Skip to content
  • Matthias Ahouansou's avatar
    fix(keys): only use keys valid at the time of PDU or transaction, and actually refresh keys · 9087da91
    Matthias Ahouansou authored and Charles Hall's avatar Charles Hall committed
    
    
    Previously, we only fetched keys once, only requesting them again if we have any missing, allowing for ancient keys to be used to sign PDUs and transactions
    Now we refresh keys that either have or are about to expire, preventing attacks that make use of leaked private keys of a homeserver
    We also ensure that when validating PDUs or transactions, that they are valid at the origin_server_ts or time of us receiving the transaction respectfully
    As to not break event authorization for old rooms, we need to keep old keys around
    We move verify_keys which we no longer see in direct requests to the origin to old_verify_keys
    We keep old_verify_keys indefinitely as mentioned above, as to not break event authorization (at least until a future MSC addresses this)
    
    Original patch by Matthias. Benjamin just rebased it onto grapevine and
    fixed clippy/rustc warnings.
    
    Co-authored-by: default avatarBenjamin Lee <benjamin@computer.surgery>
    9087da91