matrix-org / matrix-org/matrix-spec

Signatures object is not defined explicitly

Abierto
#653 3 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

A-Client-Server A-S2S clarification
Lenguaje dominante
HTML
Estrellas
330
Forks
150
Merge medio
2 h 21 min
PR fusionados (30 d)
3

Descripción

I'm not quite sure how to organize this, but I think that the Signatures object could use a little more definition.

The Signatures object is referred to several times in the Federation API, but it isn't explicitly defined like other objects types are. There is a reference to the Signing JSON (section 3) in the appendix, but the actual schema isn't described until Section 3.2. It requires some scrolling to get down to the definition from the link given in the Federation API.

A sentence in Section 3.2 of the appendix mentions that the key for the field is "the name of the entity signing it." For device signatures, it is explicitly stated that the entity name is the User ID and the signing key identifier is the concatenation of the algorithm and device ID. (Cf. signatures request parameter in key claim endpoint.

On the other hand, for server signatures it doesn't seem to be explicitly stated that the key for a homeserver signature should be the server name. This can be inferred from the examples, but it could be made more explicit. I think it would be nice to have a type defined for Signatures something like this:

Signatures (generic)

Parameter Type Description
<entity name> { string: string } Map from signing key identifier to Base64-encoded string of signature. The field name should be the name of the entity signing the content.

This could be further specified for each signature type:

Server Signatures

Parameter Type Description
<server name> { string: string} Map from a homeserver key identifier to Base64-encoded string of signature. The field name should be the server name of the homeserver signing the content.

Device Signatures

Parameter Type Description
<user ID> { string: string} Map from device key identifiers to Base64-encoded string of signature. The field name should be the ID of the user who owns the device.

... and similarly for the Invite Signatures and Identity Server Signatures types.

(Now that I write this, it seems that the difficulty with this is being able to specify types for field names...)

Sorry for the rambling; let me know if I didn't get the problem across.

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Línea de trabajo

Comienza con las referencias de la Federation API al objeto Signatures, después lee el apéndice de Signing JSON, especialmente la Sección 3.2, y compara los ejemplos de firmas de device y server. Aclara el mapeo genérico de nombres de entidad y documenta las variantes server, device, invite e identity-server. Se considera terminado cuando las secciones de la API referenciadas definen los nombres de las claves y los mapas de valores sin requerir que los lectores los infieran a partir de los ejemplos.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
json
Área
documentation
Tipo de issue
Documentación
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.