fix: Adjust error codes to comply with MSC4190

This commit is contained in:
Ginger
2026-05-26 14:27:10 -04:00
parent 61ab6b4eb8
commit 7ee9e09b05
2 changed files with 26 additions and 14 deletions
+8
View File
@@ -104,6 +104,14 @@ pub(crate) async fn register_route(
}; };
let (token, device) = if !body.inhibit_login { let (token, device) = if !body.inhibit_login {
// If UIAA is disabled, we can't create a device. In that case only appservices
// can reach this point in the first place, so we return an error for them.
if !services.config.oauth.compatibility_mode.uiaa_available() {
return Err!(Request(AppserviceLoginUnsupported(
"User-interactive appservice registration is not available on this server."
)));
}
// Generate new device id if the user didn't specify one // Generate new device id if the user didn't specify one
let device_id = body let device_id = body
.device_id .device_id
+18 -14
View File
@@ -21,7 +21,7 @@ use ruma::{
}, },
login::{ login::{
self, self,
v3::{DiscoveryInfo, HomeserverInfo}, v3::{DiscoveryInfo, HomeserverInfo, LoginInfo},
}, },
logout, logout_all, logout, logout_all,
}, },
@@ -121,9 +121,18 @@ pub(crate) async fn login_route(
body: Ruma<login::v3::Request>, body: Ruma<login::v3::Request>,
) -> Result<login::v3::Response> { ) -> Result<login::v3::Response> {
if !services.config.oauth.compatibility_mode.uiaa_available() { if !services.config.oauth.compatibility_mode.uiaa_available() {
return Err!(Request(Unrecognized( return match body.login_info {
"User-interactive authentication is not available on this server." | LoginInfo::ApplicationService(_) => {
))); Err!(Request(AppserviceLoginUnsupported(
"User-interactive appservice login is not available on this server."
)))
},
| _ => {
Err!(Request(Unrecognized(
"User-interactive authentication is not available on this server."
)))
},
};
} }
let emergency_mode_enabled = services.config.emergency_password.is_some(); let emergency_mode_enabled = services.config.emergency_password.is_some();
@@ -131,13 +140,9 @@ pub(crate) async fn login_route(
// Validate login method // Validate login method
let user_id = match &body.login_info { let user_id = match &body.login_info {
#[allow(deprecated)] #[allow(deprecated)]
| login::v3::LoginInfo::Password(login::v3::Password { | LoginInfo::Password(login::v3::Password { identifier, password, user, .. }) =>
identifier, handle_login(&services, identifier.as_ref(), password, user.as_ref()).await?,
password, | LoginInfo::Token(login::v3::Token { token, .. }) => {
user,
..
}) => handle_login(&services, identifier.as_ref(), password, user.as_ref()).await?,
| login::v3::LoginInfo::Token(login::v3::Token { token, .. }) => {
debug!("Got token login type"); debug!("Got token login type");
if !services.server.config.login_via_existing_session { if !services.server.config.login_via_existing_session {
return Err!(Request(Unknown("Token login is not enabled."))); return Err!(Request(Unknown("Token login is not enabled.")));
@@ -145,7 +150,7 @@ pub(crate) async fn login_route(
services.users.find_from_login_token(token).await? services.users.find_from_login_token(token).await?
}, },
#[allow(deprecated)] #[allow(deprecated)]
| login::v3::LoginInfo::ApplicationService(login::v3::ApplicationService { | LoginInfo::ApplicationService(login::v3::ApplicationService {
identifier, identifier,
user, user,
.. ..
@@ -179,7 +184,6 @@ pub(crate) async fn login_route(
user_id user_id
}, },
| _ => { | _ => {
debug!("/login json_body: {:?}", &body.json_body);
return Err!(Request(Unknown( return Err!(Request(Unknown(
debug_warn!(?body.login_info, "Invalid or unsupported login type") debug_warn!(?body.login_info, "Invalid or unsupported login type")
))); )));
@@ -257,7 +261,7 @@ pub(crate) async fn login_token_route(
ClientIp(client): ClientIp, ClientIp(client): ClientIp,
body: Ruma<get_login_token::v1::Request>, body: Ruma<get_login_token::v1::Request>,
) -> Result<get_login_token::v1::Response> { ) -> Result<get_login_token::v1::Response> {
if !services.server.config.login_via_existing_session { if !services.config.login_via_existing_session {
return Err!(Request(Forbidden("Login via an existing session is not enabled"))); return Err!(Request(Forbidden("Login via an existing session is not enabled")));
} }