Skip to main content

Module federation

Module federation 

Source
Expand description

Federation stage F0: this server’s signing keys, canonical-JSON signing, X-Matrix request authentication, and remote key resolution/cache.

Nothing here sends events or joins rooms (that is F1+). The server name is always a parameter, so the module is testable without the process-wide name. Remote key fetching is behind RemoteKeys so tests (and staged deployments) can substitute the network.

Structs§

HttpKeyFetcher
Production fetcher: .well-known delegation, then HTTPS GET of the key document.
ParsedKeys
Verify keys parsed from a remote key/v2/server response.
RawResponse
Boxed future returned by FedTransport::request. A binary federation answer.
Target
Where a server name points after delegation.
XMatrix
Parsed Authorization: X-Matrix ... header.

Enums§

FedError
Federation-layer failure. Mapped to M_UNAUTHORIZED at the HTTP edge.

Constants§

KEY_VALIDITY_MS
Validity of a published key response (a week, within the spec’s limit).

Traits§

FedTransport
Sends one signed federation request and returns (status, json body). uri is the full path and query including /_matrix.
RemoteKeys
Fetches a remote server’s key/v2/server document.

Functions§

active_signing_key
The active signing key, generated and stored on first use.
build_x_matrix_header
Build the Authorization header value for an outgoing signed request.
cached_remote_key
Cached public key for (server, key_id) that is still valid.
canonical_json
Matrix canonical JSON: keys sorted, no whitespace. serde_json keeps object keys in a sorted map (the preserve_order feature is not enabled), and the output is compact UTF-8, which is what the signing rules need for the integer/string/array/object values used here.
enc
Percent-encode one path segment (RFC 3986 unreserved characters pass through).
last_fetch_ms
Last time any key of server was fetched, if ever.
may_refetch
Whether a refetch for an unknown key is allowed right now.
now_ms
Current time in milliseconds since the epoch.
parse_server_keys
Validate a remote key response: right server name, not expired, and self-signed by every listed key that carries a signature (at least one).
parse_server_name
Split host[:port], handling bracketed IPv6. Returns (host, port, is_ip_literal).
parse_x_matrix
Parse an X-Matrix Authorization value (quoted or bare parameters).
request_signing_object
The object a sender signs for an authenticated federation request. uri is the full path and query as the receiver sees it, including /_matrix.
resolve_target
Resolve a server name to a connection target. well_known is the delegated m.server value, when the name served one. SRV records are not consulted (F0); a name that needs SRV must publish .well-known.
retire_active_key
Retire the active key (rotation). The next call to active_signing_key mints a new one.
server_keys_response
Body of GET /_matrix/key/v2/server, self-signed.
sign_json
Sign object in place: adds signatures[server][key_id] over the canonical form without signatures and unsigned.
store_remote_keys
Store the keys of a validated response.
verify_json
Verify object.signatures[server][key_id] with a base64 public key.
verify_request_signature
Verify a signed request given the sender’s public key.

Type Aliases§

FetchFuture
Boxed future returned by RemoteKeys::fetch_server_keys.
RawFuture
ReqFuture