matrix-org / matrix-org/matrix-spec
How to identify the sender of a message: write a clear description in the spec
- Dominant language
- HTML
- Stars
- 330
- Forks
- 150
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 3
Description
Coming out of https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-x958-rvg6-956w we think we should clarify how a client should identify the sender of a room message based on the cryptographic info in the olm event that sent the message key/megolm session.
Some notes are here:
[guaranteeing-user-id.odp](https://github.com/user-attachments/files/20392073/guaranteeing-user-id.odp)
Contributor guide
Research direction
Start with the linked matrix-rust-sdk security advisory and the attached guaranteeing-user-id.odp notes. Trace how the Matrix specification describes the Olm event carrying the message key or Megolm session, then define the sender-identification guidance there. Done means the spec clearly explains how a client should identify the sender from the cryptographic information.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100