matrix-org / matrix-org/matrix-spec
User or room specific "Never send encrypted messages to unverified sessions"
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 330
- Forks
- 150
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 3
Description
Suggestion
Currently there is only an option to "Never send encrypted messages to unverified sessions from this session" which only applies to that Element Web instance.
I would like to mark users such as myself using cross-signing as "encrypt only to verified sessions" and the very few people I have happened to meet during the pandemic instead of having to remember doing this for every room with those people.
As an example to only encrypting to own verified sessions, I tend to have a room only for myself and different accounts on all protocols so I can quickly throw notes and similar there when I just need to transfer it to another device quickly and easily. I also have hanging unverified sessions as some Matrix clients are yet to implement emoji/qr verification or clearly showing their details for manual verification.
Related issues:
- https://github.com/vector-im/element-meta/issues/1114 - about the opposite, when the existing option is checked, the other end sees unclear error messages.
- https://github.com/matrix-org/matrix-doc/issues/3354 - collection of other encryption issues, some of which have been fixed.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Start by reading this proposal and the linked Element Meta and Matrix specification issues, then determine the required protocol behavior and specification changes. Done means the user- or room-specific verification policy is defined consistently with existing encryption and cross-signing rules.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100