Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Update the TLS cipher string and provide configurability for TLS on outgoing ↵ | Andrew Morgan | 2020-02-14 | 1 | -0/+9 |
|\ | | | | | | | federation (#5550) | ||||
| * | Update the TLS cipher string and provide configurability for TLS on outgoing ↵ | Amber Brown | 2019-06-28 | 1 | -0/+9 |
| | | | | | | | | federation (#5550) | ||||
* | | Added possibilty to disable local password authentication (#5092) | Andrew Morgan | 2020-02-14 | 1 | -0/+6 |
|\| | |||||
| * | Added possibilty to disable local password authentication (#5092) | Daniel Hoffend | 2019-06-27 | 1 | -0/+6 |
| | | | | | | | | | | Signed-off-by: Daniel Hoffend <dh@dotlan.net> | ||||
* | | Make it clearer that the template dir is relative to synapse's root dir (#5543) | Andrew Morgan | 2020-02-14 | 1 | -1/+9 |
|\| | |||||
| * | Make it clearer that the template dir is relative to synapse's root dir (#5543) | Andrew Morgan | 2019-06-27 | 1 | -1/+9 |
| | | | | | | Helps address #5444 | ||||
* | | Merge pull request #5524 from matrix-org/rav/new_cmdline_options | Andrew Morgan | 2020-02-14 | 1 | -1/+1 |
|\| | |||||
| * | Merge pull request #5524 from matrix-org/rav/new_cmdline_options | Richard van der Hoff | 2019-06-24 | 1 | -1/+1 |
| |\ | | | | | | | Add --data-dir and --open-private-ports options. | ||||
| | * | Add "--open-private-ports" cmdline option | Richard van der Hoff | 2019-06-24 | 1 | -1/+1 |
| | | | | | | | | | | | | This is helpful when generating a config file for running synapse under docker. | ||||
| * | | Merge pull request #5534 from matrix-org/babolivier/federation-publicrooms | Brendan Abolivier | 2019-06-24 | 1 | -4/+8 |
| |\ \ | | |/ | |/| | Split public rooms directory auth config in two | ||||
| | * | Split public rooms directory auth config in two | Brendan Abolivier | 2019-06-24 | 1 | -4/+8 |
| | | | |||||
* | | | Merge pull request #5516 from matrix-org/rav/acme_key_path | Andrew Morgan | 2020-02-13 | 1 | -0/+7 |
|\| | | |||||
| * | | Allow configuration of the path used for ACME account keys. | Richard van der Hoff | 2019-06-24 | 1 | -0/+7 |
| |/ | | | | | | | | | Because sticking it in the same place as the config isn't necessarily the right thing to do. | ||||
* | | Drop support for cpu_affinity (#5525) | Andrew Morgan | 2020-02-13 | 1 | -23/+0 |
|\| | |||||
| * | Drop support for cpu_affinity (#5525) | Richard van der Hoff | 2019-06-22 | 1 | -23/+0 |
| | | | | | | This has no useful purpose on python3, and is generally a source of confusion. | ||||
* | | Add the ability to restrict max avatar filesize and content-type (#19) | Andrew Morgan | 2019-12-12 | 1 | -0/+24 |
| | | |||||
* | | Add limit_profile_requests_to_known_users option (#18) | Andrew Morgan | 2019-12-05 | 1 | -0/+7 |
| | | |||||
* | | Create configurable ratelimiter for 3pid invites (#11) | Andrew Morgan | 2019-11-12 | 1 | -0/+6 |
| | | |||||
* | | Merge branch 'dinsic' into babolivier/dinsic-message-retention | Brendan Abolivier | 2019-08-28 | 1 | -0/+10 |
|\ \ | |||||
| * | | Lint | Brendan Abolivier | 2019-08-01 | 1 | -1/+1 |
| | | | |||||
| * | | Sample config | Brendan Abolivier | 2019-08-01 | 1 | -0/+10 |
| | | | |||||
* | | | Implement per-room message retention policies | Brendan Abolivier | 2019-08-28 | 1 | -0/+63 |
|/ / | |||||
* | | Split public rooms directory auth config in two | Brendan Abolivier | 2019-06-24 | 1 | -4/+8 |
| | | |||||
* | | Merge branch 'babolivier/third_party_event_rules' into dinsic | Brendan Abolivier | 2019-06-14 | 1 | -0/+13 |
|\| | |||||
| * | Add plugin APIs for implementations of custom event rules. | Brendan Abolivier | 2019-06-14 | 1 | -0/+13 |
| | | |||||
* | | Merge branch 'dinsic' into babolivier/userdir_hide_users | Brendan Abolivier | 2019-06-12 | 1 | -23/+136 |
|\ \ | |||||
| * | | Merge branch 'master' into dinsic | Brendan Abolivier | 2019-06-12 | 1 | -23/+136 |
| |\| | |||||
| | * | Set default room version to v4. (#5379) | Neil Johnson | 2019-06-06 | 1 | -1/+1 |
