Skip to main content

Module http

Module http 

Source
Expand description

Client-Server HTTP routes. Paths are relative; the process nests them under /_matrix if it wants that prefix.

A bearer is Authorization: Bearer <raw> or the access_token query parameter. The stored credential is the SHA-256 hex of that raw token (hash_token). POST /client/v3/register returns the raw bearer once, in the response that creates the device. Nothing else returns it.

Modules§

edge_auth
Core-side gate for the edge/core split. When the server runs with --role core, every request must carry the shared secret the edge adds (X-M4A-Edge-Secret). The tunnel and a firewall allowlist are the first line; this header is the second, so a stray process on the tunnel network cannot talk to the core. The secret comes from the environment and is never logged.
fed_net
Outgoing federation: signed requests, outbox delivery, PDU verification, remote join, and the remote halves of key query/claim and to-device.
identity
The messenger side of the seam: the signed-assertion middleware and the lifecycle events endpoint. Verification and wire formats live in m4a_seam; this file only applies them. Inert until the deployment sets Homeserver::seam.
presence
Presence: PUT/GET /presence/{userId}/status, the sync presence section, and m.presence EDUs between servers.

Structs§

Caller
Homeserver

Functions§

cors
Browser clients (Element, Cinny) call from another origin: answer preflights and allow it.
hash_token
raw_token
resolve_caller
router
wake_users
with_read_pub
Read-only work on a pooled reader connection (the store’s parallel WAL readers); falls back to the writer when no read pool is attached (in-memory stores). work must not write.