matrix-org / matrix-org/matrix-spec
[Brainstorming] More granular access controls/power levels
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 330
- Forks
- 150
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 3
Description
I've been thinking about this for a while, but I haven't reached any concrete ideas yet.
I wonder if we could take a page from how push rules work to extend power levels into specific event content?
Idea being, you can match an m.room.message event with msgtype: m.image and deny it according to auth rules, or similar kinds of things.
Any better ideas?
I feel like it would be a good idea to have an intermediary state before we get RBAC.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
This is an unresolved brainstorming issue about extending power levels with event-content rules, using push rules as a possible model. Start by reviewing the existing power-level and push-rule specifications; the work is complete only when a concrete design and agreed scope for intermediary access-control states are established.
Written by the indexing model from the issue text.
Assessment
- Domain
- authorization
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100