feat: Allow room moderators to view redacted event content (MSC2815) #2245

Open
eleboucher wants to merge 2 commits from eleboucher/continuwuity:feat/msc2815-unredacted-content into main
Contributor

This pull request...

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
<!-- In order to help reviewers know what your pull request does at a glance, you should ensure that 1. Your PR title is a short, single sentence describing what you changed 2. You have described in more detail what you have changed, why you have changed it, what the intended effect is, and why you think this will be beneficial to the project. If you have made any potentially strange/questionable design choices, but didn't feel they'd benefit from code comments, please don't mention them here - after opening your pull request, go to "files changed", and click on the "+" symbol in the line number gutter, and attach comments to the lines that you think would benefit from some clarification. --> This pull request... <!-- Example: This pull request allows us to warp through time and space ten times faster than before by double-inverting the warp drive with hyperheated jump fluid, both making the drive faster and more efficient. This resolves the common issue where we have to wait more than 10 milliseconds to engage, use, and disengage the warp drive when travelling between galaxies. --> <!-- Closes: #... --> <!-- Fixes: #... --> <!-- Uncomment the above line(s) if your pull request fixes an issue or closes another pull request by superseding it. Replace `#...` with the issue/pr number, such as `#123`. --> **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [x] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages
feat: Allow room moderators to view redacted event content (MSC2815)
All checks were successful
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 3s
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 8s
Checks / Prek / Check changed files (pull_request) Successful in 8s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m38s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m35s
e2a5936a05
nex requested changes 2026-09-13 18:19:23 +00:00
@ -0,0 +1 @@
Added [MSC2815](https://github.com/matrix-org/matrix-spec-proposals/pull/2815), letting room moderators fetch the content of redacted events, behind the `allow_moderators_to_view_redacted_content` config option. Contributed by @eleboucher.
Owner
- Added [MSC2815](https://github.com/matrix-org/matrix-spec-proposals/pull/2815), letting room moderators fetch the content of redacted events, behind the `allow_moderators_to_view_redacted_content` config option. Contributed by @eleboucher. 
+ Added support for [MSC2815](https://github.com/matrix-org/matrix-spec-proposals/pull/2815), allowing room moderators to fetch the original content of redacted events, behind the `allow_moderators_to_view_redacted_content` config option. Contributed by @eleboucher. 
```diff - Added [MSC2815](https://github.com/matrix-org/matrix-spec-proposals/pull/2815), letting room moderators fetch the content of redacted events, behind the `allow_moderators_to_view_redacted_content` config option. Contributed by @eleboucher. + Added support for [MSC2815](https://github.com/matrix-org/matrix-spec-proposals/pull/2815), allowing room moderators to fetch the original content of redacted events, behind the `allow_moderators_to_view_redacted_content` config option. Contributed by @eleboucher. ```
eleboucher marked this conversation as resolved
@ -8,0 +14,4 @@
#[derive(Deserialize)]
pub(crate) struct Msc2815Params {
#[serde(rename = "fi.mau.msc2815.include_unredacted_content", default)]
include_unredacted_content: Option<String>,
Owner

Some reason not to Option<bool>?

Some reason not to `Option<bool>`?
eleboucher marked this conversation as resolved
@ -50,0 +101,4 @@
Ok(())
}
fn content_unavailable() -> Error {
Owner

This should probably just be inlined? I only see one callsite

This should probably just be inlined? I only see one callsite
eleboucher marked this conversation as resolved
@ -1701,0 +1707,4 @@
///
/// default: false
#[serde(default)]
pub allow_moderators_to_view_redacted_content: bool,
Owner

There's going to need to be a way to define a lifetime for unredacted content before it is truly deleted from the db (maybe a default of 90d?), otherwise people will complain the server doesn't respect redactions at all, and also that it'll cause abusive content to remain in the db forever. A purge task will also probably be necessary instead of just deleting when the expired entry is requested, since they may never be requested

There's going to need to be a way to define a lifetime for unredacted content before it is truly deleted from the db (maybe a default of 90d?), otherwise people will complain the server doesn't respect redactions at all, and also that it'll cause abusive content to remain in the db forever. A purge task will also probably be necessary instead of just deleting when the expired entry is requested, since they may never be requested
Author
Contributor

done boss

done boss
feat: Expire retained unredacted content and address review
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 15s
Checks / Prek / Check changed files (pull_request) Successful in 8s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m35s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
0a1eddb1b6
eleboucher force-pushed feat/msc2815-unredacted-content from 0a1eddb1b6
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 15s
Checks / Prek / Check changed files (pull_request) Successful in 8s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m35s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 04862cb54e
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Has been cancelled
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2026-09-13 18:58:03 +00:00
Compare
eleboucher force-pushed feat/msc2815-unredacted-content from 04862cb54e
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Has been cancelled
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to e9cfb8c11b
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 9s
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m40s
Checks / Prek / Check changed files (pull_request) Successful in 12s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m30s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m45s
2026-09-13 19:00:16 +00:00
Compare
eleboucher requested review from nex 2026-09-13 19:00:58 +00:00
Owner

The reason why I didn't merge it when I did this before is because I wanted to avoid doing a redundant move of the data into a new column and instead handle redactions as relations, doing the redaction of retained events on access.

The reason why I didn't merge it when I did this [before](https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/jade/msc2815) is because I wanted to avoid doing a redundant move of the data into a new column and instead handle redactions as relations, doing the redaction of retained events on access.
Author
Contributor

@Jade wrote in #2245 (comment):

The reason why I didn't merge it when I did this before is because I wanted to avoid doing a redundant move of the data into a new column and instead handle redactions as relations, doing the redaction of retained events on access.

Tulir told me to do it so i did, i didn't look or anything but just respect orders

@Jade wrote in https://forgejo.ellis.link/continuwuation/continuwuity/pulls/2245#issuecomment-35567: > The reason why I didn't merge it when I did this [before](https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/jade/msc2815) is because I wanted to avoid doing a redundant move of the data into a new column and instead handle redactions as relations, doing the redaction of retained events on access. Tulir told me to do it so i did, i didn't look or anything but just respect orders
Owner

@Jade wrote in #2245 (comment):

The reason why I didn't merge it when I did this before is because I wanted to avoid doing a redundant move of the data into a new column and instead handle redactions as relations, doing the redaction of retained events on access.

tbh I think that can just be a future improvement, that's a significantly more complex thing than this is, and I'm quite happy to get a cheap win. It's not like this is too hot of a path anyway

@Jade wrote in https://forgejo.ellis.link/continuwuation/continuwuity/pulls/2245#issuecomment-35567: > The reason why I didn't merge it when I did this [before](https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/jade/msc2815) is because I wanted to avoid doing a redundant move of the data into a new column and instead handle redactions as relations, doing the redaction of retained events on access. tbh I think that can just be a future improvement, that's a significantly more complex thing than this is, and I'm quite happy to get a cheap win. It's not like this is too hot of a path anyway
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 9s
Required
Details
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m40s
Required
Details
Checks / Prek / Check changed files (pull_request) Successful in 12s
Required
Details
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m30s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m45s
Required
Details
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u feat/msc2815-unredacted-content:eleboucher-feat/msc2815-unredacted-content
git switch eleboucher-feat/msc2815-unredacted-content
Sign in to join this conversation.
No reviewers
nex
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!2245
No description provided.