Skip to content

For rebase: large batch of route implementations - #2

Merged
Fizzadar merged 26 commits into
mainfrom
nick/astra-does-the-rest
Oct 5, 2026
Merged

Fizzadar merged 26 commits into
mainfrom
nick/astra-does-the-rest

Conversation

@Fizzadar

Copy link
Copy Markdown
Contributor

See commits..

@indent

indent Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
PR Summary

This PR fills in a large set of Matrix client-server and federation endpoints that used to be stubbed or missing in Babbleserv. It also fixes correctness problems in token handling, federation signature checks, JSON parsing, version ranges and worker locks. Several stored formats change (access/refresh tokens, filters) and new FDB indexes are added.

  • Accounts: registration with dummy UIA and a publicRegistration setting, plus register/available, /refresh with idempotent token rotation, logout / logout-all, password change and device deletion behind password UIA, expired-token soft-logout responses, and a cleanup worker for UIA sessions and expired tokens.
  • Devices and pushers: deleting a device now also removes its keys, UIA sessions and pushers. Pushers record which device created them and support append. Pusher requests are validated against the spec.
  • Room tags: implemented on top of m.tag room account data.
  • Filters: stored as raw JSON with validation; unknown filter IDs return 404.
  • Media:
    • config endpoint and a size limit on uploads
    • a filesystem datastore
    • async create/upload/complete
    • cached PNG thumbnails, with limits on image size
    • fetching remote media over federation, including multipart responses and IP-filtered redirects
    • federation download and thumbnail endpoints
    • downloads now stream through the server instead of redirecting to S3
  • Rooms:
    • createRoom handles visibility, room_alias_name, power_level_content_override and room-version checks, and fails if any initial state event is rejected
    • published room directory (client and federation) with paging tokens
    • joined member count is kept up to date
    • joined_members endpoint
    • repeated sends with the same device and txnID return the original event, and unsigned.transaction_id is included in responses
  • User directory: search over a substring index of user IDs and display names, limited to users the requester can see. A new worker finds remote users and fetches their profiles.
  • Federation: checks all signatures the event requires, not just the origin's. Also rejects presence updates for users on other servers and serves server keys as canonical JSON.
  • Correctness fixes:
    • rejects trailing or null JSON bodies and malformed version tokens
    • the latest-write cursor follows commit order
    • a worker whose lock lease has passed to another worker no longer clears that worker's lock
    • presence timeouts are handled atomically in small batches, and status messages and activity times are kept

Issues

All clear! No issues remaining. 🎉

7 issues already resolved
  • Tokens stored before this PR are 3-element (access) and 2-element (refresh) tuples, but valueToAuthTokenTup now reads tup[3] and valueToRefreshTokenTup reads tup[2..5], so every existing session gets a 500 from the global auth middleware (not M_UNKNOWN_TOKEN), and re-login with the same device_id, logout, device deletion and /refresh panic too. Decode missing trailing fields as empty/zero values.
  • GET /v3/publicRooms has no auth, and a non-local server param makes the homeserver send an X-Matrix-signed request to any server name (including IP literals or internal hosts) through c.fedClient, whose HTTP timeout this PR sets to 0. Anonymous callers can therefore trigger outbound requests and hold them open indefinitely. Require auth for remote lookups and use a client that has a timeout. (fixed by commit e391ad0)
  • User-ID search grams are only written for users created after this PR (TxnCreateLocalUser). txnUpdateSearchIndex only writes grams that are new relative to searchGrams(userID, previous), so a later profile update never adds user-ID grams either. Every local user registered before deploy stays invisible to /user_directory/search by localpart, and is only partly findable by display name. Add a backfill, or have profile updates always ensure the user-ID grams exist.
  • Pusher keys moved from (userID, pushKey) to (userID, appID, pushKey). TxnGetPushersForUser still returns legacy rows through the userID prefix, but TxnDeletePusherForUser only clears the new key. Legacy pushers therefore survive kind: null, gateway rejection in PushNotificationIterator, and device logout, and they keep receiving pushes. (fixed by commit d4d16fb)
  • UIASessionCleanupIterator.handleCleanupLoop returns on any cleanup error. PanicRetryLoop treats a normal return as done, so the worker stops until restart, and expired UIA sessions and access tokens then pile up. Log the error and wait for the next tick instead. (fixed by commit e391ad0)
  • A failed remote LookupProfile is always rescheduled for now+1m, with no backoff and no attempt limit, and jobs run earliest-due-first. Only users seen solely in private rooms are affected now, since public-room joins take their profile from the member event. For those users, anyone on an unreachable server is polled forever and pushes back newly discovered users. Add exponential backoff and a retry cap. (fixed by commit e391ad0)
  • In syncRooms, the membership-join branch sets from.UserVersion--, which wraps from 0 to 65535 when the join is the first event in its transaction. That covers profile-change member updates, rejoins and plain joins. The old GetVersionRange wrapped 65535 back to 0 and cancelled this out. The new VersionstampAfter carries into the next commit instead, so these rooms come back empty in incremental sync, which is what broke TestAvatarUrlUpdate, TestDisplayNameUpdate and TestDeviceListUpdates. (fixed by commit c32af90)

CI Checks

All CI checks passed on e391ad0.

Comment thread internal/databases/accounts/tokens/tokens.go
Comment thread internal/routes/client/publicrooms.go
Comment thread internal/databases/accounts/users/search.go
Comment thread internal/databases/accounts/users/pushers.go Outdated
Comment thread internal/workers/uiasessioncleanupiterator.go Outdated
Comment thread internal/workers/remoteuserdirectoryiterator.go Outdated
@Fizzadar
Fizzadar force-pushed the nick/add-notification-counts branch from e4d92e1 to ea91220 Compare September 30, 2026 21:24
@Fizzadar
Fizzadar force-pushed the nick/astra-does-the-rest branch 2 times, most recently from d4d16fb to c32af90 Compare September 30, 2026 22:03
@Fizzadar
Fizzadar force-pushed the nick/astra-does-the-rest branch from c32af90 to e391ad0 Compare September 30, 2026 22:28
Base automatically changed from nick/add-notification-counts to main October 3, 2026 18:11
@Fizzadar
Fizzadar merged commit e391ad0 into main Oct 5, 2026
3 checks passed
@Fizzadar
Fizzadar deleted the nick/astra-does-the-rest branch October 5, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant