Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upTwo cross-signing keys uploads (of which the first is empty) during registration #13286
Comments
|
Are we ok with it coming with a cost of a longer (15s under current circumstances) login / registration flow? |
|
Currently we do this to skip a second account password prompt if that's all we would need to upload keys, so I suppose the choices look like:
|
|
Another option would be for the synapse side to move this request to a work that passes the request to the master if it actually gets past auth, so at least the first request that intentionally fails auth is fast? |
Apparently this would not be straightforward to do on synapse, so maybe not for now. |
|
One thing I don't understand here is why we can't assume that the server will always require interactive auth? The MSC seems to imply so at least. Are there any conditions that the homeserver would not enforce this? E.g. if you have interactively authenticated recently already? |
|
During the standup, we were it may be possible to skip the first request that tests auth and instead pass along as password if we have one. In the current world, it's highly likely for a server to require the same auth for login and key upload, so it's reasonable to pass along if we have it. No information is leaked, since we sending the password to the homeserver which already has it. |
If we already have an account password to use during secret storage setup, then it's highly likely that the homeserver accepts passwords for device signing key upload as well. This change then assumes password auth will work without checking to avoid a request when the server is under high load. Fixes vector-im/riot-web#13286
If we already have an account password to use during secret storage setup, then it's highly likely that the homeserver accepts passwords for device signing key upload as well. This change then assumes password auth will work without checking to avoid a request when the server is under high load. Fixes vector-im/riot-web#13286


/_matrix/client/unstable/keys/device_signing/uploadwith request body{}which returns a401. Then later, it does the same request with the cross-signing keys it generated.