Expand description
Federation stage F0: this server’s signing keys, canonical-JSON signing,
X-Matrix request authentication, and remote key resolution/cache.
Nothing here sends events or joins rooms (that is F1+). The server name is
always a parameter, so the module is testable without the process-wide
name. Remote key fetching is behind RemoteKeys so tests (and staged
deployments) can substitute the network.
Structs§
- Http
KeyFetcher - Production fetcher:
.well-knowndelegation, then HTTPS GET of the key document. - Parsed
Keys - Verify keys parsed from a remote
key/v2/serverresponse. - RawResponse
- Boxed future returned by
FedTransport::request. A binary federation answer. - Target
- Where a server name points after delegation.
- XMatrix
- Parsed
Authorization: X-Matrix ...header.
Enums§
- FedError
- Federation-layer failure. Mapped to
M_UNAUTHORIZEDat the HTTP edge.
Constants§
- KEY_
VALIDITY_ MS - Validity of a published key response (a week, within the spec’s limit).
Traits§
- FedTransport
- Sends one signed federation request and returns
(status, json body).uriis the full path and query including/_matrix. - Remote
Keys - Fetches a remote server’s
key/v2/serverdocument.
Functions§
- active_
signing_ key - The active signing key, generated and stored on first use.
- build_
x_ matrix_ header - Build the
Authorizationheader value for an outgoing signed request. - cached_
remote_ key - Cached public key for
(server, key_id)that is still valid. - canonical_
json - Matrix canonical JSON: keys sorted, no whitespace.
serde_jsonkeeps object keys in a sorted map (thepreserve_orderfeature is not enabled), and the output is compact UTF-8, which is what the signing rules need for the integer/string/array/object values used here. - enc
- Percent-encode one path segment (RFC 3986 unreserved characters pass through).
- last_
fetch_ ms - Last time any key of
serverwas fetched, if ever. - may_
refetch - Whether a refetch for an unknown key is allowed right now.
- now_ms
- Current time in milliseconds since the epoch.
- parse_
server_ keys - Validate a remote key response: right server name, not expired, and self-signed by every listed key that carries a signature (at least one).
- parse_
server_ name - Split
host[:port], handling bracketed IPv6. Returns(host, port, is_ip_literal). - parse_
x_ matrix - Parse an
X-MatrixAuthorization value (quoted or bare parameters). - request_
signing_ object - The object a sender signs for an authenticated federation request.
uriis the full path and query as the receiver sees it, including/_matrix. - resolve_
target - Resolve a server name to a connection target.
well_knownis the delegatedm.servervalue, when the name served one. SRV records are not consulted (F0); a name that needs SRV must publish.well-known. - retire_
active_ key - Retire the active key (rotation). The next call to
active_signing_keymints a new one. - server_
keys_ response - Body of
GET /_matrix/key/v2/server, self-signed. - sign_
json - Sign
objectin place: addssignatures[server][key_id]over the canonical form withoutsignaturesandunsigned. - store_
remote_ keys - Store the keys of a validated response.
- verify_
json - Verify
object.signatures[server][key_id]with a base64 public key. - verify_
request_ signature - Verify a signed request given the sender’s public key.
Type Aliases§
- Fetch
Future - Boxed future returned by
RemoteKeys::fetch_server_keys. - RawFuture
- ReqFuture