||||
|
|
|
||||||
|
|
@ -97,6 +97,10 @@ paths:
|
||||||
- The invitee is already a member of the room.
|
- The invitee is already a member of the room.
|
||||||
- The inviter is not currently in the room.
|
- The inviter is not currently in the room.
|
||||||
- The inviter's power level is insufficient to invite users to the room.
|
- The inviter's power level is insufficient to invite users to the room.
|
||||||
|
|
||||||
|
{{% added-in v="1.18"%}} The `M_INVITE_BLOCKED` error code is used to
|
||||||
|
indicate that the homeserver rejected the invite due to
|
||||||
|
[invite blocking](/client-server-api/#invite-permission).
|
||||||
content:
|
content:
|
||||||
application/json:
|
application/json:
|
||||||
schema:
|
schema:
|
||||||
|
|
|
||||||
|
|
@ -155,11 +155,17 @@ paths:
|
||||||
]
|
]
|
||||||
"403":
|
"403":
|
||||||
description: |-
|
description: |-
|
||||||
The invite is not allowed. This could be for a number of reasons, including:
|
The invite is not allowed.
|
||||||
|
|
||||||
|
The `M_FORBIDDEN` error code is used to indicate one of the following:
|
||||||
|
|
||||||
* The sender is not allowed to send invites to the target user/homeserver.
|
* The sender is not allowed to send invites to the target user/homeserver.
|
||||||
* The homeserver does not permit anyone to invite its users.
|
* The homeserver does not permit anyone to invite its users.
|
||||||
* The homeserver refuses to participate in the room.
|
* The homeserver refuses to participate in the room.
|
||||||
|
|
||||||
|
{{% added-in v="1.18"%}} The `M_INVITE_BLOCKED` error code is used to
|
||||||
|
indicate that the homeserver rejected the invite due to
|
||||||
|
[invite blocking](/client-server-api/#invite-permission).
|
||||||
content:
|
content:
|
||||||
application/json:
|
application/json:
|
||||||
schema:
|
schema:
|
||||||
|
|
|
||||||
|
|
@ -192,11 +192,17 @@ paths:
|
||||||
}
|
}
|
||||||
"403":
|
"403":
|
||||||
description: |-
|
description: |-
|
||||||
The invite is not allowed. This could be for a number of reasons, including:
|
The invite is not allowed.
|
||||||
|
|
||||||
|
The `M_FORBIDDEN` error code is used to indicate one of the following:
|
||||||
|
|
||||||
* The sender is not allowed to send invites to the target user/homeserver.
|
* The sender is not allowed to send invites to the target user/homeserver.
|
||||||
* The homeserver does not permit anyone to invite its users.
|
* The homeserver does not permit anyone to invite its users.
|
||||||
* The homeserver refuses to participate in the room.
|
* The homeserver refuses to participate in the room.
|
||||||
|
|
||||||
|
{{% added-in v="1.18"%}} The `M_INVITE_BLOCKED` error code is used to
|
||||||
|
indicate that the homeserver rejected the invite due to
|
||||||
|
[invite blocking](/client-server-api/#invite-permission).
|
||||||
content:
|
content:
|
||||||
application/json:
|
application/json:
|
||||||
schema:
|
schema:
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"$ref": "core/event.json",
|
||||||
|
"type": "m.invite_permission_config",
|
||||||
|
"content": {
|
||||||
|
"default_action": "block"
|
||||||
|
}
|
||||||
|
}
|
||||||
21
data/event-schemas/schema/m.invite_permission_config.yaml
Normal file
21
data/event-schemas/schema/m.invite_permission_config.yaml
Normal file
|
|
@ -0,0 +1,21 @@
|
||||||
|
---
|
||||||
|
$schema: https://json-schema.org/draft/2020-12/schema
|
||||||
|
allOf:
|
||||||
|
- $ref: core-event-schema/event.yaml
|
||||||
|
- title: Invite Permission
|
||||||
|
type: object
|
||||||
|
description: |-
|
||||||
|
The permission configuration for receiving invites for the current account.
|
||||||
|
properties:
|
||||||
|
content:
|
||||||
|
type: object
|
||||||
|
properties:
|
||||||
|
default_action:
|
||||||
|
type: string
|
||||||
|
description: |-
|
||||||
|
When set to `block`, the user does not wish to receive *any* room invites, and they
|
||||||
|
should be rejected automatically by the homeserver.
|
||||||
|
|
||||||
|
A missing, invalid or unsupported value means that the user wants to receive invites
|
||||||
|
as normal. Other parts of the specification might still have effects on invites, like
|
||||||
|
[ignoring users](/client-server-api/#ignoring-users).
|
||||||
Loading…
Reference in a new issue