| | | | | | | | | | | | | Set default room version to v4. | ||||
| | * | Add ability to perform password reset via email without trusting the ↵ | Andrew Morgan | 2019-06-06 | 1 | -10/+50 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | identity server (#5377) Sends password reset emails from the homeserver instead of proxying to the identity server. This is now the default behaviour for security reasons. If you wish to continue proxying password reset requests to the identity server you must now enable the email.trust_identity_server_for_password_resets option. This PR is a culmination of 3 smaller PRs which have each been separately reviewed: * #5308 * #5345 * #5368 | ||||
| | * | Stop hardcoding trust of old matrix.org key (#5374) | Richard van der Hoff | 2019-06-06 | 1 | -6/+37 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There are a few changes going on here: * We make checking the signature on a key server response optional: if no verify_keys are specified, we trust to TLS to validate the connection. * We change the default config so that it does not require responses to be signed by the old key. * We replace the old 'perspectives' config with 'trusted_key_servers', which is also formatted slightly differently. * We emit a warning to the logs every time we trust a key server response signed by the old key. | ||||
| | * | Merge branch 'rav/fix_custom_ca' into rav/enable_tls_verification | Richard van der Hoff | 2019-06-05 | 1 | -0/+16 |
| | |\ | |||||
| | | * | Neilj/mau tracking config explainer (#5284) | Neil Johnson | 2019-06-05 | 1 | -0/+16 |
| | | | | | | | | | | | | | | | | Improve documentation of monthly active user blocking and mau_trial_days | ||||
| | * | | Update sample config | Richard van der Hoff | 2019-06-05 | 1 | -4/+4 |
| | |/ | |||||
| | * | Merge pull request #5276 from matrix-org/babolivier/account_validity_job_delta | Erik Johnston | 2019-05-31 | 1 | -1/+3 |
| | |\ | | | | | | | | | Allow configuring a range for the account validity startup job | ||||
| | * | | regenerate sample config | Amber Brown | 2019-05-29 | 1 | -3/+3 |
| | | | | |||||
| | * | | Add missing blank line in config (#5249) | Richard van der Hoff | 2019-05-24 | 1 | -0/+1 |
| | | | | |||||
| | * | | Add config option for setting homeserver's default room version (#5223) | Andrew Morgan | 2019-05-23 | 1 | -0/+9 |
| | | | | | | | | | | | | | | | | | | | | Replaces DEFAULT_ROOM_VERSION constant with a method that first checks the config, then returns a hardcoded value if the option is not present. That hardcoded value is now located in the server.py config file. | ||||
| | * | | Room Statistics (#4338) | Amber Brown | 2019-05-21 | 1 | -0/+16 |
| | | | | |||||
* | | | | Generate sample config | Brendan Abolivier | 2019-06-10 | 1 | -0/+5 |
|/ / / | |||||
* | | | Merge branch 'babolivier/account_validity_job_delta' of ↵ dinsic_2019-05-31 | Erik Johnston | 2019-05-31 | 1 | -1/+3 |
|\ \ \ | | |/ | |/| | | | | github.com:matrix-org/synapse into dinsic | ||||
| * | | Sample config | Brendan Abolivier | 2019-05-31 | 1 | -1/+1 |
| | | | |||||
| * | | Sample config | Brendan Abolivier | 2019-05-31 | 1 | -8/+3 |
| | | | |||||
| * | | Config and changelog | Brendan Abolivier | 2019-05-28 | 1 | -0/+7 |
| |/ | |||||
* | | Merge pull request #5214 from matrix-org/babolivier/password-policy | Brendan Abolivier | 2019-05-22 | 1 | -0/+30 |
|\ \ | | | | | | | Allow server admins to define and enforce a password policy (MSC2000) | ||||
| * | | Improve documentation on generated configuration | Brendan Abolivier | 2019-05-21 | 1 | -7/+27 |
| | | | |||||
| * | | Config and changelog | Brendan Abolivier | 2019-05-20 | 1 | -0/+10 |
| | | | |||||
* | | | Merge branch 'babolivier/account_validity_expiration_date' into dinsic | Brendan Abolivier | 2019-05-21 | 1 | -0/+8 |
|\ \ \ | | |/ | |/| | |||||
| * | | Doc | Brendan Abolivier | 2019-05-21 | 1 | -0/+8 |
| |/ | |||||
