fix: don't allow unjoined users to send typing notifications

merge-requests/257/head
Timo Kösters 2 years ago
parent 3573d40027
commit b6b27b66c8
No known key found for this signature in database
GPG Key ID: 24DA7517711A2BA4

@ -1,5 +1,5 @@
use crate::{database::DatabaseGuard, utils, Result, Ruma};
use ruma::api::client::typing::create_typing_event;
use crate::{database::DatabaseGuard, Error, utils, Result, Ruma};
use ruma::api::client::{typing::create_typing_event, error::ErrorKind};
/// # `PUT /_matrix/client/r0/rooms/{roomId}/typing/{userId}`
///
@ -12,6 +12,13 @@ pub async fn create_typing_event_route(
let sender_user = body.sender_user.as_ref().expect("user is authenticated");
if !db.rooms.is_joined(sender_user, &body.room_id)? {
return Err(Error::BadRequest(
ErrorKind::Forbidden,
"You are not in this room.",
));
}
if let Typing::Yes(duration) = body.state {
db.rooms.edus.typing_add(
sender_user,

@ -770,17 +770,21 @@ pub async fn send_transaction_message_route(
}
}
Edu::Typing(typing) => {
if typing.typing {
db.rooms.edus.typing_add(
&typing.user_id,
&typing.room_id,
3000 + utils::millis_since_unix_epoch(),
&db.globals,
)?;
} else {
db.rooms
.edus
.typing_remove(&typing.user_id, &typing.room_id, &db.globals)?;
if db.rooms.is_joined(&typing.user_id, &typing.room_id)? {
if typing.typing {
db.rooms.edus.typing_add(
&typing.user_id,
&typing.room_id,
3000 + utils::millis_since_unix_epoch(),
&db.globals,
)?;
} else {
db.rooms.edus.typing_remove(
&typing.user_id,
&typing.room_id,
&db.globals,
)?;
}
}
}
Edu::DeviceListUpdate(DeviceListUpdateContent { user_id, .. }) => {

Loading…
Cancel
Save