element-hq / element-hq/synapse
Ability for users to audit their device's IP access
- Dominant language
- Python
- Stars
- 4.6k
- Forks
- 600
- Avg merge
- 5d 22h
- Merged PRs (30d)
- 51
Description
This issue has been migrated from [#8485](https://github.com/matrix-org/synapse/issues/8485).
---
Currently we expose the most recent IP address for a user's device. In order to see if someone has stolen your access_token it would be very nice to expose the full audit the server has.
Contributor guide
Research direction
The issue names no files or tests. Start by locating the existing code and endpoint that expose a device's most recent IP address, then trace how access-token activity is recorded. Done would require an agreed design and an API exposing the device's full server-side IP access audit, but the issue does not define its scope or retention requirements.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100