Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Application service API authentication requires access_token to be in the query parameters #679

Closed
jplatte opened this issue Aug 17, 2020 · 5 comments · Fixed by matrix-org/matrix-spec-proposals#2832
Labels
A-Application-Services Issues affecting the AS API improvement An idea/future MSC for the spec

Comments

@jplatte
Copy link
Contributor

jplatte commented Aug 17, 2020

There's an existing issue about this at matrix-org/matrix-spec-proposals#1424, but it got closed by matrix-org/matrix-spec-proposals#1534 which updates the wording about the usage of the client-server API for appservices, but not the wording about authentication in the appservice API itself. This seems like an oversight.

@turt2live
Copy link
Member

Which direction of traffic is your concern in? Homeserver -> Appservice or Appservice -> Homeserver?

@jplatte
Copy link
Contributor Author

jplatte commented Aug 17, 2020

I think this is Homeserver > Appservice? This is the section I'm talking about.

@turt2live
Copy link
Member

Right, so matrix-org/matrix-spec-proposals#1424 was about the other direction. It is true that the only way homeservers can prove their identity to an appservice is through the query parameters, and this would require an MSC to change.

@richvdh richvdh transferred this issue from matrix-org/matrix-spec-proposals Mar 1, 2022
@turt2live turt2live added improvement An idea/future MSC for the spec A-Application-Services Issues affecting the AS API labels May 31, 2022
@richvdh richvdh changed the title Application service API authentication uses query string for access token only? Application service API authentication requires access_token to be in the query parameters Jun 9, 2022
@Half-Shot
Copy link
Contributor

This seems like it would be solved by matrix-org/matrix-spec-proposals#2832.

@turt2live
Copy link
Member

Closing in favour of MSC, given it's on the edge of FCP.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-Application-Services Issues affecting the AS API improvement An idea/future MSC for the spec
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants