Skip to content

MSC4140: manage delayed events through an authenticated client - #924

Draft
barodeur wants to merge 3 commits into
matrix-org:mainfrom
barodeur:msc4140-authenticated-management
Draft

barodeur wants to merge 3 commits into
matrix-org:mainfrom
barodeur:msc4140-authenticated-management

Conversation

@barodeur

@barodeur barodeur commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

This is a sister PR to element-hq/synapse#20257

Delayed Event (MSC4140) management endpoint should be authenticated.

This PR:

  • modifies the existing test to send authenticated requests
  • adds new tests to ensure
    • access must be authenticated
    • that authenticated user can only change their own delayed events

Signed-off-by: Paul Chobert paul@chobert.fr

MSC4140 describes the delayed event management endpoints
(POST /delayed_events/{delay_id}/{cancel,restart,send}) as authenticated,
and scopes them to the requesting user. Make every management call on
a real delay ID, and the negative tests on an unknown delay ID, go
through the user who scheduled the event instead of the unauthenticated
client.

The only unauthenticated call left is the one asserting that the bulk
GET answers 401 without a token.
…coped

Per MSC4140, the management endpoints are authenticated, and a delay ID
that does not belong to the requesting user is answered with 404
M_NOT_FOUND. Add two tests:

- without a token, each of cancel, restart and send answers 401, and the
  delayed event stays scheduled;
- another user gets 404 for each action on someone else's delay ID, and
  the delayed event still fires on its original timeout.

These need a homeserver that enforces both rules.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant