Compare commits

...

12 commits
v1.19 ... main

Author SHA1 Message Date
gewitternacht d0ba2aaef8
improve event format description of m.room.encrypted events (#2413)
Some checks failed
Spec / 🔎 Validate OpenAPI specifications (push) Has been cancelled
Spec / 🔎 Check Event schema examples (push) Has been cancelled
Spec / 🔎 Check OpenAPI definitions examples (push) Has been cancelled
Spec / 🔎 Check JSON Schemas inline examples (push) Has been cancelled
Spec / ⚙️ Calculate baseURL for later jobs (push) Has been cancelled
Spec / 📢 Run towncrier for changelog (push) Has been cancelled
Spell Check / Spell Check with Typos (push) Has been cancelled
Spec / 🐍 Build OpenAPI definitions (push) Has been cancelled
Spec / 📖 Build the spec (push) Has been cancelled
Spec / 🔎 Validate generated HTML (push) Has been cancelled
Spec / 📖 Build the historical backup spec (push) Has been cancelled
Spec / Create release (push) Has been cancelled
Signed-off-by: Johanna Stuber <johannas@element.io>
Co-authored-by: Richard van der Hoff <1389908+richvdh@users.noreply.github.com>
2026-07-21 21:42:20 +01:00
No. 3265c38d59
Fix logic error in validation of incoming olm-encrypted messages (#2394)
* Fix logic error in validation of incoming olm-encrypted messages

Signed-off-by: tusooa <tusooa@kazv.moe>
Co-authored-by: Richard van der Hoff <1389908+richvdh@users.noreply.github.com>
2026-07-21 21:38:44 +01:00
Patrick Cloke a0de71c500
Spec for MSC4127: Removal of query string auth (#2408)
Signed-off-by: Patrick Cloke <clokep@patrick.cloke.us>
2026-07-21 21:38:05 +01:00
networkException 4c2bb5aae1
Clarify user avatar_urls to always use MXC URIs (#2422)
Some checks failed
Spec / 🔎 Validate OpenAPI specifications (push) Has been cancelled
Spec / 🔎 Check Event schema examples (push) Has been cancelled
Spec / 🔎 Check OpenAPI definitions examples (push) Has been cancelled
Spec / 🔎 Check JSON Schemas inline examples (push) Has been cancelled
Spec / ⚙️ Calculate baseURL for later jobs (push) Has been cancelled
Spec / 📢 Run towncrier for changelog (push) Has been cancelled
Spell Check / Spell Check with Typos (push) Has been cancelled
Spec / 🐍 Build OpenAPI definitions (push) Has been cancelled
Spec / 📖 Build the spec (push) Has been cancelled
Spec / 🔎 Validate generated HTML (push) Has been cancelled
Spec / 📖 Build the historical backup spec (push) Has been cancelled
Spec / Create release (push) Has been cancelled
Previously the spec would use a mix of `string`, `URI`
and `MXC URI` for values of a user's `avatar_url` in
different apis (like `m.room.member`, `m.presence`,
CS profile endpoints).

This clarification updates all occurances to be MXC URIs,
prompted by https URIs `m.room.member#avatar_url` events
in the wild.

Signed-off-by: networkException <git@nwex.de>
2026-07-17 13:27:19 +02:00
gewitternacht f9dec5dc92
Fix typesetting of symbols in Olm/Megolm spec (#2421)
Some checks are pending
Spec / 🔎 Validate OpenAPI specifications (push) Waiting to run
Spec / 🔎 Check Event schema examples (push) Waiting to run
Spec / 🔎 Check OpenAPI definitions examples (push) Waiting to run
Spec / 🔎 Check JSON Schemas inline examples (push) Waiting to run
Spec / ⚙️ Calculate baseURL for later jobs (push) Waiting to run
Spec / 🐍 Build OpenAPI definitions (push) Blocked by required conditions
Spec / 📢 Run towncrier for changelog (push) Waiting to run
Spec / 📖 Build the spec (push) Blocked by required conditions
Spec / 🔎 Validate generated HTML (push) Blocked by required conditions
Spec / 📖 Build the historical backup spec (push) Blocked by required conditions
Spec / Create release (push) Blocked by required conditions
Spell Check / Spell Check with Typos (push) Waiting to run
* properly typeset symbols in Olm/Megolm message format tables

Signed-off-by: Johanna Stuber <johannas@element.io>

* use \mathit in Olm spec analogously to Megolm spec

Signed-off-by: Johanna Stuber <johannas@element.io>

* add newsfragment

Signed-off-by: Johanna Stuber <johannas@element.io>

* fix typo

Signed-off-by: Johanna Stuber <johannas@element.io>

---------

Signed-off-by: Johanna Stuber <johannas@element.io>
2026-07-16 11:55:30 -04:00
Johannes Marbach 16b04f9d6c
Add further normative language in mutual rooms server behaviour (#2407)
* Add further normative language in mutual rooms server behaviour

Signed-off-by: Johannes Marbach <n0-0ne+github@mailbox.org>

* Avoid superfluous MUST

Co-authored-by: Hubert Chathi <hubertc@matrix.org>

---------

Signed-off-by: Johannes Marbach <n0-0ne+github@mailbox.org>
Co-authored-by: Hubert Chathi <hubertc@matrix.org>
2026-07-16 11:18:09 -04:00
Kim Brose 966109da49
Clarify that clients must avoid producing ambiguous matrix.to URIs (#2396)
Some checks are pending
Spec / 🔎 Validate OpenAPI specifications (push) Waiting to run
Spec / 🔎 Check Event schema examples (push) Waiting to run
Spec / 🔎 Check OpenAPI definitions examples (push) Waiting to run
Spec / 🔎 Check JSON Schemas inline examples (push) Waiting to run
Spec / ⚙️ Calculate baseURL for later jobs (push) Waiting to run
Spec / 🐍 Build OpenAPI definitions (push) Blocked by required conditions
Spec / 📢 Run towncrier for changelog (push) Waiting to run
Spec / 📖 Build the spec (push) Blocked by required conditions
Spec / 🔎 Validate generated HTML (push) Blocked by required conditions
Spec / 📖 Build the historical backup spec (push) Blocked by required conditions
Spec / Create release (push) Blocked by required conditions
Spell Check / Spell Check with Typos (push) Waiting to run
2026-07-15 17:43:19 +00:00
gewitternacht e2b879d13d
Rename OlmPayload -> OlmPlaintext to avoid confusion with Olm message Payload Bytes (#2418)
Some checks are pending
Spec / 🔎 Validate OpenAPI specifications (push) Waiting to run
Spec / 🔎 Check Event schema examples (push) Waiting to run
Spec / 🔎 Check OpenAPI definitions examples (push) Waiting to run
Spec / 🔎 Check JSON Schemas inline examples (push) Waiting to run
Spec / ⚙️ Calculate baseURL for later jobs (push) Waiting to run
Spec / 🐍 Build OpenAPI definitions (push) Blocked by required conditions
Spec / 📢 Run towncrier for changelog (push) Waiting to run
Spec / 📖 Build the spec (push) Blocked by required conditions
Spec / 🔎 Validate generated HTML (push) Blocked by required conditions
Spec / 📖 Build the historical backup spec (push) Blocked by required conditions
Spec / Create release (push) Blocked by required conditions
Spell Check / Spell Check with Typos (push) Waiting to run
Signed-off-by: Johanna Stuber <johannas@element.io>
2026-07-15 10:41:01 +01:00
gewitternacht bf5fbc9945
use User ID type in OlmPayload and DeviceKeys (#2412)
Some checks are pending
Spec / 🔎 Validate OpenAPI specifications (push) Waiting to run
Spec / 🔎 Check Event schema examples (push) Waiting to run
Spec / 🔎 Check OpenAPI definitions examples (push) Waiting to run
Spec / 🔎 Check JSON Schemas inline examples (push) Waiting to run
Spec / ⚙️ Calculate baseURL for later jobs (push) Waiting to run
Spec / 🐍 Build OpenAPI definitions (push) Blocked by required conditions
Spec / 📢 Run towncrier for changelog (push) Waiting to run
Spec / 📖 Build the spec (push) Blocked by required conditions
Spec / 🔎 Validate generated HTML (push) Blocked by required conditions
Spec / 📖 Build the historical backup spec (push) Blocked by required conditions
Spec / Create release (push) Blocked by required conditions
Spell Check / Spell Check with Typos (push) Waiting to run
* use User ID type in OlmPayload and DeviceKeys

Signed-off-by: Johanna Stuber <johannas@element.io>

* add newsfragment

Signed-off-by: Johanna Stuber <johannas@element.io>

---------

Signed-off-by: Johanna Stuber <johannas@element.io>
2026-07-14 18:42:07 -04:00
Hagen 1edf62c3f1
Spec for MSC4402: Consistent redirects for .well-known-files (#2404)
* Spec for MSC4402: Consistent redirects for .well-known-files

Signed-off-by: Hagen Echzell <hagene@uio.no>

* Add changelog file

Signed-off-by: Hagen Echzell <hagene@uio.no>

* Indicate spec version for changes

Signed-off-by: Hagen Echzell <hagene@uio.no>

* Capitalize some `should`s

Signed-off-by: Hagen Echzell <hagene@uio.no>

* Increment added-in spec version after release of 1.19

Signed-off-by: Hagen Echzell <hagene@uio.no>

---------

Signed-off-by: Hagen Echzell <hagene@uio.no>
2026-07-14 18:28:49 -04:00
Kim Brose 97fcfd93d9
Clarifications and spelling (#2417)
* remove confusing redundant clause

Signed-off-by: HarHarLinks <2803622+HarHarLinks@users.noreply.github.com>

* clarify the class of relation disallowed in threads

Signed-off-by: HarHarLinks <2803622+HarHarLinks@users.noreply.github.com>

* spelling

Signed-off-by: HarHarLinks <2803622+HarHarLinks@users.noreply.github.com>

* add newsfragment

Signed-off-by: HarHarLinks <2803622+HarHarLinks@users.noreply.github.com>

---------

Signed-off-by: HarHarLinks <2803622+HarHarLinks@users.noreply.github.com>
2026-07-14 18:05:35 -04:00
Travis Ralston 68994d7fcd Become unstable
Some checks failed
Spec / 🔎 Validate OpenAPI specifications (push) Has been cancelled
Spec / 🔎 Check Event schema examples (push) Has been cancelled
Spec / 🔎 Check OpenAPI definitions examples (push) Has been cancelled
Spec / 🔎 Check JSON Schemas inline examples (push) Has been cancelled
Spec / ⚙️ Calculate baseURL for later jobs (push) Has been cancelled
Spec / 📢 Run towncrier for changelog (push) Has been cancelled
Spell Check / Spell Check with Typos (push) Has been cancelled
Spec / 🐍 Build OpenAPI definitions (push) Has been cancelled
Spec / 📖 Build the spec (push) Has been cancelled
Spec / 🔎 Validate generated HTML (push) Has been cancelled
Spec / 📖 Build the historical backup spec (push) Has been cancelled
Spec / Create release (push) Has been cancelled
2026-07-08 08:28:42 -06:00
102 changed files with 108 additions and 405 deletions

View file

@ -0,0 +1 @@
Clarify that clients must avoid producing ambiguous matrix.to URIs. Contributed by @HarHarLinks.

View file

@ -0,0 +1 @@
Correct some errors in the description of the validation process for incoming Olm-encrypted messages.

View file

@ -0,0 +1 @@
Clients are now supposed to follow 30x redirects from `/.well-known/matrix/client` as per [MSC4402](https://github.com/matrix-org/matrix-spec-proposals/pull/4402).

View file

@ -0,0 +1 @@
Add further normative language in mutual rooms server behaviour.

View file

@ -0,0 +1 @@
Providing access tokens via query string parameters is no longer supported.

View file

@ -0,0 +1 @@
Use the User ID type in OlmPayload and DeviceKeys.

View file

@ -0,0 +1 @@
Improve the format description of `m.room.encrypted` (Olm/Megolm) events.

View file

@ -0,0 +1 @@
Wording improvements and spelling fixes. Contributed by @HarHarLinks.

View file

@ -0,0 +1 @@
Rename OlmPayload to OlmPlaintext to avoid confusion with Olm message Payload Bytes.

View file

@ -0,0 +1 @@
Use MXC URI type for all user `avatar_url` fields. Contributed by @networkException.

View file

@ -0,0 +1 @@
Providing access tokens via query string parameters is no longer supported.

View file

@ -0,0 +1 @@
Fix typesetting of some symbols in the Olm/Megolm spec.

View file

@ -71,13 +71,13 @@ offlineSearch = true
[params.version]
# must be one of "unstable", "current", "historical"
# this is used to decide whether to show a banner pointing to the current release
status = "stable"
status = "unstable"
# A URL pointing to the latest, stable release of the spec. To be shown in the unstable version warning banner.
current_version_url = "https://spec.matrix.org/latest"
# The following is used when status = "stable", and is displayed in various UI elements on a released version
# of the spec.
major = "1"
minor = "19"
# major = "1"
# minor = "19"
[[params.versions]]
# We must include this parameter to enable docsy's version picker in the navbar. The picker

View file

@ -887,20 +887,22 @@ https://matrix.to/#/<identifier>/<extra parameter>?<additional arguments>
The identifier may be a room ID, room alias, or user ID. The
extra parameter is only used in the case of permalinks where an event ID
is referenced. The matrix.to URI, when referenced, must always start
is referenced. The matrix.to URI, when referenced, MUST always start
with `https://matrix.to/#/` followed by the identifier.
The `<additional arguments>` and the preceding question mark are
optional and only apply in certain circumstances, documented below.
OPTIONAL and only apply in certain circumstances, documented below.
Clients should not rely on matrix.to URIs falling back to a web server
if accessed and instead should perform some sort of action within the
Clients SHOULD NOT rely on matrix.to URIs falling back to a web server
if accessed and instead SHOULD perform some sort of action within the
client. For example, if the user were to click on a matrix.to URI for a
room alias, the client may open a view for the user to participate in
room alias, the client MAY open a view for the user to participate in
the room.
The components of the matrix.to URI (`<identifier>` and
`<extra parameter>`) MUST be percent-encoded as per RFC 3986.
Failure to do so will result in downstream software misinterpreting
the links as invalid/not turning them into clickable links in UI.
Examples of matrix.to URIs are:

View file

@ -429,6 +429,7 @@ Instead, they can be reached via HTTPS on the [server name](/appendices/#server-
Servers hosting the `.well-known` JSON file SHOULD offer CORS headers,
as per the [CORS](#web-browser-clients) section in this specification.
{{% added-in v="1.20" %}} Servers SHOULD also ensure that each 30x redirect, if any, offers such CORS headers.
{{% /boxes/note %}}
The flow for auto-discovery is as follows:
@ -437,6 +438,7 @@ The flow for auto-discovery is as follows:
Matrix ID at the first colon.
2. Extract the hostname from the server name as described by the [grammar](/appendices/#server-name).
3. Make a GET request to `https://hostname/.well-known/matrix/client`.
{{% added-in v="1.20" %}} 30x redirects SHOULD be followed, however redirection loops should be avoided.
1. If the returned status code is 404, then `IGNORE`.
2. If the returned status code is not 200, or the response body is
empty, then `FAIL_PROMPT`.
@ -568,15 +570,9 @@ invalidate the access token the client must use [token revocation](#token-revoca
Access tokens may be provided via a request header, using the Authentication
Bearer scheme: `Authorization: Bearer TheTokenHere`.
Clients may alternatively provide the access token via a query string parameter:
`access_token=TheTokenHere`. This method is deprecated to prevent the access
token being leaked in access/HTTP logs and SHOULD NOT be used by clients.
Homeservers MUST support both methods.
{{% boxes/note %}}
{{% changed-in v="1.11" %}}
Sending the access token as a query string parameter is now deprecated.
{{% changed-in v="1.20" %}}
Sending the access token as a query string parameter is no longer supported.
{{% /boxes/note %}}
When credentials are required but missing or invalid, the HTTP call will
@ -3660,7 +3656,7 @@ The actual aggregation format depends on the `rel_type`.
When an event is served to the client through the APIs listed below, a
`m.relations` property is included under `unsigned` if the event has child
events which can be aggregated and point at it. The `m.relations` property is
events which can be aggregated. The `m.relations` property is
an object keyed by `rel_type` and value being the type-specific aggregated
format for that `rel_type`. This `m.relations` property is known as a "bundled
aggregation".

View file

@ -1723,28 +1723,30 @@ Devices that support Olm must include "m.olm.v1.curve25519-aes-sha2" in
their list of supported messaging algorithms, must list a Curve25519
device key, and must publish Curve25519 one-time keys.
An event encrypted using Olm has the following format:
The content of an [`m.room.encrypted`](#mroomencrypted) event using Olm has the following format:
```json
{
"type": "m.room.encrypted",
"content": {
"algorithm": "m.olm.v1.curve25519-aes-sha2",
"sender_key": "<sender_curve25519_key>",
"ciphertext": {
"<device_curve25519_key>": {
"type": 0,
"body": "<encrypted_payload_base_64>"
"body": "<base64_encoded_olm_message>"
}
}
}
}
```
`ciphertext` is a mapping from device Curve25519 key to an encrypted
payload for that device. `body` is a Base64-encoded [Olm message body](/olm-megolm/olm/#the-olm-message-format).
`type` is an integer indicating the type of the message body: 0 for the
initial [pre-key message](/olm-megolm/olm/#pre-key-messages), 1 for [normal messages](/olm-megolm/olm/#normal-messages).
Note that when the event is received from the server, it will have a `type`
(with a value of `m.room.encrypted`) and `sender` property alongside the
`content` property. In `content`, `ciphertext` is a mapping from a device
Curve25519 key to an object with a `type` and a `body`. Here, `body` is a
Base64-encoded [Olm message](/olm-megolm/olm/#the-olm-message-format), and
`type` is an integer indicating the type of the message:
0 for the initial [pre-key messages](/olm-megolm/olm/#pre-key-messages),
1 for [normal messages](/olm-megolm/olm/#normal-messages).
Olm sessions will generate messages with a type of 0 until they receive
a message. Once a session has decrypted a message it will produce
@ -1762,12 +1764,9 @@ Messages with type 1 can only be decrypted with an existing session. If
there is no matching session, the client must treat this as an invalid
message.
The plaintext payload is of the form:
The plaintext corresponding to the "Cipher-Text" in an an [Olm message](/olm-megolm/olm/#normal-messages) is of the form:
{{% definition path="api/client-server/definitions/olm_payload" %}}
The type and content of the plaintext message event are given in the
payload.
{{% definition path="api/client-server/definitions/olm_plaintext" %}}
If a client has multiple sessions established with another device, it
should use the session from which it last received and successfully
@ -1781,6 +1780,7 @@ of olm sessions maintained per device should be at least 4.
###### Validation of incoming decrypted events
{{% changed-in v="1.15" %}} Existing checks made more explicit, and checks for `sender_device_keys` added.
{{% changed-in v="1.19" %}} Corrections to some errors in the description of the verification checks.
After decrypting an incoming encrypted event, clients MUST apply the
following checks:
@ -1788,8 +1788,9 @@ following checks:
1. The `sender` property in the decrypted content must match the
`sender` of the event.
2. The `keys.ed25519` property in the decrypted content must match
the `sender_key` property in the cleartext `m.room.encrypted`
event body.
the Ed25519 identity key of the sending device. This key can be
obtained from either [`/keys/query`](#post_matrixclientv3keysquery)
or the `sender_device_keys` object (see below).
3. The `recipient` property in the decrypted content must match
the user ID of the local user.
4. The `recipient_keys.ed25519` property in the decrypted content
@ -1797,11 +1798,11 @@ following checks:
5. Where `sender_device_keys` is present in the decrypted content:
1. `sender_device_keys.user_id` must also match the `sender`
of the event.
2. `sender_device_keys.keys.ed25519:<device_id>` must also match
2. `sender_device_keys.keys.curve25519:<device_id>` must match
the `sender_key` property in the cleartext `m.room.encrypted`
event body.
3. `sender_device_keys.keys.curve25519:<device_id>` must match
the Curve25519 key used to establish the Olm session.
3. `sender_device_keys.keys.ed25519:<device_id>` must be the same
as the `keys.ed25519` property in the decrypted content.
4. The `sender_device_keys` structure must have a valid signature
from the key with ID `ed25519:<device_id>` (i.e., the sending
device's Ed25519 key).
@ -1894,23 +1895,26 @@ This uses:
Devices that support Megolm must support Olm, and include
"m.megolm.v1.aes-sha2" in their list of supported messaging algorithms.
An event encrypted using Megolm has the following format:
The content of an [`m.room.encrypted`](#mroomencrypted) event using Megolm has the following format:
```json
{
"type": "m.room.encrypted",
"content": {
"algorithm": "m.megolm.v1.aes-sha2",
"sender_key": "<sender_curve25519_key>",
"device_id": "<sender_device_id>",
"session_id": "<outbound_group_session_id>",
"ciphertext": "<encrypted_payload_base_64>"
"ciphertext": "<base64_encoded_megolm_message>"
}
}
```
Note that when the event is received from the server, it will have additional
properties alongside the `content` property, including a `type` (with a value
of `m.room.encrypted`) and a `sender` property. (See [Room event format](#room-event-format).)
The encrypted payload can contain any message event. The plaintext is of
the form:
Within `content`, `ciphertext`
is a Base64-encoded [Megolm message](/olm-megolm/megolm/#message-format),
whose plaintext body is of the form:
```json
{
@ -1920,7 +1924,7 @@ the form:
}
```
We include the room ID in the payload, because otherwise the homeserver
We include the room ID in the encrypted message, because otherwise the homeserver
would be able to change the room a message was sent in.
Clients must guard against replay attacks by keeping track of the

View file

@ -91,13 +91,13 @@ For example, a replacement for an encrypted event might look like this:
"sender_key": "<sender_curve25519_key>",
"device_id": "<sender_device_id>",
"session_id": "<outbound_group_session_id>",
"ciphertext": "<encrypted_payload_base_64>"
"ciphertext": "<base64_encoded_megolm_message>"
}
// irrelevant fields not shown
}
```
... and, once decrypted, the payload might look like this:
... and the plaintext body of the Megolm message might look like this:
```json
{

View file

@ -6,9 +6,9 @@
#### Server behaviour
The server may decide that the response to this endpoint is too large, and only return a
subset of the results. In this case, the server should populate the optional field `next_batch`
with an [opaque identifier](/appendices/#opaque-identifiers). The client may then supply
The server MAY decide that the response to this endpoint is too large, and only return a
subset of the results. In this case, the server populates the optional field `next_batch`
with an [opaque identifier](/appendices/#opaque-identifiers). The client can then supply
the identifier as the `from` query parameter in a subsequent request, along with the original
`user_id`, to fetch the next batch of responses. This will continue until the server no longer
inserts `next_batch`, meaning there are no further results.

View file

@ -191,7 +191,7 @@ Note that, as in the example above, child events of the `latest_event` should
themselves be aggregated and included under `m.relations` for that event. The
server should be careful to avoid loops, though loops are not currently
possible due to `m.thread` not being permitted to target an event with an
`m.relates_to` property.
`m.relates_to` property with a `rel_type`.
`count` is simply the number of events using `m.thread` as a `rel_type` pointing to the target event.
It does not include events sent by [ignored users](#ignoring-users).

View file

@ -167,16 +167,9 @@ requests.
Access tokens may be provided via a request header, using the
Authentication Bearer scheme: `Authorization: Bearer TheTokenHere`.
Clients may alternatively provide the access token via a query string
parameter: `access_token=TheTokenHere`. This method is deprecated to
prevent the access token being leaked in access/HTTP logs and SHOULD NOT
be used by clients.
Identity Servers MUST support both methods.
{{% boxes/note %}}
{{% changed-in v="1.11" %}}
Sending the access token as a query string parameter is now deprecated.
{{% changed-in v="1.20" %}}
Sending the access token as a query string parameter is no longer supported.
{{% /boxes/note %}}
When credentials are required but missing or invalid, the HTTP call will

View file

@ -257,8 +257,8 @@ consists of the following key-value pairs:
**Name**|**Tag**|**Type**|**Meaning**
:-----:|:-----:|:-----:|:-----:
Message-Index|0x08|Integer|The index of the ratchet, i
Cipher-Text|0x12|String|The cipher-text, Xi, of the message
Message-Index|0x08|Integer|The index of the ratchet, \(i\).
Cipher-Text|0x12|String|The cipher-text of the message, \(X_i\).
Within the payload, integers are encoded using a variable length encoding. Each
integer is encoded as a sequence of bytes with the high bit set followed by a

View file

@ -17,12 +17,12 @@ side of an \(=\) it means that the output is split.
When this document uses \(\operatorname{ECDH}\left(K_A,K_B\right)\) it means
that each party computes a Diffie-Hellman agreement using their private key
and the remote party's public key.
So party \(A\) computes \(\operatorname{ECDH}\left(K_B^{public},K_A^{private}\right)\)
and party \(B\) computes \(\operatorname{ECDH}\left(K_A^{public},K_B^{private}\right)\).
So party \(A\) computes \(\operatorname{ECDH}\left(K_B^{\mathit{public}},K_A^{\mathit{private}}\right)\)
and party \(B\) computes \(\operatorname{ECDH}\left(K_A^{\mathit{public}},K_B^{\mathit{private}}\right)\).
Where this document uses \(\operatorname{HKDF}\left(salt,IKM,info,L\right)\) it
Where this document uses \(\operatorname{HKDF}\left(\mathit{salt},\mathit{IKM},\mathit{info},L\right)\) it
refers to the [HMAC-based key derivation function][] with a salt value of
\(salt\), input key material of \(IKM\), context string \(info\),
\(\mathit{salt}\), input key material of \(\mathit{IKM}\), context string \(\mathit{info}\),
and output keying material length of \(L\) bytes.
## The Olm Algorithm
@ -226,9 +226,9 @@ significant bits are stored in the first byte.
**Name**|**Tag**|**Type**|**Meaning**
:-----:|:-----:|:-----:|:-----:
Ratchet-Key|0x0A|String|The public part of the ratchet key, Ti, of the message
Chain-Index|0x10|Integer|The chain index, j, of the message
Cipher-Text|0x22|String|The cipher-text, Xi,j, of the message
Ratchet-Key|0x0A|String|The public part of the ratchet key of the message, \(T_i\).
Chain-Index|0x10|Integer|The chain index of the message, \(j\).
Cipher-Text|0x22|String|The cipher-text of the message, \(X_{i,j}\).
The length of the MAC is determined by the authenticated encryption algorithm
being used. (Olm version 1 uses [HMAC-SHA-256][], truncated to 8 bytes). The
@ -251,9 +251,9 @@ The payload uses the same key-value format as for normal messages.
**Name**|**Tag**|**Type**|**Meaning**
:-----:|:-----:|:-----:|:-----:
One-Time-Key|0x0A|String|The public part of Bob's single-use key, Eb.
Base-Key|0x12|String|The public part of Alice's single-use key, Ea.
Identity-Key|0x1A|String|The public part of Alice's identity key, Ia.
One-Time-Key|0x0A|String|The public part of Bob's single-use key, \(E_B\).
Base-Key|0x12|String|The public part of Alice's single-use key, \(E_A\).
Identity-Key|0x1A|String|The public part of Alice's identity key, \(I_A\).
Message|0x22|String|An embedded Olm message with its own version and MAC.
## Olm Authenticated Encryption
@ -268,13 +268,13 @@ message key using [HKDF-SHA-256][] using the default salt and an info of
\[
\begin{aligned}
AES\_KEY_{i,j}\;\parallel\;HMAC\_KEY_{i,j}\;\parallel\;AES\_IV_{i,j}
\mathit{AES\_KEY}_{i,j}\;\parallel\;\mathit{HMAC\_KEY}_{i,j}\;\parallel\;\mathit{AES\_IV}_{i,j}
&= \operatorname{HKDF}\left(0,M_{i,j},\text{``OLM\_KEYS"},80\right)
\end{aligned}
\]
The plain-text is encrypted with AES-256, using the key \(AES\_KEY_{i,j}\)
and the IV \(AES\_IV_{i,j}\) to give the cipher-text, \(X_{i,j}\).
The plain-text is encrypted with AES-256, using the key \(\mathit{AES\_KEY}_{i,j}\)
and the IV \(\mathit{AES\_IV}_{i,j}\) to give the cipher-text, \(X_{i,j}\).
Then the entire message (including the Version Byte and all Payload Bytes) are
passed through [HMAC-SHA-256][]. The first 8 bytes of the MAC are appended to the message.

View file

@ -26,7 +26,6 @@ paths:
[/sync](/client-server-api/#get_matrixclientv3sync).
operationId: setAccountData
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -118,7 +117,6 @@ paths:
that set the account data.
operationId: getAccountData
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -188,7 +186,6 @@ paths:
clients in the per-room entries via [/sync](/client-server-api/#get_matrixclientv3sync).
operationId: setAccountDataPerRoom
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -288,7 +285,6 @@ paths:
visible to the user that set the account data.
operationId: getAccountDataPerRoom
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -383,7 +379,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -45,7 +45,6 @@ paths:
{{% /boxes/warning %}}
security:
- {}
- accessTokenQuery: []
- accessTokenBearer: []
operationId: deactivateAccount
requestBody:
@ -143,7 +142,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -27,7 +27,6 @@ paths:
specified in this document.
operationId: getWhoIs
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -120,7 +119,6 @@ paths:
prior to trying to do account lookups.
operationId: getAdminSuspendUser
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -208,7 +206,6 @@ paths:
prior to trying to do account lookups.
operationId: setAdminSuspendUser
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -313,7 +310,6 @@ paths:
prior to trying to do account lookups.
operationId: getAdminLockUser
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -400,7 +396,6 @@ paths:
prior to trying to do account lookups.
operationId: setAdminLockUser
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -506,7 +501,5 @@ servers:
default: /_matrix/client
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -31,7 +31,6 @@ paths:
identifiers that it will accept to reset the user's account password.
operationId: getAccount3PIDs
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -106,7 +105,6 @@ paths:
operationId: post3PIDs
deprecated: true
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -216,7 +214,6 @@ paths:
{{% /boxes/warning %}}
operationId: add3PID
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -279,7 +276,6 @@ paths:
Homeservers should track successful binds so they can be unbound later.
operationId: bind3PID
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -345,7 +341,6 @@ paths:
to determine if this endpoint is available.
operationId: delete3pidFromAccount
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -415,7 +410,6 @@ paths:
identity server instead.
operationId: unbind3pidFromAccount
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -614,7 +608,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -57,7 +57,6 @@ paths:
example: mautrix-go_1683636478256400935_123
required: true
security:
- appserviceAccessTokenQuery: []
- appserviceAccessTokenBearer: []
responses:
"200":
@ -177,7 +176,5 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
appserviceAccessTokenQuery:
$ref: definitions/security.yaml#/appserviceAccessTokenQuery
appserviceAccessTokenBearer:
$ref: definitions/security.yaml#/appserviceAccessTokenBearer

View file

@ -70,7 +70,6 @@ paths:
- visibility
required: true
security:
- appserviceAccessTokenQuery: []
- appserviceAccessTokenBearer: []
responses:
"200":
@ -98,7 +97,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
appserviceAccessTokenQuery:
$ref: definitions/security.yaml#/appserviceAccessTokenQuery
appserviceAccessTokenBearer:
$ref: definitions/security.yaml#/appserviceAccessTokenBearer

View file

@ -33,7 +33,6 @@ paths:
Delivery Network (CDN).
operationId: getContentAuthed
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/serverName'
@ -106,7 +105,6 @@ paths:
Delivery Network (CDN).
operationId: getContentOverrideNameAuthed
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/serverName'
@ -177,7 +175,6 @@ paths:
Delivery Network (CDN).
operationId: getContentThumbnailAuthed
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/serverName'
@ -353,7 +350,6 @@ paths:
{{% /boxes/note %}}
operationId: getUrlPreviewAuthed
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -432,7 +428,6 @@ paths:
{{% /boxes/note %}}
operationId: getConfigAuthed
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -472,8 +467,6 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer
parameters:

View file

@ -27,7 +27,6 @@ paths:
The caller must have the required power level in order to perform this operation.
operationId: ban
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -101,7 +100,6 @@ paths:
The caller must have the required power level in order to perform this operation.
operationId: unban
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -179,7 +177,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -24,7 +24,6 @@ paths:
and other relevant capabilities.
operationId: getCapabilities
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -218,8 +217,6 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer
schemas:

View file

@ -22,7 +22,6 @@ paths:
summary: Upload some content to the content repository.
operationId: uploadContent
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/contentType'
@ -82,7 +81,6 @@ paths:
operationId: uploadContentToMXC
x-addedInMatrixVersion: "1.7"
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/serverName'
@ -192,7 +190,6 @@ paths:
operationId: createContent
x-addedInMatrixVersion: "1.7"
security:
- accessTokenQuery: []
- accessTokenBearer: []
# empty json object
responses:
@ -579,7 +576,6 @@ paths:
being shared should also not be shared with the homeserver.
operationId: getUrlPreview
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -660,7 +656,6 @@ paths:
than is advertised by the server on this endpoint.
operationId: getConfig
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -700,8 +695,6 @@ servers:
default: /_matrix
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer
parameters:

View file

@ -80,7 +80,6 @@ paths:
x-changedInMatrixVersion:
"1.16": Added server behaviour for how the initial power levels change depending on room version.
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -304,7 +303,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -52,7 +52,6 @@ paths:
{{% /boxes/note %}}
operationId: uploadCrossSigningKeys
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -182,7 +181,6 @@ paths:
property, which contains the new signature(s) to add.
operationId: uploadCrossSigningSignatures
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -294,7 +292,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -20,6 +20,8 @@ properties:
description: |-
The ID of the user the device belongs to. Must match the user ID used
when logging in.
format: mx-user-id
pattern: "^@"
example: "@alice:example.com"
device_id:
type: string

