Skip to content

MSC4140: assert delayed event management is authenticated and owner-scoped - #935

Draft
barodeur wants to merge 2 commits into
matrix-org:mainfrom
barodeur:msc4140-authenticated-assertions
Draft

barodeur wants to merge 2 commits into
matrix-org:mainfrom
barodeur:msc4140-authenticated-assertions

Conversation

@barodeur

@barodeur barodeur commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Note

This PR should be merged after element-hq/synapse#20257

This is a follow-up to #924, and a sister PR to element-hq/synapse#20257

Delayed Event (MSC4140) management endpoints should be authenticated, and scoped to the user who scheduled the delayed event.

This PR adds two tests for cancel, restart and send:

  • without an access token, they answer 401 M_MISSING_TOKEN, and the delayed event stays scheduled
  • with another user's access token, they answer 404 M_NOT_FOUND, and the delayed event stays scheduled

It is stacked on #924 should be reviewed with barodeur/complement@msc4140-authenticated-management...msc4140-authenticated-assertions

Signed-off-by: Paul Chobert paul@chobert.fr

MSC4140 describes the delayed event management endpoints
(POST /delayed_events/{delay_id}/{cancel,restart,send}) as authenticated,
and scopes them to the requesting user. Make every management call on
a real delay ID, and the negative tests on an unknown delay ID, go
through the user who scheduled the event instead of the unauthenticated
client.

The only unauthenticated call left is the one asserting that the bulk
GET answers 401 without a token.

Signed-off-by: Paul Chobert <paul@chobert.fr>
…coped

Per MSC4140, the management endpoints are authenticated, and a delay ID
that does not belong to the requesting user is answered with 404
M_NOT_FOUND. Add two tests:

- without a token, each of cancel, restart and send answers 401, and the
  delayed event stays scheduled;
- another user gets 404 for each action on someone else's delay ID, and
  the delayed event still fires on its original timeout.

These need a homeserver that enforces both rules.

Signed-off-by: Paul Chobert <paul@chobert.fr>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant