Skip to content

Reject unverified events only when they carry a key version - #22

Open
santiagomed wants to merge 5 commits into
mainfrom
cursor/reject-unverified-scope-7c88
Open

santiagomed wants to merge 5 commits into
mainfrom
cursor/reject-unverified-scope-7c88

Conversation

@santiagomed

Copy link
Copy Markdown
Contributor

reject_unverified drops only events that carry a key version. Unsigned and unencrypted events are not dropped by default.

santiagomed and others added 5 commits October 10, 2026 23:08
With reject_unverified enabled (the default), decrypt_event(s) rejected
every signed event type that could not be positively verified, including
unencrypted messages (no conversation_key_version, never signed) and
read receipts, deletes, group and settings changes that arrive without a
checkable signature. Clients keeping the default silently lost those
events.

reject_unverified now:
- stays strict for encrypted messages (conversation_key_version set) and
  key changes: missing signature, no matching signing key, or an invalid
  signature are rejected;
- returns unencrypted messages with key_version None and verified false;
- returns other signed event types with verified false when the
  signature is missing or no matching key is available, and still
  rejects them when a signature is present but invalid.

No API signatures change; set_reject_unverified(false) behaves as before.
…eipts

Add deterministic fixture vectors for an unencrypted message and an
unsigned read receipt, and pin in every binding suite that both decode
under the default reject-unverified policy with verified false.
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ santiagomed
❌ github-actions[bot]
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants