matrix-org / matrix-org/matrix-spec

How to identify the sender of a message: write a clear description in the spec

Open
#2,441 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
330
Forks
150
Avg merge
2h 21m
Merged PRs (30d)
3

Description

Coming out of https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-x958-rvg6-956w we think we should clarify how a client should identify the sender of a room message based on the cryptographic info in the olm event that sent the message key/megolm session.

Some notes are here:

[guaranteeing-user-id.odp](https://github.com/user-attachments/files/20392073/guaranteeing-user-id.odp)

Contributor guide

Open the contributing guide

Research direction

Start with the linked matrix-rust-sdk security advisory and the attached guaranteeing-user-id.odp notes. Trace how the Matrix specification describes the Olm event carrying the message key or Megolm session, then define the sender-identification guidance there. Done means the spec clearly explains how a client should identify the sender from the cryptographic information.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.