Skip to content

MSC4140: authenticate the delayed event management endpoints and allow guests - #20257

Draft
barodeur wants to merge 3 commits into
element-hq:developfrom
barodeur:msc4140-authenticated-management
Draft

barodeur wants to merge 3 commits into
element-hq:developfrom
barodeur:msc4140-authenticated-management

Conversation

@barodeur

@barodeur barodeur commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Note

This depends on matrix-org/complement#924

MSC4140 makes the management endpoints authenticated and scoped to the requesting user:

A set of new authenticated Client-Server API endpoints at POST /_matrix/client/v1/delayed_events/{delay_id}/{action} [...]

If no delayed event for the requesting user with the specified delay_id can be found, the homeserver will respond with HTTP 404 and a standard error response with an errcode of M_NOT_FOUND.

All delayed event related endpoints are available to guest accounts.

Today cancel, restart and send accept requests without an access token and act on any delay_id; a token, when present, only keys the ratelimiter (#19794). The two GET endpoints reject guests.

What changes

  • cancel, restart and send require an access token and answer 404 for a delay_id that belongs to another user.
  • The management ratelimiter is keyed on the user only.
  • GET /delayed_events/{delay_id} and GET /delayed_events allow guests.
  • rc_delayed_event_mgmt documentation updated accordingly.

Appservices acting for a user through ?user_id= keep working.

Pull Request Checklist

  • Pull request is based on the develop branch
  • Pull request includes a changelog file. The entry should:
    • Be a short description of your change which makes sense to users. "Fixed a bug that prevented receiving messages from other servers." instead of "Moved X method from EventStore to EventWorkerStore.".
    • Use markdown where necessary, mostly for code blocks.
    • End with either a period (.) or an exclamation mark (!).
    • Start with a capital letter.
    • Feel free to credit yourself, by adding a sentence "Contributed by @github_username." or "Contributed by [Your Name]." to the end of the entry.
  • Code style is correct (run the linters)

The `cancel`, `restart` and `send` delayed event endpoints accepted
unauthenticated requests and acted on any delayed event with a matching
`delay_id`. MSC4140 now specifies these as authenticated endpoints that
only act on the requesting user's own delayed events, returning 404
`M_NOT_FOUND` otherwise, and makes every delayed event endpoint
available to guests.

Authenticate the four management servlets (allowing guests), pass the
requester through to the handler, and scope the three store lookups to
the requester's localpart, as the single-event lookup already does. The
management ratelimiter is now always keyed on the requester, so the
source-IP fallback and its mention in the config docs are removed.

The two GET servlets also allow guests now.
…cated-management

# Conflicts:
#	tests/rest/client/test_delayed_events.py

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant