diff options
author | Nick Mills-Barrett <nick@beeper.com> | 2022-12-07 17:35:41 +0000 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-12-07 17:35:41 +0000 |
commit | 60c3fea3271468dd1f9e9c5fae2d22dd9778293b (patch) | |
tree | 72bbf7d215cd42cebc3e9e56c1f02892370858bd /synapse/rest | |
parent | Unit tests CI speedup (#14610) (diff) | |
download | synapse-60c3fea3271468dd1f9e9c5fae2d22dd9778293b.tar.xz |
Reject receipt requests with invalid room or event IDs. (#14632)
If the room or event IDs are empty or of an invalid form they should be rejected.
Diffstat (limited to 'synapse/rest')
-rw-r--r-- | synapse/rest/client/receipts.py | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/synapse/rest/client/receipts.py b/synapse/rest/client/receipts.py index 18a282b22c..28b7d30ea8 100644 --- a/synapse/rest/client/receipts.py +++ b/synapse/rest/client/receipts.py @@ -20,7 +20,7 @@ from synapse.api.errors import Codes, SynapseError from synapse.http.server import HttpServer from synapse.http.servlet import RestServlet, parse_json_object_from_request from synapse.http.site import SynapseRequest -from synapse.types import JsonDict +from synapse.types import EventID, JsonDict, RoomID from ._base import client_patterns @@ -56,6 +56,9 @@ class ReceiptRestServlet(RestServlet): ) -> Tuple[int, JsonDict]: requester = await self.auth.get_user_by_req(request) + if not RoomID.is_valid(room_id) or not event_id.startswith(EventID.SIGIL): + raise SynapseError(400, "A valid room ID and event ID must be specified") + if receipt_type not in self._known_receipt_types: raise SynapseError( 400, |