Skip to main content

Module messaging

Module messaging 

Source
Expand description

Timeline send, redact, and history paging over an open connection. Entitlements are the builder’s. A private room does not consult a paid flag.

Structs§

EventFilter
MessagesPage
One page of /messages’ timeline window — [get_messages]’s own DB-only core, unit-tested directly.
MessagesQuery
RedactBody
RedactOutcome
RelationsQuery
SendOutcome
StreamToken
A parsed pagination position — see the module doc.

Enums§

Direction

Constants§

BURST_LIMIT_COUNT
Short-window burst cap: at most this many sends/redacts per device.
BURST_LIMIT_WINDOW_SECS
…within this many seconds.
LEGACY_DM_KEY_STATE_TYPE
MATRIX_SEND_DAILY_LIMIT
Per-sender messages-per-day cap in private rooms, mirroring dm_db’s own DM_MESSAGE_DAILY_LIMIT value.
MESSAGES_DEFAULT_LIMIT
MESSAGES_MAX_LIMIT
ONE_DAY_MS
REFUSED_SEND_STATE_TYPES
Every state-event type PUT /state/{eventType}/{stateKey} owns, refused outright on /send (P6 binding rule) — includes our own org.example.legacy_dm_key alongside the standard m.room.* state types.

Functions§

apply_redact
PUT /redact/{eventId}/{txnId}’s whole DB-side decision + write (plan §4 redact row): txn-dedup peek first; then Member; then own-event OR PowerCheck(redact) — redact does NOT require the sender’s level to exceed the target’s own level (spec rule, unlike kick/ban/unban); then the dedup-checked redaction itself (which enforces the v11 unredactable-event-type rule and maps to 403 via MatrixStoreError::UnredactableEvent).
apply_send
PUT /send/{eventType}/{txnId}’s whole DB-side decision + write (plan §4 send row): txn-dedup peek first (a repeat short-circuits everything else and returns the ORIGINAL event, per the idempotency rule); then Member, the type-refusal rule, PowerCheck(events[type] else events_default), the send-rate limits, and the m.replace-sender rule; then the dedup-checked insert itself.
check_rate_limits
check_replace_target_sender
An m.replace must come from the target event’s ORIGINAL sender (P6 binding rule) — a no-op for content with no m.relates_to, or a rel_type other than m.replace.
check_send_event_type_allowed
PUT /send/{eventType}/{txnId}’s type-refusal rule (P6 binding rule): state-event types and org.example.legacy_dm_key go through /state; org.example.legacy_dm is migration-only; m.room.redaction goes through /redact; and, in an encrypted room, only m.room.encrypted and m.reaction (server-visible metadata, coordinator ruling) are accepted at all.
clamp_limit
event_passes_filter
format_stream_token
lazy_load_member_state
paginate_messages
parse_filter
parse_stream_token
"t{stream_id}", a bare "0", or a sync token "s{stream_id}_{typing_gen}" — see the module doc. Anything else, and any negative stream id, is refused with M_INVALID_PARAM.
power_levels_of
require_member
require_power
resolve_messages_start
The page start GET /messages walks from: the explicit from token when present, else the far end of the timeline for dir — the newest event going backward, the very beginning going forward (Matrix makes from optional and defines exactly this).