matrix-org / matrix-org/matrix-spec

We should veto m.login.password flows on plain-text transports like plain HTTP (SPEC-346)

Open
#155 2 comments 0 reactions 0 assignees View on GitHub
A-Client-Server feature p1
Dominant language
HTML
Stars
330
Forks
150
Avg merge
2h 21m
Merged PRs (30d)
3

Description

Submitted by @​matthew:matrix.org
Meanwhile, implementing a flow for some mechanism like SCRAM for folks who can't speak TLS could be good - see https://twitter.com/HCornflower/status/697791409785450500

(Imported from https://matrix.org/jira/browse/SPEC-346)

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the imported SPEC-346 issue and the Matrix m.login.password flow, including the plain-HTTP case and the suggested SCRAM alternative. Done would require an agreed specification for how password flows are handled on plain-text transports; the payload names no files or tests.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.