mirror of
https://forgejo.ellis.link/continuwuation/continuwuity.git
synced 2026-05-26 20:49:55 +00:00
feat: Add config check to make sure default ACL doesn't self-ban the server
This commit is contained in:
@@ -2,6 +2,7 @@ use std::env::consts::OS;
|
|||||||
|
|
||||||
use either::Either;
|
use either::Either;
|
||||||
use figment::Figment;
|
use figment::Figment;
|
||||||
|
use ruma::events::room::server_acl::RoomServerAclEventContent;
|
||||||
|
|
||||||
use super::DEPRECATED_KEYS;
|
use super::DEPRECATED_KEYS;
|
||||||
use crate::{Config, Err, Result, Server, debug, debug_info, debug_warn, error, warn};
|
use crate::{Config, Err, Result, Server, debug, debug_info, debug_warn, error, warn};
|
||||||
@@ -254,11 +255,38 @@ pub fn check(config: &Config) -> Result {
|
|||||||
));
|
));
|
||||||
}
|
}
|
||||||
|
|
||||||
if config.default_room_acl_allow.is_some() && config.default_room_acl_deny.is_some() {
|
match (&config.default_room_acl_allow, &config.default_room_acl_deny) {
|
||||||
return Err!(Config(
|
| (Some(_), Some(_)) => {
|
||||||
"default_room_acl_deny",
|
return Err!(Config(
|
||||||
"Cannot provide a value for both default_room_acl_allow and default_room_acl_deny"
|
"default_room_acl_deny",
|
||||||
));
|
"Cannot provide a value for both default_room_acl_allow and \
|
||||||
|
default_room_acl_deny."
|
||||||
|
));
|
||||||
|
},
|
||||||
|
| (Some(allow), None) => {
|
||||||
|
if !RoomServerAclEventContent::new(true, allow.clone(), vec![])
|
||||||
|
.is_allowed(&config.server_name)
|
||||||
|
{
|
||||||
|
return Err!(Config(
|
||||||
|
"default_room_acl_allow",
|
||||||
|
"The default room Access Control List does not allow this server in the \
|
||||||
|
rooms it creates. Note that when using an allow list, servers are denied \
|
||||||
|
unless they match an allow value."
|
||||||
|
));
|
||||||
|
}
|
||||||
|
},
|
||||||
|
| (None, Some(deny)) => {
|
||||||
|
if !RoomServerAclEventContent::new(true, vec!["*".to_owned()], deny.clone())
|
||||||
|
.is_allowed(&config.server_name)
|
||||||
|
{
|
||||||
|
return Err!(Config(
|
||||||
|
"default_room_acl_deny",
|
||||||
|
"The default room Access Control List denies this server access to the \
|
||||||
|
rooms it creates."
|
||||||
|
));
|
||||||
|
}
|
||||||
|
},
|
||||||
|
| _ => (),
|
||||||
}
|
}
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
|
|||||||
Reference in New Issue
Block a user