Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replying to Notify Everyone (@room) Triggers Another Notification #20334

Closed
NHAS opened this issue Dec 22, 2021 · 4 comments
Closed

Replying to Notify Everyone (@room) Triggers Another Notification #20334

NHAS opened this issue Dec 22, 2021 · 4 comments
Labels
A-Notifications A-Replies reply O-Occasional Affects or can be seen by some users regularly or most users rarely S-Minor Impairs non-critical functionality or suitable workarounds exist T-Defect X-Spec-Changes

Comments

@NHAS
Copy link

NHAS commented Dec 22, 2021

Steps to reproduce

An a user with notify all permissions pings the room, any user (even if they do not have the permissions to notify all)
is able to ping the room by replying to the @ room notification.

image

Outcome

What did you expect?

If a user responds to a room notification, it does not ping the whole room again if the user does not have permissions to do so.

What happened instead?

The room was pinged

Operating system

MacOS

Browser information

Chrome 96.0.4664.93

URL for webapp

Private (version: 1.9.7 Olm version: 3.2.8)

Application version

Element version: 1.9.7 Olm version: 3.2.8

Homeserver

Private

Will you send logs?

No

@NHAS NHAS added the T-Defect label Dec 22, 2021
@HarHarLinks
Copy link

afaik this is due to reply fallbacks: the @room is actually part of the reply, even though it doesn't look like it.
matrix-org/matrix-spec-proposals#2781

@NHAS
Copy link
Author

NHAS commented Dec 22, 2021

Interesting! In my opinion I think this is still a bug as an unprivileged user is able to still ping a whole room

@germain-gg germain-gg added O-Occasional Affects or can be seen by some users regularly or most users rarely S-Minor Impairs non-critical functionality or suitable workarounds exist labels Dec 23, 2021
@HarHarLinks
Copy link

unprivileged user is able to still ping a whole room

I don't think they are: In your test case you get a ping because it's a reply to you, not because the reply includes @room

@t3chguy
Copy link
Member

t3chguy commented Apr 25, 2023

Closing in favour of element-hq/element-meta#886

@t3chguy t3chguy closed this as completed Apr 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-Notifications A-Replies reply O-Occasional Affects or can be seen by some users regularly or most users rarely S-Minor Impairs non-critical functionality or suitable workarounds exist T-Defect X-Spec-Changes
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants