grapevine/book
timedout 9a50c2448a validate event type and membership for create_join and create_invite
Both of these endpoints sign the received event so without the
validation a malicious server can use these endpoints to trick our
server into signing effectively arbitrary forged events from local
users.

Rebased from a continuwuity patch by nex. The create_join changes were
not present in the continuwuity version because these checks were
already present there.

Co-authored-by: Olivia Lee <olivia@computer.surgery>
2025-12-21 14:15:26 -08:00
..
contributing add a style guide 2024-12-11 14:01:38 -08:00
installing document that conduwuit migration is unlikely to work 2025-04-11 13:10:23 -07:00
changelog.md validate event type and membership for create_join and create_invite 2025-12-21 14:15:26 -08:00
code-of-conduct.md add a code of conduct 2024-06-17 16:39:22 -07:00
contributing.md move security info to its own page 2024-12-11 13:26:16 -08:00
installing.md document supported targets 2024-12-13 16:59:13 -08:00
introduction.md improve link accessibility 2025-08-06 12:27:45 -07:00
migration.md move conduit migration to installing section 2024-12-13 16:59:13 -08:00
SUMMARY.md document that conduwuit migration is unlikely to work 2025-04-11 13:10:23 -07:00