-
-
Notifications
You must be signed in to change notification settings - Fork 97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Application service API authentication requires access_token
to be in the query parameters
#679
Application service API authentication requires access_token
to be in the query parameters
#679
Comments
Which direction of traffic is your concern in? Homeserver -> Appservice or Appservice -> Homeserver? |
I think this is Homeserver > Appservice? This is the section I'm talking about. |
Right, so matrix-org/matrix-spec-proposals#1424 was about the other direction. It is true that the only way homeservers can prove their identity to an appservice is through the query parameters, and this would require an MSC to change. |
access_token
to be in the query parameters
This seems like it would be solved by matrix-org/matrix-spec-proposals#2832. |
Closing in favour of MSC, given it's on the edge of FCP. |
There's an existing issue about this at matrix-org/matrix-spec-proposals#1424, but it got closed by matrix-org/matrix-spec-proposals#1534 which updates the wording about the usage of the client-server API for appservices, but not the wording about authentication in the appservice API itself. This seems like an oversight.
The text was updated successfully, but these errors were encountered: