MSC4140: Cancellable delayed events#4140
Conversation
Signed-off-by: Timo K <toger5@hotmail.de>
Signed-off-by: Timo K <toger5@hotmail.de>
2bc07c4 to
0eb1abc
Compare
Signed-off-by: Timo K <toger5@hotmail.de>
0eb1abc to
8bf6db7
Compare
Signed-off-by: Timo K <toger5@hotmail.de>
Signed-off-by: Timo K <toger5@hotmail.de>
3e54c2a to
c82adf7
Compare
Signed-off-by: Timo K <toger5@hotmail.de>
c82adf7 to
54fff99
Compare
…is used to trigger on of the actions Signed-off-by: Timo K <toger5@hotmail.de>
Signed-off-by: Timo K <toger5@hotmail.de>
Add event type to the body Add event id template variable
Co-authored-by: Andrew Ferrazzutti <af_0_af@hotmail.com>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
|
With the assumption that the alternative gets further information added into the MSC, this appears ready to go (though there's no comments on the M_FORBIDDEN thread 😇) @mscbot fcp merge |
|
Team member @turt2live has proposed to merge this. The next step is review by the rest of the tagged people: Once at least 75% of reviewers approve (and there are no outstanding concerns), this will enter its final comment period. If you spot a major issue that hasn't been raised at any point in this process, please speak up! See this document for information about what commands tagged team members can give me. |
|
MSCs proposed for Final Comment Period (FCP) should meet the requirements outlined in the checklist prior to being accepted into the spec. This checklist is a bit long, but aims to reduce the number of follow-on MSCs after a feature lands. SCT members: please check off things you check for, and raise a concern against FCP if the checklist is incomplete. If an item doesn't apply, prefer to check it rather than remove it. Unchecking items is encouraged where applicable. MSC authors: feel free to ask in a thread on your MSC or in the#matrix-spec:matrix.org room for clarification of any of these points.
|
| If a requested delay exceeds this maximum, the homeserver will respond with HTTP 400 | ||
| and a [standard error response](https://spec.matrix.org/v1.18/client-server-api/#standard-error-response) | ||
| with an `errcode` of `M_INVALID_PARAM`. |
There was a problem hiding this comment.
To go even further with #4140 (comment), how about returning M_FORBIDDEN & HTTP 403 even for this case of requesting a delay longer than allowed?
This would prevent needing a special case error response for delayed events being entirely disallowed, as both that case & this one would then both give the same response.
It also looks like the spec uses M_INVALID_PARAM only for parameter values that are always invalid (like a malformed room alias or MXID), as opposed to values that are disallowed by server config that may change later.
There was a problem hiding this comment.
Erm, actually, the special case would still be needed for when the maximum per-user amount of delayed events is 0, lest the response would be M_LIMIT_EXCEEDED & HTTP 429 for a limit that can never be satisfied.
But the point stands about M_FORBIDDEN & HTTP 403 potentially being more appropriate than M_INVALID_PARAM / HTTP 400.
There was a problem hiding this comment.
But the point stands about
M_FORBIDDEN& HTTP 403 potentially being more appropriate thanM_INVALID_PARAM/ HTTP 400.
This sounds sensible to me.
Also reword the special case error response now that only the 0-limit case is special
|
|
||
| The `delay_id` is an [opaque identifier](https://spec.matrix.org/v1.18/appendices/#opaque-identifiers) | ||
| generated by the homeserver. | ||
| It MUST be globally unique and SHOULD be cryptographically secure (in the sense that it is infeasible to predict). |
There was a problem hiding this comment.
There's a mismatch here with the wording in the Security considerations – Authentication section below, which says
As such, generated
delay_ids MUST be cryptographically random such that they are difficult to guess.
-
"cryptographically random" vs. "cryptographically secure" – I think a more accurate and unambiguous wording in both places would be something like
generated using a CSPRNG (Cryptographically Secure Pseudorandom Number Generator) and has sufficient entropy
-
MUST vs. SHOULD – I would change the SHOULD here to MUST, because that's what the authentication for these endpoints through knowledge of
delay_idrelies on.
There was a problem hiding this comment.
A bit later, "the cryptographic security of the delay_id" is mentioned again, which reads a bit weird to me. Alternatives that would sound better to me are for example
- the CSPRNG-generated
delay_id, or - the cryptographic randomness of the
delay_id, or - the unpredictability of the
delay_id.
There was a problem hiding this comment.
A bit later, "the cryptographic security of the
delay_id" is mentioned again, which reads a bit weird to me. Alternatives that would sound better to me are for example* the CSPRNG-generated `delay_id`, or * the cryptographic randomness of the `delay_id`, or * the unpredictability of the `delay_id`.
