element-hq / element-hq/synapse
Synapse allows user creation via the Synapse Admin API when MAS is enabled
- Dominant language
- Python
- Stars
- 4.6k
- Forks
- 600
- Avg merge
- 5d 22h
- Merged PRs (30d)
- 51
Description
### Description
Synapse allows user creation via the Admin API when MAS is enabled. When doing this, the user is not created in MAS rendering it unusable without further Admin action. Synapse should not allow user creation via the Synapse Admin API when MAS is enabled.
### Steps to reproduce
Setup MAS on a server and call https://element-hq.github.io/synapse/latest/admin_api/user_admin_api.html#create-or-modify-account
```bash
curl --request PUT \
--url http://synapse.matrix.local/_synapse/admin/v2/users/@test2:matrix.local \
--header 'authorization: Bearer mct_KEpx1aJaIxmCBwih8owIoy8L6CGZRr_wOous1' \
--header 'content-type: application/json' \
--data '{
"threepids": [
{
"medium": "email",
"address": "test2@example.com"
}
]
}'
{"name":"@test2:matrix.local","admin":false,"deactivated":false,"locked":false,"shadow_banned":false,"creation_ts":1759229586,"appservice_id":null,"consent_server_notice_sent":null,"consent_version":null,"consent_ts":null,"user_type":null,"is_guest":false,"suspended":false,"displayname":"test2","avatar_url":null,"threepids":[{"medium":"email","address":"test2@example.com","validated_at":1759229586035,"added_at":1759229586035}],"external_ids":[],"erased":false,"last_seen_ts":null}%
```
### Homeserver
n/a
### Synapse Version
1.138.2
### Installation Method
Docker (matrixdotorg/synapse)
### Database
PostgreSQL, no migration, no restore
### Workers
Single process
### Platform
Debian 13 + Podman and EMS
### Configuration
homeserver.yaml
```yaml
# Configuration file for Synapse.
#
# This is a YAML file: see [1] for a quick introduction. Note in particular
# that *indentation is important*: all the elements of a list or dictionary
# should have the same indentation.
#
# [1] https://docs.ansible.com/ansible/latest/reference_appendices/YAMLSyntax.html
#
# For more information on how to configure Synapse, including a complete accounting of
# each option, go to docs/usage/configuration/config_documentation.md or
# https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html
server_name: "matrix.local"
pid_file: /data/homeserver.pid
listeners:
- port: 8448
tls: false
type: http
x_forwarded: true
resources:
- names: [client, federation]
compress: false
bind_addresses:
- 0.0.0.0
database:
name: psycopg2
args:
database: synapse
cp_max: 10
cp_min: 5
host: postgres
password: password
user: synapse
log_config: "/data/log.config.yaml"
