unsigned
should be stripped of disallowed keys when received over S2S
#1524
Labels
clarification
An area where the expected behaviour is understood, but the spec could do with being more explicit
We should spell out the fact that the
unsigned
field of PDUs received over S2S should be stripped of everything except an explicitly allowed set of keys, to prevent issues as described in matrix-org/synapse#11080.Synapse already has mitigations for this, as does Dendrite.
The text was updated successfully, but these errors were encountered: