Skip to content

Comments

[FS-507] Improve the Federated Welcome Message Request#2412

Merged
mdimjasevic merged 18 commits intodevelopfrom
fs-507/only-raw-welcome-in-fed-req
May 25, 2022
Merged

[FS-507] Improve the Federated Welcome Message Request#2412
mdimjasevic merged 18 commits intodevelopfrom
fs-507/only-raw-welcome-in-fed-req

Conversation

@mdimjasevic
Copy link
Contributor

An earlier PR #2368 introduced a federated welcome message request "mls-welcome" that beside a raw welcome message also included the list of recipients. This is not only redundant, but it also opens ground for abuse by allowing to include recipients that are not intended to receive the welcome message. This PR fixes the issue by updating the federated request to carry only the raw welcome message. The endpoint handler decodes the welcome message and also checks for key package references.

Tracked by https://wearezeta.atlassian.net/browse/FS-507.

Checklist

  • The PR Title explains the impact of the change.
  • The PR description provides context as to why the change should occur and what the code contributes to that effect. This could also be a link to a JIRA ticket or a Github issue, if there is one.
  • changelog.d contains the following bits of information (details):
    • A file with the changelog entry in one or more suitable sub-sections. The sub-sections are marked by directories inside changelog.d.

Marko Dimjašević added 3 commits May 18, 2022 15:42
@mdimjasevic mdimjasevic temporarily deployed to cachix May 18, 2022 14:11 Inactive
Marko Dimjašević added 3 commits May 19, 2022 11:10
@mdimjasevic mdimjasevic temporarily deployed to cachix May 19, 2022 12:33 Inactive
@mdimjasevic mdimjasevic temporarily deployed to cachix May 20, 2022 06:30 Inactive
@mdimjasevic mdimjasevic requested a review from pcapriotti May 20, 2022 06:34
@mdimjasevic mdimjasevic temporarily deployed to cachix May 20, 2022 06:39 Inactive
@mdimjasevic mdimjasevic temporarily deployed to cachix May 20, 2022 06:44 Inactive
@mdimjasevic mdimjasevic temporarily deployed to cachix May 23, 2022 09:05 Inactive
@pcapriotti pcapriotti temporarily deployed to cachix May 23, 2022 09:41 Inactive
@pcapriotti pcapriotti temporarily deployed to cachix May 23, 2022 11:55 Inactive
@mdimjasevic mdimjasevic temporarily deployed to cachix May 24, 2022 09:44 Inactive
@mdimjasevic mdimjasevic temporarily deployed to cachix May 24, 2022 13:03 Inactive
@mdimjasevic mdimjasevic temporarily deployed to cachix May 25, 2022 14:35 Inactive
@mdimjasevic mdimjasevic merged commit 4c2dc58 into develop May 25, 2022
@mdimjasevic mdimjasevic deleted the fs-507/only-raw-welcome-in-fed-req branch May 25, 2022 18:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants