Expand description
Client-Server HTTP routes. Paths are relative; the process nests them
under /_matrix if it wants that prefix.
A bearer is Authorization: Bearer <raw> or the access_token query
parameter. The stored credential is the SHA-256 hex of that raw token
(hash_token). POST /client/v3/register returns the raw bearer once,
in the response that creates the device. Nothing else returns it.
Modules§
- edge_
auth - Core-side gate for the edge/core split. When the server runs with
--role core, every request must carry the shared secret the edge adds (X-M4A-Edge-Secret). The tunnel and a firewall allowlist are the first line; this header is the second, so a stray process on the tunnel network cannot talk to the core. The secret comes from the environment and is never logged. - fed_net
- Outgoing federation: signed requests, outbox delivery, PDU verification, remote join, and the remote halves of key query/claim and to-device.
- identity
- The messenger side of the seam: the signed-assertion middleware and the
lifecycle events endpoint. Verification and wire formats live in
m4a_seam; this file only applies them. Inert until the deployment setsHomeserver::seam. - presence
- Presence:
PUT/GET /presence/{userId}/status, the syncpresencesection, andm.presenceEDUs between servers.
Structs§
Functions§
- cors
- Browser clients (Element, Cinny) call from another origin: answer preflights and allow it.
- hash_
token - raw_
token - resolve_
caller - router
- wake_
users - with_
read_ pub - Read-only work on a pooled reader connection (the store’s parallel WAL readers); falls back to
the writer when no read pool is attached (in-memory stores).
workmust not write.