matrix-org / matrix-org/matrix-spec

Disable invites for 1:1 private DMs/direct chats by default OR ask for 2nd user's consent before actually inviting

Open
#831 25 comments 11 reactions 0 assignees View on GitHub
enhancement
Dominant language
HTML
Stars
330
Forks
150
Avg merge
2h 21m
Merged PRs (30d)
3

Description

### Suggestion

Please read vector-im/element-meta#320 for context.

I would like for all clients/servers to disallow inviting a 3rd user into a private 1:1 chat by default.

If a user wants advanced functionality by inviting bots or personal assistants, _that_ should involve an extra step or two, not the other way around, as the workaround suggested in the linked issue does.

The most straightforward method of creating and using a 1:1 chat, without tweaking anything, should cater to the average non-tech-savvy user, someone who would have no idea of the consequences of being part of a 1:1 chat where both users are admins and can invite all and sundry to become part of a potentially private conversation.

This could be a very targeted, narrow component of matrix-org/matrix-spec#289.

### Alternative

I would like for all clients/servers to ask the 2nd user for consent before sending out an invite to any 3rd user to a private 1:1 chat. This will ensure that no single user can abuse their admin privilege to allow others to gatecrash a private conversation.

Contributor guide

Open the contributing guide

Research direction

Read vector-im/element-meta#320 and matrix-org/matrix-spec#289 first for the existing context. Then determine where the Matrix specification should define the default invite restriction or second-user consent requirement; the work is done when the agreed behavior is clearly specified for clients and servers.

Written by the indexing model from the issue text.

Assessment

Domain
backend-api-design, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.