-
Notifications
You must be signed in to change notification settings - Fork 416
MSC4140: Remove auth from delayed event management endpoints #19152
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
MSC4140: Remove auth from delayed event management endpoints #19152
Conversation
- Ratelimit based on IP address, as we do for some other unauthed endpoints (like login) - Remove docstrings for methods whose parameters are self-documenting - Remove named-argument splitter (*) from methods where remaining parameters are unambiguous - Add required SQLite-specific schema migration - Apply the schema migration & update latest schema version - Apply automatic formatting & linting fixes
As long as it is still supported for backwards compatibility, want to keep testing it to guard against regressions
Do this to prevent a false-positive failure of the check_schema_delta script that thinks indexes are being created on an existing table, when they are really being created on a new replacement table.
|
This will conflict with #19038, and IMO should go in first because:
|
This prevents having to break DB compatibility / having to bump SCHEMA_COMPAT_VERSION. Use UNIQUE INDEX instead of ALTER TABLE for compatibility with SQLite.
This satisfies the check-schema-delta script.
This should also fix the portdb script
Better to have this comment together with the explanation on why the upgrade should be safe
|
With matrix-org/complement#817 merged, this PR is now covered by Complement tests. |
This reverts commit 76872b1, which is no longer needed now that the lower-bound version of parameterized has been increased.
devonh
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changes seem sensible to me. It's mostly just changing the API shape to align with recent developments on the MSC.
The DB index addition stuff should be okay.
As per recent proposals in MSC4140, remove authentication for restarting/cancelling/sending a delayed event, and give each of those actions its own endpoint. (The original consolidated endpoint is still supported for backwards compatibility.)
Pull Request Checklist
EventStoretoEventWorkerStore.".code blocks.