media_store_path: /data/media_store
registration_shared_secret: "BzH=ey,lZQA9yPnMx6RRV=qoC1QP@,T2Fjyq9JOt~_s*uA2Ntj"
report_stats: false
macaroon_secret_key: ".EPROTvsQF=4:JnIbUg5+5WVKhVp8Y*QeItCJKiPSfSdeS&fcb"
form_secret: ":jYOevmnZHiCg_G:3sk8Cw&Pc*a,ij01I~h,fD#=YFON9atVkM"
signing_key_path: "/data/matrix.local.signing.key"
trusted_key_servers:
- server_name: "matrix.org"
accept_keys_insecurely: true
# vim:ft=yaml
enable_registration: false
enable_registration_without_verification: true
password_config:
pepper: s3cr3tP3pp3r
presence:
enabled: true
suppress_key_server_warning: true
user_directory:
enabled: true
prefer_local_users: true
search_all_users: true
matrix_authentication_service:
enabled: true
endpoint: http://mas:8080/
secret: secret
```
MAS config.yaml
```yaml
http:
listeners:
- name: web
resources:
- name: discovery
- name: human
- name: oauth
- name: compat
- name: graphql
- name: assets
- name: adminapi
binds:
- host: 0.0.0.0
port: 8080
proxy_protocol: false
- name: internal
resources:
- name: health
binds:
- host: localhost
port: 8081
proxy_protocol: false
public_base: http://mas.matrix.local:80
issuer: http://mas.matrix.local:80
trusted_proxies:
- 0.0.0.0/0
email:
from: 'mas@matrix.local'
reply_to: 'mas@matrix.local'
transport: smtp
hostname: mailhog
mode: plain
port: 1025
secrets:
encryption: c58abd1727d39c6a2a77a3f1107581395b71bee058102d38b02d047539ed4d55
keys:
- key: |
-----BEGIN RSA PRIVATE KEY-----
MIIEpQIBAAKCAQEA1XHawQ5yBHfTqaqFKPt7qQkDSuZqQDLE5UhHoE1Xdflcpdby
q43M+7K2Or9rjU/u87HIWg2h06LX7/aUAqXuHUhmUjTFLj5uM3vMI6eqewtgqfyY
Hwvh4iNqYbADAE+/hnoqGPMkGg+QN/V3DsvVYraYrVF21N3qK9DvN1PV4Elmi6z/
r6Z+dOCz267stDklDMRvmtRjxWzgRe3ve2Z5XdKilujVS9RkiymhI1+d6iKzRpfU
jmteUK9PVVmXhFcYcNwYtUIzUR6n4iCcD7Z/TH25MDjUqjklWBnpUufeOpdnkCte
K3iqNUR8qWg32PQ/JC8x4mgdWeNRs/56dw358QIDAQABAoIBAQCfBqDxTY3tfkmZ
E476pcPQgQKO/3USN8EzAtM6v+T15L/+X1OWNaQPs2rKAmxjcLabok2fqqBzSdSQ
2KoV/wKVlqeFgAOZHLKGcSn7NqRx4Fw4yhWcrAGztqc/+R+DT+dmjgZnaF/xer78
sknuIDfvwBOorhVXK6+YzaYtFq022JxWH1Y0xukgz+DOAWsUjTSS7vxXA7XkNucF
ee2Z43Xj9w1NIaS8VfI8pvYds/FkzZRigXqoueH5zmNFyb6yv/4DCMA8z6Sq5Xjs
X0q1ODMXkkba13o0PvkrjPofBR53e0VZwnd+CIa1tTHmnPj1kC5Jyu/xeB3Dz2/I
U96LX3MxAoGBAPa0i8143Hf1EIL14g9xbH8PVcNmOS52XU3cTFrwESPm39Dl6Xph
BlVCOUEwSw7B6JBNJXvCQgWxKSKiDqSUkt4MNnAUUsnpHMMJQBkJrRbNxsWQwn8U
u0ouQVshHS9w8LJ0m3iH0RjNoxb/7P1cch0SRS3gtmY6zwIup4QLetljAoGBAN18
g2IiKxJkQFaoV4XMlMYzmqzC4I51mjgQqi71fGJSvyN1ZtxtYX9SiaQ6wBcnZMP+
Yt0d18tm9j21F0selPmjVm6SNrpytnBsnuAn2UF9MpD8237mPzpBnc4oZoPFmDY0
CXETnyeMsA7ss39X/agMCSDcguPKjr6r4yR6TqmbAoGBALRLWAxOspi8MVf0CESO
+OKWu2+0yj9JY4DeabLf1TbuqE0LaSj1tWIjpqIcgA4F6kdjCey7F/L++PgFhTwE
FJ1QQYyBXcuPoGRs4zopFyUeN5D07R9gcEuTKFJIDgM4v787ds+MOmStC+5oFLNI
l2DllEcl/UcS3WxT2jqnBR3PAoGBAIzrxiRQHRuMkasRXO6Spi4dc1Jsg7fgd4ko
gT9zjfp5L4f+EL47EgeSmmTVxJZ2yBQz7O9HJ6ARGKdWa0WuZZcYJ8weV5f1mMKb
OdLhR8f1QpEhcP6ivKPyT9d1uRQqSphiL4e0tlTRnMtCK0rgz1F2pvAznUwV+xCy
CMmS0C31AoGAKLkCMGbS9ZlN69iN2bwglbyFeoQgvrRn8eohAQEQ5+tCl0zry/Ks
LHlmUaw+3e0h+SQtBlv9tYN1Gj4krjHhXRrQs6hvRnxolgWhkNzSByiCnCfyIaS9
j8qx2S4wQ5eOcLvGvDRqQTcoqOvPcBK79gGB489ztbNlGswjIVarreE=
-----END RSA PRIVATE KEY-----
- key: |
-----BEGIN EC PRIVATE KEY-----
MHcCAQEEIMyR4XrvBZT/VIi9a4vykbxStoW6b9cCAe8/VE/zlkiKoAoGCCqGSM49
AwEHoUQDQgAEQkycGbbeXtVS3MpHA10rikNtPcdq3Q59Q6A4EbHcfd5OJvRpkP+0
6kp2gCytsD2gTNY+8od7eOyPKAvUE/JHUw==
-----END EC PRIVATE KEY-----
- key: |
-----BEGIN EC PRIVATE KEY-----
MIGkAgEBBDBjncpuN2qj52evX5+jxHqbmg22zxiMw5LK1flkNdQpCWDiArhi+1fS
6f8xcRc+A6GgBwYFK4EEACKhZANiAATo07iuSobVQtheCcoMGGQQKV5A51NsZgwT
90oBnZ5iZ+y0vgQzTCeGwDfpOCiewi0vd3DFOylgcUJ+g46zAChNGC5hB6NzdU23
ZGlGI20AjckDZRwbnTD7zrWSzNAYXa8=
-----END EC PRIVATE KEY-----
- key: |
-----BEGIN EC PRIVATE KEY-----
MHQCAQEEIBRJrjUWrUv/zUx+HWBaY8XLr9FOsnIE8njH5I4hrUhwoAcGBSuBBAAK
oUQDQgAEdtyJUocKE53O4DemaIQo9i3mxyteDxUP3Raz2d5eZY5Er+gOrx5OWvvf
Iob5fGo3Roxabeq276XirPelpM1O1w==
-----END EC PRIVATE KEY-----
passwords:
enabled: true
schemes:
- version: 1
algorithm: argon2id
minimum_complexity: 0
matrix:
kind: synapse
homeserver: matrix.local
secret: secret
endpoint: http://synapse:8448/
account:
password_registration_enabled: true
clients:
- client_auth_method: client_secret_basic
client_id: 0000000000000000000SYNAPSE
client_secret: secret
- client_auth_method: client_secret_post
client_id: 01JTTHHQBMKE8W3VCXRVFVW04P
client_secret: secret
redirect_uris:
- http://mas.matrix.local:80/api/doc/oauth2-callback
database:
database: mas
host: mas-postgres
password: password
port: 5432
username: mas
experimental:
access_token_ttl: 86400
compat_token_ttl: 86400
inactive_session_expiration:
expire_compat_sessions: false
ttl: 86400
policy:
client_registration:
allow_host_mismatch: true
allow_insecure_uris: true
allow_missing_client_uri: true
data:
admin_clients:
- 0000000000000000000SYNAPSE
- 01JTTHHQBMKE8W3VCXRVFVW04P
admin_users:
- admin
```
### Relevant log output
```shell
2025-09-30 10:53:06,040 - synapse.access.http.8448 - 515 - INFO - PUT-55 - 10.89.0.19 - 8448 - {@admin:matrix.local} Processed request: 0.015sec/0.000sec (0.002sec, 0.002sec) (0.002sec/0.010sec/14) 484B 201 "PUT /_synapse/admin/v2/users/@test2:matrix.local HTTP/1.1" "curl/8.14.1" [0 dbevts]
```
### Anything else that would be useful to know?
_No response_
Contributor guide
Assessment
This issue has not been assessed yet.