fix: Remove non-compliant and non-functional non-authoritative directory queries #1393
Labels
No labels
Blocked
Bug
Cherry-picking
Database
Dependencies
Dependencies/Renovate
Difficulty
Easy
Difficulty
Hard
Difficulty
Medium
Documentation
Enhancement
Good first issue
Help wanted
Inherited
Matrix/Administration
Matrix/Appservices
Matrix/Auth
Matrix/Client
Matrix/Core
Matrix/E2EE
Matrix/Federation
Matrix/Hydra
Matrix/MSC
Matrix/Media
Matrix/T&S
Meta
Meta/CI
Meta/Packaging
Priority
Blocking
Priority
High
Priority
Low
Security
Status
Confirmed
Status
Duplicate
Status
Invalid
Status
Needs Investigation
Support
To-Merge
Wont fix
old/ci/cd
old/rust
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
continuwuation/continuwuity!1393
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "nex/fix/remote-aliases"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Currently there's behaviour that the spec explicitly forbids where continuwuity will query non-authoritative homeservers (i.e. servers other than the one in the alias) to resolve remote room aliases. All complaint homeservers receiving these bad requests will correctly refuse to respond with anything of use, making these additional lookups at best pointless, or at worse opens us up to a spoofing attack.
This pull request removes this behaviour completely. It also ensures only non-stale resident servers are returned, for fun (and performance).
Pull request checklist:
mainbranch, and the branch is named something other thanmain.myself, if applicable. This includes ensuring code compiles.
Good for review, had this deployed since I pushed it (same for @Aranjedeath) and no complaints so far. I'll attach a news fragment later
655c3054e22d634a5ad02d634a5ad031e2195e56