Skip to content
This repository was archived by the owner on Apr 26, 2024. It is now read-only.

Commit 0bd9689

Browse files
authored
Fix a missing await when in the spaces summary. (#10208)
This could cause a minor data leak if someone defined a non-restricted join rule with an allow key or used a restricted join rule in an older room version, but this is unlikely. Additionally this starts adding unit tests to the spaces summary handler.
1 parent e9f2ad8 commit 0bd9689

File tree

3 files changed

+100
-3
lines changed

3 files changed

+100
-3
lines changed

changelog.d/10208.bugfix

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Fix a bug introduced in v1.35.1 where an `allow` key of a `m.room.join_rules` event could be applied for incorrect room versions and configurations.

synapse/handlers/space_summary.py

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -445,14 +445,13 @@ async def _is_room_accessible(
445445
member_event_id = state_ids.get((EventTypes.Member, requester), None)
446446

447447
# If they're in the room they can see info on it.
448-
member_event = None
449448
if member_event_id:
450449
member_event = await self._store.get_event(member_event_id)
451450
if member_event.membership in (Membership.JOIN, Membership.INVITE):
452451
return True
453452

454453
# Otherwise, check if they should be allowed access via membership in a space.
455-
if self._event_auth_handler.has_restricted_join_rules(
454+
if await self._event_auth_handler.has_restricted_join_rules(
456455
state_ids, room_version
457456
):
458457
allowed_rooms = (

tests/handlers/test_space_summary.py

Lines changed: 98 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,15 @@
1111
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
14-
from typing import Any, Optional
14+
from typing import Any, Iterable, Optional, Tuple
1515
from unittest import mock
1616

17+
from synapse.api.errors import AuthError
1718
from synapse.handlers.space_summary import _child_events_comparison_key
19+
from synapse.rest import admin
20+
from synapse.rest.client.v1 import login, room
21+
from synapse.server import HomeServer
22+
from synapse.types import JsonDict
1823

1924
from tests import unittest
2025

@@ -79,3 +84,95 @@ def test_invalid_ordering_value(self):
7984

8085
ev1 = _create_event("!abc:test", "a" * 51)
8186
self.assertEqual([ev2, ev1], _order(ev1, ev2))
87+
88+
89+
class SpaceSummaryTestCase(unittest.HomeserverTestCase):
90+
servlets = [
91+
admin.register_servlets_for_client_rest_resource,
92+
room.register_servlets,
93+
login.register_servlets,
94+
]
95+
96+
def prepare(self, reactor, clock, hs: HomeServer):
97+
self.hs = hs
98+
self.handler = self.hs.get_space_summary_handler()
99+
100+
self.user = self.register_user("user", "pass")
101+
self.token = self.login("user", "pass")
102+
103+
def _add_child(self, space_id: str, room_id: str, token: str) -> None:
104+
"""Add a child room to a space."""
105+
self.helper.send_state(
106+
space_id,
107+
event_type="m.space.child",
108+
body={"via": [self.hs.hostname]},
109+
tok=token,
110+
state_key=room_id,
111+
)
112+
113+
def _assert_rooms(self, result: JsonDict, rooms: Iterable[str]) -> None:
114+
"""Assert that the expected room IDs are in the response."""
115+
self.assertCountEqual([room.get("room_id") for room in result["rooms"]], rooms)
116+
117+
def _assert_events(
118+
self, result: JsonDict, events: Iterable[Tuple[str, str]]
119+
) -> None:
120+
"""Assert that the expected parent / child room IDs are in the response."""
121+
self.assertCountEqual(
122+
[
123+
(event.get("room_id"), event.get("state_key"))
124+
for event in result["events"]
125+
],
126+
events,
127+
)
128+
129+
def test_simple_space(self):
130+
"""Test a simple space with a single room."""
131+
space = self.helper.create_room_as(self.user, tok=self.token)
132+
room = self.helper.create_room_as(self.user, tok=self.token)
133+
self._add_child(space, room, self.token)
134+
135+
result = self.get_success(self.handler.get_space_summary(self.user, space))
136+
# The result should have the space and the room in it, along with a link
137+
# from space -> room.
138+
self._assert_rooms(result, [space, room])
139+
self._assert_events(result, [(space, room)])
140+
141+
def test_visibility(self):
142+
"""A user not in a space cannot inspect it."""
143+
space = self.helper.create_room_as(self.user, tok=self.token)
144+
room = self.helper.create_room_as(self.user, tok=self.token)
145+
self._add_child(space, room, self.token)
146+
147+
user2 = self.register_user("user2", "pass")
148+
token2 = self.login("user2", "pass")
149+
150+
# The user cannot see the space.
151+
self.get_failure(self.handler.get_space_summary(user2, space), AuthError)
152+
153+
# Joining the room causes it to be visible.
154+
self.helper.join(space, user2, tok=token2)
155+
result = self.get_success(self.handler.get_space_summary(user2, space))
156+
157+
# The result should only have the space, but includes the link to the room.
158+
self._assert_rooms(result, [space])
159+
self._assert_events(result, [(space, room)])
160+
161+
def test_world_readable(self):
162+
"""A world-readable room is visible to everyone."""
163+
space = self.helper.create_room_as(self.user, tok=self.token)
164+
room = self.helper.create_room_as(self.user, tok=self.token)
165+
self._add_child(space, room, self.token)
166+
self.helper.send_state(
167+
space,
168+
event_type="m.room.history_visibility",
169+
body={"history_visibility": "world_readable"},
170+
tok=self.token,
171+
)
172+
173+
user2 = self.register_user("user2", "pass")
174+
175+
# The space should be visible, as well as the link to the room.
176+
result = self.get_success(self.handler.get_space_summary(user2, space))
177+
self._assert_rooms(result, [space])
178+
self._assert_events(result, [(space, room)])

0 commit comments

Comments
 (0)