summary refs log tree commit diff
path: root/synapse/rest
diff options
context:
space:
mode:
authorNick Mills-Barrett <nick@beeper.com>2022-12-07 17:35:41 +0000
committerGitHub <noreply@github.com>2022-12-07 17:35:41 +0000
commit60c3fea3271468dd1f9e9c5fae2d22dd9778293b (patch)
tree72bbf7d215cd42cebc3e9e56c1f02892370858bd /synapse/rest
parentUnit tests CI speedup (#14610) (diff)
downloadsynapse-60c3fea3271468dd1f9e9c5fae2d22dd9778293b.tar.xz
Reject receipt requests with invalid room or event IDs. (#14632)
If the room or event IDs are empty or of an invalid form they
should be rejected.
Diffstat (limited to 'synapse/rest')
-rw-r--r--synapse/rest/client/receipts.py5
1 files changed, 4 insertions, 1 deletions
diff --git a/synapse/rest/client/receipts.py b/synapse/rest/client/receipts.py
index 18a282b22c..28b7d30ea8 100644
--- a/synapse/rest/client/receipts.py
+++ b/synapse/rest/client/receipts.py
@@ -20,7 +20,7 @@ from synapse.api.errors import Codes, SynapseError
 from synapse.http.server import HttpServer
 from synapse.http.servlet import RestServlet, parse_json_object_from_request
 from synapse.http.site import SynapseRequest
-from synapse.types import JsonDict
+from synapse.types import EventID, JsonDict, RoomID
 
 from ._base import client_patterns
 
@@ -56,6 +56,9 @@ class ReceiptRestServlet(RestServlet):
     ) -> Tuple[int, JsonDict]:
         requester = await self.auth.get_user_by_req(request)
 
+        if not RoomID.is_valid(room_id) or not event_id.startswith(EventID.SIGIL):
+            raise SynapseError(400, "A valid room ID and event ID must be specified")
+
         if receipt_type not in self._known_receipt_types:
             raise SynapseError(
                 400,