diff options
author | Andrew Morgan <andrew@amorgan.xyz> | 2020-03-16 15:31:35 +0000 |
---|---|---|
committer | Andrew Morgan <andrew@amorgan.xyz> | 2020-03-16 15:31:35 +0000 |
commit | 9528bab8fb082d07cf7e8610be3f555618a0465e (patch) | |
tree | 26afaf6c8703b149e141461fc0ba242e376eb08d /synapse/handlers/federation.py | |
parent | Convert EventContext to attrs (#6218) (diff) | |
parent | Improve signature checking on some federation APIs (#6262) (diff) | |
download | synapse-9528bab8fb082d07cf7e8610be3f555618a0465e.tar.xz |
Improve signature checking on some federation APIs (#6262)
* commit '172f264ed': Improve signature checking on some federation APIs (#6262)
Diffstat (limited to 'synapse/handlers/federation.py')
-rw-r--r-- | synapse/handlers/federation.py | 20 |
1 files changed, 18 insertions, 2 deletions
diff --git a/synapse/handlers/federation.py b/synapse/handlers/federation.py index 5ed5e7e02a..17fec1348e 100644 --- a/synapse/handlers/federation.py +++ b/synapse/handlers/federation.py @@ -1222,7 +1222,6 @@ class FederationHandler(BaseHandler): Returns: Deferred[FrozenEvent] """ - if get_domain_from_id(user_id) != origin: logger.info( "Got /make_join request for user %r from different origin %s, ignoring", @@ -1280,11 +1279,20 @@ class FederationHandler(BaseHandler): event = pdu logger.debug( - "on_send_join_request: Got event: %s, signatures: %s", + "on_send_join_request from %s: Got event: %s, signatures: %s", + origin, event.event_id, event.signatures, ) + if get_domain_from_id(event.sender) != origin: + logger.info( + "Got /send_join request for user %r from different origin %s", + event.sender, + origin, + ) + raise SynapseError(403, "User not from origin", Codes.FORBIDDEN) + event.internal_metadata.outlier = False # Send this event on behalf of the origin server. # @@ -1510,6 +1518,14 @@ class FederationHandler(BaseHandler): event.signatures, ) + if get_domain_from_id(event.sender) != origin: + logger.info( + "Got /send_leave request for user %r from different origin %s", + event.sender, + origin, + ) + raise SynapseError(403, "User not from origin", Codes.FORBIDDEN) + event.internal_metadata.outlier = False context = yield self._handle_new_event(origin, event) |