Merge pull request #1591 from matrix-org/erikj/fixup_auth_rules

Fix up auth rules
erikj/spec_3pid_ruls^2
Erik Johnston 6 years ago committed by GitHub
commit 0adfd1ebb0
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -372,26 +372,45 @@ the state of the room.
The rules are as follows: The rules are as follows:
1. If type is ``m.room.create``, allow if and only if it has no 1. If type is ``m.room.create``:
previous events - *i.e.* it is the first event in the room.
2. If type is ``m.room.member``: a. If it has any previous events, reject.
b. If the domain of the ``room_id`` does not match the domain of the
``sender``, reject.
c. If ``content.room_version`` is present and is not a recognised version,
reject.
d. If ``content`` has no ``creator`` field, reject.
e. Otherwise, allow.
#. If event does not have a ``m.room.create`` in its ``auth_events``, reject.
#. If type is ``m.room.aliases``:
a. If event has no ``state_key``, reject.
b. If sender's domain doesn't matches ``state_key``, reject.
c. Otherwise, allow.
#. If type is ``m.room.member``:
a. If ``membership`` is ``join``: a. If no ``state_key`` key or ``membership`` key in ``content``, reject.
#. If ``membership`` is ``join``:
i. If the only previous event is an ``m.room.create`` i. If the only previous event is an ``m.room.create``
and the ``state_key`` is the creator, allow. and the ``state_key`` is the creator, allow.
#. If the ``sender`` does not match ``state_key``, reject. #. If the ``sender`` does not match ``state_key``, reject.
#. If the user's current membership state is ``invite`` or ``join``, #. If the ``sender`` is banned, reject.
allow.
#. If the ``join_rule`` is ``invite`` then allow if membership state
is ``invite`` or ``join``.
#. If the ``join_rule`` is ``public``, allow. #. If the ``join_rule`` is ``public``, allow.
#. Otherwise, reject. #. Otherwise, reject.
b. If ``membership`` is ``invite``: #. If ``membership`` is ``invite``:
i. If the ``sender``'s current membership state is not ``join``, reject. i. If the ``sender``'s current membership state is not ``join``, reject.
@ -403,7 +422,7 @@ The rules are as follows:
#. Otherwise, reject. #. Otherwise, reject.
c. If ``membership`` is ``leave``: #. If ``membership`` is ``leave``:
i. If the ``sender`` matches ``state_key``, allow if and only if that user's i. If the ``sender`` matches ``state_key``, allow if and only if that user's
current membership state is ``invite`` or ``join``. current membership state is ``invite`` or ``join``.
@ -419,7 +438,7 @@ The rules are as follows:
#. Otherwise, reject. #. Otherwise, reject.
d. If ``membership`` is ``ban``: #. If ``membership`` is ``ban``:
i. If the ``sender``'s current membership state is not ``join``, reject. i. If the ``sender``'s current membership state is not ``join``, reject.
@ -429,18 +448,25 @@ The rules are as follows:
#. Otherwise, reject. #. Otherwise, reject.
e. Otherwise, the membership is unknown. Reject. #. Otherwise, the membership is unknown. Reject.
3. If the ``sender``'s current membership state is not ``join``, reject. #. If the ``sender``'s current membership state is not ``join``, reject.
4. If the event type's *required power level* is greater than the ``sender``'s power #. If the event type's *required power level* is greater than the ``sender``'s power
level, reject. level, reject.
5. If type is ``m.room.power_levels``: #. If the event has a ``state_key`` that starts with an ``@`` and does not match
the ``sender``, reject.
#. If type is ``m.room.power_levels``:
a. If ``users`` key in ``content`` is not a dictionary with keys that are
valid user IDs with values that are integers (or a string that is an
integer), reject.
a. If there is no previous ``m.room.power_levels`` event in the room, allow. #. If there is no previous ``m.room.power_levels`` event in the room, allow.
b. For each of the keys ``users_default``, ``events_default``, #. For each of the keys ``users_default``, ``events_default``,
``state_default``, ``ban``, ``redact``, ``kick``, ``invite``, as well as ``state_default``, ``ban``, ``redact``, ``kick``, ``invite``, as well as
each entry being changed under the ``events`` or ``users`` keys: each entry being changed under the ``events`` or ``users`` keys:
@ -450,25 +476,25 @@ The rules are as follows:
#. If the new value is higher than the ``sender``'s current power level, #. If the new value is higher than the ``sender``'s current power level,
reject. reject.
c. For each entry being changed under the ``users`` key, other than the #. For each entry being changed under the ``users`` key, other than the
``sender``'s own entry: ``sender``'s own entry:
i. If the current value is equal to the ``sender``'s current power level, i. If the current value is equal to the ``sender``'s current power level,
reject. reject.
d. Otherwise, allow. #. Otherwise, allow.
6. If type is ``m.room.redaction``: #. If type is ``m.room.redaction``:
a. If the ``sender``'s power level is greater than or equal to the *redact a. If the ``sender``'s power level is greater than or equal to the *redact
level*, allow. level*, allow.
#. If the ``sender`` of the event being redacted is the same as the #. If the domain of the ``event_id`` of the event being redacted is the same
``sender`` of the ``m.room.redaction``, allow. as the domain of the ``event_id`` of the ``m.room.redaction``, allow.
#. Otherwise, reject. #. Otherwise, reject.
7. Otherwise, allow. #. Otherwise, allow.
.. NOTE:: .. NOTE::

Loading…
Cancel
Save