summary refs log tree commit diff
path: root/synapse/handlers/auth.py
diff options
context:
space:
mode:
authorRichard van der Hoff <richard@matrix.org>2020-05-07 14:16:52 +0100
committerRichard van der Hoff <richard@matrix.org>2020-05-07 14:16:52 +0100
commit617541c4c6f9dea1ac1ed0a8f1ab848507457e23 (patch)
tree7b601302be056b5fd85b55cd0d19261f86dba5fb /synapse/handlers/auth.py
parentMerge branch 'release-v1.13.0' into matrix-org-hotfixes (diff)
parentDisable validation that a UI authentication session has not been modified dur... (diff)
downloadsynapse-617541c4c6f9dea1ac1ed0a8f1ab848507457e23.tar.xz
Merge commit '4d3ebc' into matrix-org-hotfixes
Diffstat (limited to 'synapse/handlers/auth.py')
-rw-r--r--synapse/handlers/auth.py12
1 files changed, 0 insertions, 12 deletions
diff --git a/synapse/handlers/auth.py b/synapse/handlers/auth.py

index 7613e5b6ab..a167498add 100644 --- a/synapse/handlers/auth.py +++ b/synapse/handlers/auth.py
@@ -329,18 +329,6 @@ class AuthHandler(BaseHandler): # isn't arbitrary. clientdict = session.clientdict - # Ensure that the queried operation does not vary between stages of - # the UI authentication session. This is done by generating a stable - # comparator based on the URI, method, and body (minus the auth dict) - # and storing it during the initial query. Subsequent queries ensure - # that this comparator has not changed. - comparator = (uri, method, clientdict) - if (session.uri, session.method, session.clientdict) != comparator: - raise SynapseError( - 403, - "Requested operation has changed during the UI authentication session.", - ) - if not authdict: raise InteractiveAuthIncompleteError( self._auth_dict_for_flows(flows, session.session_id)