This part was resolved in 5dac49c. The original comment above is still open though.
| However, this is not strictly necessary for delayed events to be usable, and may thus be discussed in a separate MSC | ||
| in the interest of keeping this MSC focused on the core functionality of delayed events. | ||
|
|
||
| ## Security considerations |
There was a problem hiding this comment.
An aspect I'm missing here is the fact that the POST /delayed_events/{delay_id}/{action} and GET /_matrix/client/v1/delayed_events/{delay_id} endpoints are including the delay_id, which is aptly described to "behave as a scoped access token". This risks a delay_id, i.e. an access token, getting leaked to various logs.
Can this risk be avoided / reduced by putting the delay_id in a header field or the request body instead? If there's technical reasons to not do that, this should at least be mentioned in the Security Considerations.
There was a problem hiding this comment.
I suspect the main reason is that in the path in makes for a very natural REST API shape.
I think putting it into the body would require changing GET /_matrix/client/v1/delayed_events/{delay_id} to POST. It's not as nice an API but would probably work.
As a header, we could leave the HTTP method unchanged. The API shape strikes me as equally odd but technically it should also be possible.
@AndrewFerr curious what you think? Have I missed any reasons why this needs to be in the path?
There was a problem hiding this comment.
Yes, the main reason is to be able to use the delay_id as a typical "identifier" token.
Besides, there's limited effectiveness in trying to hide a delay_id by moving it into request headers / body / elsewhere, because it will nevertheless appear in client logs via /sync responses once its associated event gets sent, as per delay_id in unsigned event data.
There was a problem hiding this comment.
it will nevertheless appear in client logs via /sync responses once its associated event gets sent
But once the event gets sent, is there even a need to keep the delay_id secret any longer? Aren't all of the delay_id's access token capabilities void once the respective event is finalised?
See this part of the MSC:
If the target delayed event is already finalised with an outcome that conflicts with the action, i.e. if the action is send or restart and the delayed event has already been cancelled, or if the action is cancel and the delayed event has already been sent, the homeserver will respond with HTTP 409 and a standard error response with an errcode of M_UNKNOWN.
There was a problem hiding this comment.
But once the event gets sent, is there even a need to keep the delay_id secret any longer? Aren't all of the delay_id's access token capabilities void once the respective event is finalised?
Good point, that's correct.
In the interest of unblocking this, I'll split off the delegation feature into its own MSC. For now, I've moved it to an alternative: cd878d2
With that out of the way, I'll say that I'm still hesitant to protect delay_ids as much as access tokens, for a few reasons:
- It would preclude future endpoints from being able to use
delay_ids in ways that would "leak" them by design. A realistic possible addition is for/syncto include information about newly-scheduled delayed events (so that clients other than the one that scheduled an event would be notified of it, instead of having to manually hit the lookup endpoint to discover it). - It may add friction against migrating to using OAuth 2.0 scopes for the management endpoints.
There was a problem hiding this comment.
With the delegation removed from this MSC, and the management endpoints being authenticated, I'm obviously fine with the security considerations in this MSC 👍
I'd be interested to see the additional delegation MSC when it's ready though – especially how it plans to deal with the authentication for the management endpoints prescribed in this MSC – and I think it would be good the mention the concerns form your comment about the handling of the delay_id there.
|
|
||
| #### `delay_id` in `unsigned` event data | ||
| The `delay_id` of a sent delayed event MUST be included in the resulting room event's `unsigned` data | ||
| if, and only if, the client being given the event is authenticated as the event's sender. |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
Co-authored-by: Johannes Marbach <n0-0ne+github@mailbox.org>
Move delegation to an alternative. It is planned to be given its own MSC.
Rendered
This could also supersede MSC2228 (by making it possible to send a redaction with the
/sendendpoint. This is the case as mentioned here)Implementations
Known differences between current implementations and the proposal
M_MAX_DELAY_EXCEEDED, HTTP 400, and a response propertymax_delaywhen the server refuses to schedule an event because the requested delay is too large. The proposal has since switched to the error codeM_FORBIDDEN, HTTP 403, and publishes the maximum allowed delay in them.delayed_eventscapability (so that clients can discover it ahead of making the request)./sendand/statewith a new query parameterdelayfor scheduling delayed events. The proposal has since switched to a dedicated endpointPUT /_matrix/client/v3/rooms/{roomId}/delayed_event/{eventType}/{txnId}where the delay is included in the request body./versionskey would be required to manage the migration from the previous unstable implementation.delayandmax_delayrather thandelay_msandmax_delay_ms.running_sincerather thanscheduled_at.delay_id-based authentication on the management endpoints, rather than expecting standard authentication with a user access token.Implementations in Element Call via the Widget API
These are only informational and shouldn't be relevant for the proposal process. The MSC doesn't depend on widgets and widgets are themselves not part of the spec.
SCT stuff:
MSC checklist
FCP tickyboxes
Designated reviewers: