matrix-org / matrix-org/matrix-spec
We should veto m.login.password flows on plain-text transports like plain HTTP (SPEC-346)
Open
A-Client-Server
feature
p1
- Dominant language
- HTML
- Stars
- 330
- Forks
- 150
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 3
Description
Submitted by @matthew:matrix.org
Meanwhile, implementing a flow for some mechanism like SCRAM for folks who can't speak TLS could be good - see https://twitter.com/HCornflower/status/697791409785450500
(Imported from https://matrix.org/jira/browse/SPEC-346)
Contributor guide
Research direction
Start by reviewing the imported SPEC-346 issue and the Matrix m.login.password flow, including the plain-HTTP case and the suggested SCRAM alternative. Done would require an agreed specification for how password flows are handled on plain-text transports; the payload names no files or tests.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100