View file

@ -14,9 +14,9 @@
type: object
title: OlmPayload
title: OlmPlaintext
description: |-
The plaintext payload of an event encrypted using Olm.
The plaintext of an event encrypted using Olm.
properties:
type:
type: string
@ -27,9 +27,13 @@ properties:
sender:
type: string
description: The user ID of the event sender.
format: mx-user-id
pattern: "^@"
recipient:
type: string
description: The user ID of the intended event recipient.
format: mx-user-id
pattern: "^@"
recipient_keys:
description: The recipient's signing keys of the encrypted event.
$ref: "#/components/schemas/SigningKeys"

View file

@ -54,7 +54,8 @@ properties:
example: true
avatar_url:
type: string
format: uri
format: mx-mxc-uri
pattern: "^mxc:\\/\\/"
description: The URL for the room's avatar, if one is set.
example: "mxc://example.org/abcdef"
join_rule:

View file

@ -11,15 +11,6 @@
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
accessTokenQuery:
type: apiKey
description: |-
**Deprecated.** The `access_token` obtained during [account registration](/client-server-api/#account-registration)
or [login](/client-server-api/#login), as a query parameter.
It can also be the `as_token` of an application service.
name: access_token
in: query
accessTokenBearer:
type: http
description: |-
@ -27,21 +18,10 @@ accessTokenBearer:
or [login](/client-server-api/#login), using the `Authorization: Bearer` header.
It can also be the `as_token` of an application service.
This is the preferred method.
scheme: bearer
appserviceAccessTokenQuery:
type: apiKey
description: |-
**Deprecated.** The `as_token` of an application service, as a query
parameter.
name: access_token
in: query
appserviceAccessTokenBearer:
type: http
description: |-
The `as_token` of an application service, using the `Authorization: Bearer`
header.
This is the preferred method.
scheme: bearer

View file

@ -22,7 +22,6 @@ paths:
description: Gets information about all devices for the current user.
operationId: getDevices
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -57,7 +56,6 @@ paths:
description: Gets information on a single device, by device id.
operationId: getDevice
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -104,7 +102,6 @@ paths:
rate limits.
operationId: updateDevice
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -179,7 +176,6 @@ paths:
{{% /boxes/warning %}}
operationId: deleteDevice
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -248,7 +244,6 @@ paths:
{{% /boxes/warning %}}
operationId: deleteDevices
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -308,7 +303,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -21,7 +21,6 @@ paths:
summary: Create a new mapping from room alias to room ID.
operationId: setRoomAlias
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -182,7 +181,6 @@ paths:
have permission to update the `m.room.canonical_alias` event.
operationId: deleteRoomAlias
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -242,7 +240,6 @@ paths:
state event.
operationId: getLocalAliases
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -327,7 +324,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -28,7 +28,6 @@ paths:
[Lazy-loading room members](/client-server-api/#lazy-loading-room-members) for more information.
operationId: getEventContext
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -155,7 +154,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -25,7 +25,6 @@ paths:
restrict which events are returned to the client.
operationId: defineFilter
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -122,7 +121,6 @@ paths:
summary: Download a filter
operationId: getFilter
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -218,7 +216,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -38,7 +38,6 @@ paths:
`m.room.member` event to the room.
operationId: inviteUser
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -147,7 +146,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -33,7 +33,6 @@ paths:
and [`/sync`](/client-server-api/#get_matrixclientv3sync) APIs.
operationId: joinRoomById
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -131,7 +130,6 @@ paths:
and [`/sync`](/client-server-api/#get_matrixclientv3sync) APIs.
operationId: joinRoom
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -245,7 +243,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -23,7 +23,6 @@ paths:
description: Creates a new backup.
operationId: postRoomKeysVersion
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -81,7 +80,6 @@ paths:
description: Get information about the latest backup version.
operationId: getRoomKeysVersionCurrent
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -157,7 +155,6 @@ paths:
description: Get information about an existing backup.
operationId: getRoomKeysVersion
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -245,7 +242,6 @@ paths:
be modified.
operationId: putRoomKeysVersion
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -348,7 +344,6 @@ paths:
as well as all key data related to the backup will be deleted.
operationId: deleteRoomKeysVersion
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -401,7 +396,6 @@ paths:
description: Store a key in the backup.
operationId: putRoomKeyBySessionId
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -469,7 +463,6 @@ paths:
description: Retrieve a key from the backup.
operationId: getRoomKeyBySessionId
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -526,7 +519,6 @@ paths:
description: Delete a key from the backup.
operationId: deleteRoomKeyBySessionId
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -584,7 +576,6 @@ paths:
description: Store several keys in the backup for a given room.
operationId: putRoomKeysByRoomId
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -657,7 +648,6 @@ paths:
description: Retrieve the keys from the backup for a given room.
operationId: getRoomKeysByRoomId
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -710,7 +700,6 @@ paths:
description: Delete the keys from the backup for a given room.
operationId: deleteRoomKeysByRoomId
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -761,7 +750,6 @@ paths:
description: Store several keys in the backup.
operationId: putRoomKeys
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -849,7 +837,6 @@ paths:
description: Retrieve the keys from the backup.
operationId: getRoomKeys
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -916,7 +903,6 @@ paths:
description: Delete the keys from the backup.
operationId: deleteRoomKeys
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -987,7 +973,5 @@ components:
- etag
- count
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -24,7 +24,6 @@ paths:
description: Publishes end-to-end encryption keys for the device.
operationId: uploadKeys
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -117,7 +116,6 @@ paths:
description: Returns the current devices and identity keys for the given users.
operationId: queryKeys
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -306,7 +304,6 @@ paths:
the same key.
operationId: claimKeys
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -405,7 +402,6 @@ paths:
identity keys, between `from` and `to`.
operationId: getKeysChanges
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -476,7 +472,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -29,7 +29,6 @@ paths:
the target member's state by making a request to `/rooms/<room id>/state/m.room.member/<user id>`.
operationId: kick
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -108,7 +107,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -38,7 +38,6 @@ paths:
[`/sync`](/client-server-api/#get_matrixclientv3sync) API.
operationId: knockRoom
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -155,7 +154,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -44,7 +44,6 @@ paths:
to see.
operationId: leaveRoom
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -105,7 +104,6 @@ paths:
before calling this API.
operationId: forgetRoom
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -161,7 +159,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -22,7 +22,6 @@ paths:
description: This API returns a list of the user's current rooms.
operationId: getJoinedRooms
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -64,7 +63,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -76,7 +76,6 @@ paths:
or a server administrator.
operationId: setRoomVisibilityOnDirectory
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -189,7 +188,6 @@ paths:
stable order is recommended.
operationId: queryPublicRooms
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -288,7 +286,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -53,7 +53,6 @@ paths:
operationId: generateLoginToken
x-addedInMatrixVersion: "1.7"
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -132,7 +131,5 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -25,7 +25,6 @@ paths:
[Device keys](/client-server-api/#device-keys) for the device are deleted alongside the device.
operationId: logout
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -54,7 +53,6 @@ paths:
this way.
operationId: logout_all
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -80,7 +78,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -27,7 +27,6 @@ paths:
[Lazy-loading room members](/client-server-api/#lazy-loading-room-members) for more information.
operationId: getRoomEvents
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -188,7 +187,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -25,7 +25,6 @@ paths:
specified `user_id`.
operationId: getMutualRooms
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -121,7 +120,5 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -24,7 +24,6 @@ paths:
user has been, or would have been notified about.
operationId: getNotifications
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -146,7 +145,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -29,7 +29,6 @@ paths:
the [migration guide](https://matrix.org/docs/guides/migrating-from-client-server-api-v-1#deprecated-endpoints).
operationId: getEvents
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -100,7 +99,6 @@ paths:
the [migration guide](https://matrix.org/docs/guides/migrating-from-client-server-api-v-1#deprecated-endpoints).
operationId: initialSync
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -329,7 +327,6 @@ paths:
or the [/rooms/{roomId}/context/{eventId}](/client-server-api/#get_matrixclientv3roomsroomidcontexteventid) API.
operationId: getOneEvent
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -373,7 +370,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -30,7 +30,6 @@ paths:
example.
operationId: requestOpenIdToken
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -92,7 +91,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -40,7 +40,6 @@ paths:
to determine if this endpoint is available.
security:
- {}
- accessTokenQuery: []
- accessTokenBearer: []
operationId: changePassword
requestBody:
@ -240,7 +239,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -34,7 +34,6 @@ paths:
yet known.
operationId: peekEvents
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -116,7 +115,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -26,7 +26,6 @@ paths:
presence state of another user.
operationId: setPresence
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -83,7 +82,6 @@ paths:
description: Get the given user's presence state.
operationId: getPresence
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -163,7 +161,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -36,7 +36,6 @@ paths:
which `keyName`s they are allowed to modify.
operationId: setProfileField
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -210,7 +209,6 @@ paths:
description: Remove a specific field from a user's profile.
operationId: deleteProfileField
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -368,7 +366,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -23,7 +23,6 @@ paths:
description: Gets all currently active pushers for the authenticated user.
operationId: getPushers
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -137,7 +136,6 @@ paths:
user is deleted.
operationId: postPusher
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -297,7 +295,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -24,7 +24,6 @@ paths:
defined is `global`.
operationId: getPushRules
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -51,7 +50,6 @@ paths:
Retrieve all push rules for this user.
operationId: getPushRulesGlobal
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -68,7 +66,6 @@ paths:
description: Retrieve a single specified push rule.
operationId: getPushRule
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -133,7 +130,6 @@ paths:
description: This endpoint removes the push rule defined in the path.
operationId: deletePushRule
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -203,7 +199,6 @@ paths:
When creating push rules, they MUST be enabled by default.
operationId: setPushRule
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -333,7 +328,6 @@ paths:
description: This endpoint gets whether the specified push rule is enabled.
operationId: isPushRuleEnabled
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -396,7 +390,6 @@ paths:
push rule.
operationId: setPushRuleEnabled
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -468,7 +461,6 @@ paths:
description: This endpoint get the actions for the specified push rule.
operationId: getPushRuleActions
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -540,7 +532,6 @@ paths:
This can be used to change the actions of builtin rules.
operationId: setPushRuleActions
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -627,7 +618,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -25,7 +25,6 @@ paths:
the read receipt's location.
operationId: setReadMarker
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -97,7 +96,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -25,7 +25,6 @@ paths:
specified.
operationId: postReceipt
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -138,7 +137,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -33,7 +33,6 @@ paths:
Server administrators may redact events sent by users on their server.
operationId: redactEvent
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -110,7 +109,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -31,7 +31,6 @@ paths:
page 1 and a `to` token from page 2 to paginate over the same range, however.
operationId: getRelatingEvents
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/roomId'
@ -89,7 +88,6 @@ paths:
page 1 and a `to` token from page 2 to paginate over the same range, however.
operationId: getRelatingEventsWithRelType
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/roomId'
@ -151,7 +149,6 @@ paths:
page 1 and a `to` token from page 2 to paginate over the same range, however.
operationId: getRelatingEventsWithRelTypeAndEventType
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- $ref: '#/components/parameters/roomId'
@ -220,8 +217,6 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer
parameters:

View file

@ -59,7 +59,6 @@ paths:
- reason
required: true
security:
- accessTokenQuery: []
- accessTokenBearer: []
x-changedInMatrixVersion:
1.18: |
@ -143,7 +142,6 @@ paths:
description: The reason the content is being reported.
required: true
security:
- accessTokenQuery: []
- accessTokenBearer: []
x-changedInMatrixVersion:
1.8: |
@ -228,7 +226,6 @@ paths:
- reason
required: true
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -277,7 +274,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -46,7 +46,6 @@ paths:
found in that direction is outside of the expected range.
operationId: getEventByTimestamp
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -141,7 +140,5 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -17,7 +17,6 @@ paths:
[migration guide](https://matrix.org/docs/guides/migrating-from-client-server-api-v-1#deprecated-endpoints).
operationId: roomInitialSync
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -182,7 +181,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -39,7 +39,6 @@ paths:
the event.
operationId: sendMessage
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -124,7 +123,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -39,7 +39,6 @@ paths:
being removed or are already present in the state event.
operationId: setRoomStateWithKey
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -153,7 +152,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -22,7 +22,6 @@ paths:
description: Upgrades the given room to a particular room version.
operationId: upgradeRoom
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -124,7 +123,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -24,7 +24,6 @@ paths:
retrieve this event e.g. by being a member in the room for this event.
operationId: getOneRoomEvent
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -83,7 +82,6 @@ paths:
taken from the state of the room when they left.
operationId: getRoomStateWithKey
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -154,7 +152,6 @@ paths:
description: Get the state events for the current state of a room.
operationId: getRoomState
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -265,7 +262,6 @@ paths:
- leave
- ban
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -318,7 +314,6 @@ paths:
format: mx-room-id
pattern: "^!"
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -340,7 +335,8 @@ paths:
description: The display name of the user this object is representing.
avatar_url:
type: string
format: uri
format: mx-mxc-uri
pattern: "^mxc:\\/\\/"
description: The avatar of the user this object is representing, as an [`mxc://`
URI](/client-server-api/#matrix-content-mxc-uris).
description: A map from user ID to a RoomMember object.
@ -374,7 +370,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -22,7 +22,6 @@ paths:
description: Performs a full text search across different categories.
operationId: search
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -238,7 +237,8 @@ paths:
title: Display name
avatar_url:
type: string
format: uri
format: mx-mxc-uri
pattern: "^mxc:\\/\\/"
title: Avatar Url
events_before:
type: array
@ -379,7 +379,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -30,7 +30,6 @@ paths:
Invalid child rooms and parent events are not covered by this endpoint.
operationId: getSpaceHierarchy
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -231,7 +230,5 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -44,7 +44,6 @@ paths:
events, alongside other state, when lazy-loading is not enabled.
operationId: sync
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -686,7 +685,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -23,7 +23,6 @@ paths:
description: List the tags set by a user on a room.
operationId: getRoomTags
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -75,7 +74,6 @@ paths:
description: Add a tag to the room.
operationId: setRoomTag
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -125,7 +123,6 @@ paths:
description: Remove a tag from the room.
operationId: deleteRoomTag
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -177,7 +174,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -25,7 +25,6 @@ paths:
required for queries against each protocol.
operationId: getProtocols
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -101,7 +100,6 @@ paths:
third-party protocol.
operationId: getProtocolMetadata
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -145,7 +143,6 @@ paths:
as reasonably possible given the network type.
operationId: queryLocationByProtocol
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -192,7 +189,6 @@ paths:
a set of user parameters.
operationId: queryUserByProtocol
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -238,7 +234,6 @@ paths:
alias.
operationId: queryLocationByAlias
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -274,7 +269,6 @@ paths:
description: Retrieve an array of third-party users from a Matrix User ID.
operationId: queryUserByID
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -318,7 +312,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -59,7 +59,6 @@ paths:
- The matrix user ID who invited them to the room
operationId: inviteBy3PID
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -133,7 +132,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -27,7 +27,6 @@ paths:
user has participated in the thread.
operationId: getThreadRoots
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -161,7 +160,5 @@ servers:
default: /_matrix/client/v1
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -24,7 +24,6 @@ paths:
client devices.
operationId: sendToDevice
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -98,7 +97,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -26,7 +26,6 @@ paths:
user has stopped typing.
operationId: setTyping
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: path
@ -101,7 +100,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -39,7 +39,6 @@ paths:
`Accept-Language` header provided in the request, if present.
operationId: searchUserDirectory
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -90,7 +89,8 @@ paths:
description: The display name of the user, if one exists.
avatar_url:
type: string
format: uri
format: mx-mxc-uri
pattern: "^mxc:\\/\\/"
example: mxc://bar.com/foo
description: The avatar url, as an [`mxc://`
URI](/client-server-api/#matrix-content-mxc-uris),
@ -132,7 +132,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -45,7 +45,6 @@ paths:
operationId: getVersions
security:
- {}
- accessTokenQuery: []
- accessTokenBearer: []
x-changedInMatrixVersion:
"1.10": |
@ -102,7 +101,5 @@ servers:
default: /_matrix/client
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -24,7 +24,6 @@ paths:
calls.
operationId: getTurnServer
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -89,7 +88,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -1,4 +1,5 @@
# Copyright 2018 New Vector Ltd
# Copyright 2026 Hagen Echzell
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
@ -20,7 +21,11 @@ paths:
get:
summary: Gets Matrix server discovery information about the domain.
description: |-
Gets discovery information about the domain. The file may include
Gets discovery information about the domain.
{{% added-in v="1.20" %}} Clients SHOULD follow 30x redirects, carefully
avoiding redirect loops, and use normal X.509 certificate validation.
The file may include
additional keys, which MUST follow the Java package naming convention,
e.g. `com.example.myapp.property`. This ensures property names are
suitably namespaced for each application and reduces the risk of

View file

@ -30,7 +30,6 @@ paths:
body.
operationId: getTokenOwner
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -115,7 +114,5 @@ servers:
default: /_matrix/client/v3
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -11,18 +11,9 @@
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
accessTokenQuery:
type: apiKey
description: |-
**Deprecated.** The `access_token` returned by a call to `/register`, as a
query parameter.
name: access_token
in: query
accessTokenBearer:
type: http
description: |-
The `access_token` returned by a call to `/register`, using the
`Authorization: Bearer` header.
This is the preferred method.
scheme: bearer

View file

@ -23,7 +23,6 @@ paths:
description: Determines if a given 3pid has been validated by a user.
operationId: getValidated3pidV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -129,7 +128,6 @@ paths:
deprecated.
operationId: bindV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -281,7 +279,6 @@ paths:
homeserver is acting on behalf of a client.
operationId: unbindV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -386,7 +383,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -58,7 +58,6 @@ paths:
request.
operationId: getAccount
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -100,7 +99,6 @@ paths:
future requests to the server.
operationId: logout
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -152,7 +150,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -40,7 +40,6 @@ paths:
deprecated.
operationId: emailRequestTokenV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -108,7 +107,6 @@ paths:
deprecated.
operationId: emailSubmitTokenPostV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -200,7 +198,6 @@ paths:
used by end-users, and so the response should be human-readable.
operationId: emailSubmitTokenGetV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -263,7 +260,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -27,7 +27,6 @@ paths:
to `store-invite`, and fetch the sender of the invite.
operationId: blindlySignStuffV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -133,7 +132,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -28,7 +28,6 @@ paths:
any of the algorithms defined in this specification.
operationId: getHashDetails
security:
- accessTokenQuery: []
- accessTokenBearer: []
responses:
"200":
@ -71,7 +70,6 @@ paths:
later in this specification.
operationId: lookupUsersV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -164,7 +162,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -40,7 +40,6 @@ paths:
deprecated.
operationId: msisdnRequestTokenV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -110,7 +109,6 @@ paths:
deprecated.
operationId: msisdnSubmitTokenPostV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -202,7 +200,6 @@ paths:
used by end-users, and so the response should be human-readable.
operationId: msisdnSubmitTokenGetV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
parameters:
- in: query
@ -264,7 +261,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -51,7 +51,6 @@ paths:
the `address` of the pending invite for display purposes.
operationId: storeInviteV2
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -235,7 +234,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -118,7 +118,6 @@ paths:
may not be accepting all terms at once.
operationId: agreeToTerms
security:
- accessTokenQuery: []
- accessTokenBearer: []
requestBody:
content:
@ -159,7 +158,5 @@ servers:
default: /_matrix/identity/v2
components:
securitySchemes:
accessTokenQuery:
$ref: definitions/security.yaml#/accessTokenQuery
accessTokenBearer:
$ref: definitions/security.yaml#/accessTokenBearer

View file

@ -172,6 +172,8 @@ paths:
example: John Doe
avatar_url:
type: string
format: mx-mxc-uri
pattern: "^mxc:\\/\\/"
description: |-
The avatar URL for the user's avatar. MUST either be omitted or set to
`null` if the user does not have an avatar set.

View file

@ -12,6 +12,8 @@
"properties": {
"avatar_url": {
"type": "string",
"format": "mx-mxc-uri",
"pattern": "^mxc:\\/\\/",
"description": "The current avatar URL for this user, if any."
},
"displayname": {

Some files were not shown because too many files have changed in this diff Show more