fix: Only pop unsigned from PDUs

This commit is contained in:
timedout
2026-03-29 14:21:30 +01:00
parent 303ad4ab9c
commit 127030ac38
+6 -46
View File
@@ -891,52 +891,12 @@ impl Service {
&self, &self,
mut pdu_json: CanonicalJsonObject, mut pdu_json: CanonicalJsonObject,
) -> Box<RawJsonValue> { ) -> Box<RawJsonValue> {
// NOTE: We do not support event format v1 (for rooms v1 and v2) - we only pdu_json.remove("unsigned");
// support rooms version 3 and newer (event format v2), so we do not need to // NOTE: Historically there have been attempts to further reduce the amount of
// worry about keys that would've been retained in v1 and v2. Only v3 onward. // data sent over the wire to remote servers. However, so far, the only key
let mut top_level_keys = vec![ // that is safe to drop entirely is `unsigned` - the rest of the keys are
"auth_events", // actually included as part of the content hash, and will cause issues if
"content", // removed, even if they're irrelevant.
"depth",
"hashes",
"origin_server_ts",
"prev_events",
"room_id",
"sender",
"signatures",
"state_key",
"type",
];
if let Some(room_id) = pdu_json
.get("room_id")
.and_then(|v| RoomId::parse(v.as_str()?).ok())
{
if let Ok(room_version) = self.services.state.get_room_version(room_id).await {
use RoomVersionId::*;
if !matches!(room_version, V3 | V4 | V5 | V6 | V7 | V8 | V9 | V10) {
// Redacts is no longer top-level after V10
top_level_keys.retain(|e| *e != "redacts");
}
if matches!(room_version, V12) {
if is_create_event(&pdu_json) {
// room_id is removed from m.room.create events in v12, but we need it
// for all other events.
top_level_keys.retain(|e| *e != "room_id");
}
}
}
}
let to_remove = pdu_json
.keys()
.filter(|k| !top_level_keys.contains(&k.as_str()))
.cloned()
.collect::<Vec<_>>();
for key in to_remove {
pdu_json.remove(key.as_str());
}
to_raw_value(&pdu_json).expect("CanonicalJson is valid serde_json::Value") to_raw_value(&pdu_json).expect("CanonicalJson is valid serde_json::Value")
} }
} }