summary refs log tree commit diff
path: root/synapse/crypto
diff options
context:
space:
mode:
authorMark Haines <mark.haines@matrix.org>2014-11-14 19:10:52 +0000
committerMark Haines <mark.haines@matrix.org>2014-11-14 19:11:04 +0000
commit8c2b5ea7c44e3915068cd9ec18e5c22d0a3acfcc (patch)
treecc9d5c93ab2bc044e7e3cd51b43025c68a00da76 /synapse/crypto
parentValidate signatures on incoming events (diff)
downloadsynapse-8c2b5ea7c44e3915068cd9ec18e5c22d0a3acfcc.tar.xz
Fix PDU and event signatures
Diffstat (limited to 'synapse/crypto')
-rw-r--r--synapse/crypto/event_signing.py11
1 files changed, 10 insertions, 1 deletions
diff --git a/synapse/crypto/event_signing.py b/synapse/crypto/event_signing.py
index c7e6bec8f5..79274fd552 100644
--- a/synapse/crypto/event_signing.py
+++ b/synapse/crypto/event_signing.py
@@ -16,6 +16,7 @@
 
 
 from synapse.api.events.utils import prune_event
+from synapse.federation.units import Pdu
 from syutil.jsonutil import encode_canonical_json
 from syutil.base64util import encode_base64, decode_base64
 from syutil.crypto.jsonsign import sign_json
@@ -58,6 +59,8 @@ def _compute_content_hash(event, hash_algorithm):
     event_json.pop("unsigned", None)
     event_json.pop("signatures", None)
     event_json.pop("hashes", None)
+    event_json.pop("outlier", None)
+    event_json.pop("destinations", None)
     event_json_bytes = encode_canonical_json(event_json)
     return hash_algorithm(event_json_bytes)
 
@@ -75,7 +78,13 @@ def compute_event_reference_hash(event, hash_algorithm=hashlib.sha256):
 
 def compute_event_signature(event, signature_name, signing_key):
     tmp_event = prune_event(event)
-    redact_json = tmp_event.get_full_dict()
+    tmp_event.origin = event.origin
+    tmp_event.origin_server_ts = event.origin_server_ts
+    d = tmp_event.get_full_dict()
+    kwargs = dict(event.unrecognized_keys)
+    kwargs.update({k: v for k, v in d.items()})
+    tmp_pdu = Pdu(**kwargs)
+    redact_json = tmp_pdu.get_dict()
     redact_json.pop("signatures", None)
     redact_json.pop("age_ts", None)
     redact_json.pop("unsigned", None)