Additional notes on security considerations

toger5/expiring-events-keep-alive
Hugh Nimmo-Smith 1 year ago
parent 677d6f3d33
commit 4caecd1928

@ -585,8 +585,13 @@ The following alternative names for this concept are considered
## Security considerations ## Security considerations
All new endpoints are authenticated.
Servers SHOULD impose a maximum timeout value for future timeouts of not more than a month. Servers SHOULD impose a maximum timeout value for future timeouts of not more than a month.
As described [above](#power-levels-are-evaluated-at-the-point-of-sending), the homeserver MUST evaluate and enforce the
power levels at the time of the delayed event being sent (i.e. added to the DAG).
## Unstable prefix ## Unstable prefix
Whilst the MSC is in the proposal stage, the following should be used: Whilst the MSC is in the proposal stage, the following should be used:

Loading…
Cancel
Save