Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Commit

Permalink
Merge pull request #5805 from matrix-org/erikj/validate_state
Browse files Browse the repository at this point in the history
  • Loading branch information
anoadragon453 committed Feb 20, 2020
2 parents 233743a + 55a0c98 commit e7ffd4a
Show file tree
Hide file tree
Showing 2 changed files with 10 additions and 2 deletions.
1 change: 1 addition & 0 deletions changelog.d/5805.misc
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Deny sending well known state types as non-state events.
11 changes: 9 additions & 2 deletions synapse/events/validator.py
Original file line number Diff line number Diff line change
Expand Up @@ -189,17 +189,18 @@ def validate_builder(self, event):

elif event.type == EventTypes.Topic:
self._ensure_strings(event.content, ["topic"])

self._ensure_state_event(event)
elif event.type == EventTypes.Name:
self._ensure_strings(event.content, ["name"])

self._ensure_state_event(event)
elif event.type == EventTypes.Member:
if "membership" not in event.content:
raise SynapseError(400, "Content has not membership key")

if event.content["membership"] not in Membership.LIST:
raise SynapseError(400, "Invalid membership key")

self._ensure_state_event(event)
elif event.type == EventTypes.Tombstone:
if "replacement_room" not in event.content:
raise SynapseError(400, "Content has no replacement_room key")
Expand All @@ -209,9 +210,15 @@ def validate_builder(self, event):
400, "Tombstone cannot reference the room it was sent in"
)

self._ensure_state_event(event)

def _ensure_strings(self, d, keys):
for s in keys:
if s not in d:
raise SynapseError(400, "'%s' not in content" % (s,))
if not isinstance(d[s], string_types):
raise SynapseError(400, "'%s' not a string type" % (s,))

def _ensure_state_event(self, event):
if not event.is_state():
raise SynapseError(400, "'%s' must be state events" % (event.type,))

0 comments on commit e7ffd4a

Please sign in to comment.