* | | Merge branch 'babolivier/per_room_profiles' into dinsic dinsic_2019-05-17 | Brendan Abolivier | 2019-05-17 | 1 | -28/+49 |
|\| | |||||
| * | Changelog + sample config | Brendan Abolivier | 2019-05-16 | 1 | -0/+6 |
| | | |||||
| * | Make all the rate limiting options more consistent (#5181) | Amber Brown | 2019-05-15 | 1 | -28/+25 |
| | | |||||
| * | Add ability to blacklist ip ranges for federation traffic (#5043) | Andrew Morgan | 2019-05-13 | 1 | -0/+18 |
| | | |||||
* | | Merge branch 'release-v0.99.4' into dinsic dinsic_2019-05-14 | Brendan Abolivier | 2019-05-14 | 1 | -10/+93 |
|\| | |||||
| * | add options to require an access_token to GET /profile and /publicRooms on ↵ | Matthew Hodgson | 2019-05-08 | 1 | -0/+14 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | CS API (#5083) This commit adds two config options: * `restrict_public_rooms_to_local_users` Requires auth to fetch the public rooms directory through the CS API and disables fetching it through the federation API. * `require_auth_for_profile_requests` When set to `true`, requires that requests to `/profile` over the CS API are authenticated, and only returns the user's profile if the requester shares a room with the profile's owner, as per MSC1301. MSC1301 also specifies a behaviour for federation (only returning the profile if the server asking for it shares a room with the profile's owner), but that's currently really non-trivial to do in a not too expensive way. Next step is writing down a MSC that allows a HS to specify which user sent the profile query. In this implementation, Synapse won't send a profile query over federation if it doesn't believe it already shares a room with the profile's owner, though. Groups have been intentionally omitted from this commit. | ||||
| * | Fix sample config | Richard van der Hoff | 2019-05-06 | 1 | -1/+1 |
| | | | | | | | | ... after it got broken in 1565ebec2c. | ||||
| * | Merge branch 'master' into develop | Richard van der Hoff | 2019-05-03 | 1 | -5/+12 |
| |\ | |||||
| | * | more config comment updates | Richard van der Hoff | 2019-05-03 | 1 | -2/+5 |
| | | | |||||
| | * | Blacklist 0.0.0.0 and :: by default for URL previews | Richard van der Hoff | 2019-05-03 | 1 | -5/+9 |
| | | | |||||
| * | | Merge pull request #5124 from matrix-org/babolivier/aliases | Brendan Abolivier | 2019-05-02 | 1 | -0/+5 |
| |\ \ | | | | | | | | | Add some limitations to alias creation | ||||
| | * | | Add some limitations to alias creation | Brendan Abolivier | 2019-05-02 | 1 | -0/+5 |
| | | | | |||||
| * | | | Fix sample config | Richard van der Hoff | 2019-05-01 | 1 | -2/+2 |
| |/ / | |||||
| * | | Config option for verifying federation certificates (MSC 1711) (#4967) | Andrew Morgan | 2019-04-25 | 1 | -0/+34 |
| | | | |||||
| * | | Merge pull request #5047 from matrix-org/babolivier/account_expiration | Brendan Abolivier | 2019-04-17 | 1 | -3/+26 |
| |\ \ | | | | | | | | | Send out emails with links to extend an account's validity period | ||||
| | * | | Send out emails with links to extend an account's validity period | Brendan Abolivier | 2019-04-17 | 1 | -3/+26 |
| | | | | |||||
* | | | | Merge branch 'develop' into dinsic | Andrew Morgan | 2019-04-15 | 1 | -0/+9 |
|\| | | | |||||
| * | | | Merge pull request #5027 from matrix-org/babolivier/account_expiration | Brendan Abolivier | 2019-04-09 | 1 | -0/+6 |
| |\| | | | | | | | | | | Add time-based account expiration | ||||
| | * | | Add account expiration feature | Brendan Abolivier | 2019-04-09 | 1 | -0/+6 |
| | |/ | |||||
| * | | add context to phonehome stats (#5020) | Neil Johnson | 2019-04-08 | 1 | -0/+3 |
| | | | | | | | | | | | | add context to phonehome stats | ||||
| * | | Add config option to block users from looking up 3PIDs (#5010) | Brendan Abolivier | 2019-04-04 | 1 | -0/+4 |
| |/ | |||||
* | | Add config option to block users from looking up 3PIDs (#5010) dinsic_2019-04-05 | Brendan Abolivier | 2019-04-05 | 1 | -0/+4 |
| | | |||||
* | | Sample config | Erik Johnston | 2019-04-03 | 1 | -0/+5 |
| | | |||||
* | | Update sample config | Erik Johnston | 2019-03-21 | 1 | -0/+52 |
|/ | |||||
* | Merge pull request #4896 from matrix-org/erikj/disable_room_directory | Erik Johnston | 2019-03-21 | 1 | -0/+6 |
|\ | | | | | Add option to disable search room lists | ||||
| * | Fix up config comments | Erik Johnston | 2019-03-20 | 1 | -3/+4 |
| | | |||||
| * | Add option to disable search room lists | Erik Johnston | 2019-03-19 | 1 | -0/+5 |
| | | | | | | | | This disables both local and remote room list searching. | ||||
* | | Merge pull request #4895 from matrix-org/erikj/disable_user_search | Erik Johnston | 2019-03-20 | 1 | -0/+5 |
|\ \ | | | | | | | Add option to disable searching in the user dir | ||||
| * | | Fix up sample config | Erik Johnston | 2019-03-20 | 1 | -2/+4 |
| | | | |||||
| * | | Update sample config | Erik Johnston | 2019-03-19 | 1 | -0/+3 |
| |/ | |||||
* / | Batch up outgoing read-receipts to reduce federation traffic. (#4890) | Richard van der Hoff | 2019-03-20 | 1 | -0/+8 |
|/ | | | | Rate-limit outgoing read-receipts as per #4730. | ||||
* | Comment out most options in the generated config. (#4863) | Richard van der Hoff | 2019-03-19 | 1 | -73/+80 |
| | | | | | | | | | | | | | | | | | | | | Make it so that most options in the config are optional, and commented out in the generated config. The reasons this is a good thing are as follows: * If we decide that we should change the default for an option, we can do so, and only those admins that have deliberately chosen to override that option will be stuck on the old setting. * It moves us towards a point where we can get rid of the super-surprising feature of synapse where the default settings for the config come from the generated yaml. * It makes setting up a test config for unit testing an order of magnitude easier (see forthcoming PR). * It makes the generated config more consistent, and hopefully easier for users to understand. | ||||
* | Add ratelimiting on failed login attempts (#4865) | Brendan Abolivier | 2019-03-18 | 1 | -0/+6 |
| | |||||
* | Add ratelimiting on login (#4821) | Brendan Abolivier | 2019-03-15 | 1 | -11/+28 |
| | | | Add two ratelimiters on login (per-IP address and per-userID). | ||||
* | Document using a certificate with a full chain (#4849) | Andrew Morgan | 2019-03-13 | 1 | -0/+5 |
| | |||||
* | Clarify what registration_shared_secret allows for (#2885) (#4844) | Aaron Raimist | 2019-03-11 | 1 | -2/+2 |
| | | | | | | | | | | * Clarify what registration_shared_secret allows for (#2885) Signed-off-by: Aaron Raimist <aaron@raim.ist> * Add changelog Signed-off-by: Aaron Raimist <aaron@raim.ist> | ||||
* | Reword the sample config header to be less scary (#4801) | Matthew Hodgson | 2019-03-07 | 1 | -5/+10 |
| | |||||
* | Update sample config | Brendan Abolivier | 2019-03-05 | 1 | -11/+13 |
| | |||||
* | Add rate-limiting on registration (#4735) | Brendan Abolivier | 2019-03-05 | 1 | -0/+11 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Rate-limiting for registration * Add unit test for registration rate limiting * Add config parameters for rate limiting on auth endpoints * Doc * Fix doc of rate limiting function Co-Authored-By: babolivier <contact@brendanabolivier.com> * Incorporate review * Fix config parsing * Fix linting errors * Set default config for auth rate limiting * Fix tests * Add changelog * Advance reactor instead of mocked clock * Move parameters to registration specific config and give them more sensible default values * Remove unused config options * Don't mock the rate limiter un MAU tests * Rename _register_with_store into register_with_store * Make CI happy * Remove unused import * Update sample config * Fix ratelimiting test for py2 * Add non-guest test | ||||
* | Include a default configuration file in the 'docs' directory. (#4791) | Richard van der Hoff | 2019-03-04 | 1 | -0/+1041 |