Skip to content

MSC4140: Cancellable delayed events#4140

Open
toger5 wants to merge 224 commits into
mainfrom
toger5/expiring-events-keep-alive
Open

MSC4140: Cancellable delayed events#4140
toger5 wants to merge 224 commits into
mainfrom
toger5/expiring-events-keep-alive

Conversation

@toger5

@toger5 toger5 commented May 7, 2024

Copy link
Copy Markdown

Rendered

This could also supersede MSC2228 (by making it possible to send a redaction with the /send endpoint. This is the case as mentioned here)

Implementations

Known differences between current implementations and the proposal

  • The implementations use the error code M_MAX_DELAY_EXCEEDED, HTTP 400, and a response property max_delay when the server refuses to schedule an event because the requested delay is too large. The proposal has since switched to the error code M_FORBIDDEN, HTTP 403, and publishes the maximum allowed delay in the m.delayed_events capability (so that clients can discover it ahead of making the request).
  • The implementations use the existing endpoints /send and /state with a new query parameter delay for scheduling delayed events. The proposal has since switched to a dedicated endpoint PUT /_matrix/client/v3/rooms/{roomId}/delayed_event/{eventType}/{txnId} where the delay is included in the request body.
  • The implementations use delay and max_delay rather than delay_ms and max_delay_ms.
  • The implementations use running_since rather than scheduled_at.
  • The implementations support the delegation feature by using delay_id-based authentication on the management endpoints, rather than expecting standard authentication with a user access token.

Implementations in Element Call via the Widget API

These are only informational and shouldn't be relevant for the proposal process. The MSC doesn't depend on widgets and widgets are themselves not part of the spec.


SCT stuff:

MSC checklist

FCP tickyboxes

Designated reviewers:

  • Security team (requested out of band)
  • @anoadragon453 with Backend experience

toger5 added 2 commits May 7, 2024 18:52
Signed-off-by: Timo K <toger5@hotmail.de>
Signed-off-by: Timo K <toger5@hotmail.de>
@toger5
toger5 force-pushed the toger5/expiring-events-keep-alive branch from 2bc07c4 to 0eb1abc Compare May 7, 2024 17:03
Signed-off-by: Timo K <toger5@hotmail.de>
@toger5
toger5 force-pushed the toger5/expiring-events-keep-alive branch from 0eb1abc to 8bf6db7 Compare May 8, 2024 15:49
Signed-off-by: Timo K <toger5@hotmail.de>
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Comment thread proposals/4140-expiring-events-with-keep-alive-endpoint.md Outdated
Signed-off-by: Timo K <toger5@hotmail.de>
@turt2live turt2live changed the title Draft for expiring event PR MSC4140: Expiring events with keep alive endpoint May 9, 2024
@turt2live turt2live added proposal A matrix spec change proposal. Process state. A-Client Server Client-Server API kind:feature MSC for not-core and not-maintenance stuff needs-implementation This MSC does not have a qualifying implementation for the SCT to review. The MSC cannot enter FCP. labels May 9, 2024
@toger5
toger5 force-pushed the toger5/expiring-events-keep-alive branch from 3e54c2a to c82adf7 Compare May 10, 2024 17:54
Signed-off-by: Timo K <toger5@hotmail.de>
@toger5
toger5 force-pushed the toger5/expiring-events-keep-alive branch from c82adf7 to 54fff99 Compare May 10, 2024 18:08
toger5 added 3 commits May 13, 2024 16:56
…is used to trigger on of the actions

Signed-off-by: Timo K <toger5@hotmail.de>
Signed-off-by: Timo K <toger5@hotmail.de>
Add event type to the body
Add event id template variable
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
toger5 and others added 2 commits May 31, 2024 09:20
Co-authored-by: Andrew Ferrazzutti <af_0_af@hotmail.com>
Johennes and others added 8 commits June 29, 2026 09:05
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Co-authored-by: Travis Ralston <travisr@matrix.org>
Comment thread proposals/4140-delayed-events-futures.md Outdated
@turt2live

Copy link
Copy Markdown
Member

With the assumption that the alternative gets further information added into the MSC, this appears ready to go (though there's no comments on the M_FORBIDDEN thread 😇)

@mscbot fcp merge

@mscbot

mscbot commented Jun 30, 2026

Copy link
Copy Markdown
Collaborator

Team member @turt2live has proposed to merge this. The next step is review by the rest of the tagged people:

Once at least 75% of reviewers approve (and there are no outstanding concerns), this will enter its final comment period. If you spot a major issue that hasn't been raised at any point in this process, please speak up!

See this document for information about what commands tagged team members can give me.

@mscbot mscbot added proposed-final-comment-period Currently awaiting signoff of a majority of team members in order to enter the FCP. Process state. disposition-merge Process state. labels Jun 30, 2026
@turt2live

Copy link
Copy Markdown
Member

MSCs proposed for Final Comment Period (FCP) should meet the requirements outlined in the checklist prior to being accepted into the spec. This checklist is a bit long, but aims to reduce the number of follow-on MSCs after a feature lands.

SCT members: please check off things you check for, and raise a concern against FCP if the checklist is incomplete. If an item doesn't apply, prefer to check it rather than remove it. Unchecking items is encouraged where applicable.

MSC authors: feel free to ask in a thread on your MSC or in the#matrix-spec:matrix.org room for clarification of any of these points.

  • Are appropriate implementation(s) specified in the MSC’s PR description?
  • Are all MSCs that this MSC depends on already accepted?
  • For each new endpoint that is introduced:
    • Have authentication requirements been specified?
    • Have rate-limiting requirements been specified?
    • Have guest access requirements been specified?
    • Are error responses specified?
      • Does each error case have a specified errcode (e.g. M_FORBIDDEN) and HTTP status code?
        • If a new errcode is introduced, is it clear that it is new?
  • Will the MSC require a new room version, and if so, has that been made clear?
    • Is the reason for a new room version clearly stated? For example, modifying the set of redacted fields changes how event IDs are calculated, thus requiring a new room version.
  • Are backwards-compatibility concerns appropriately addressed?
  • Are the endpoint conventions honoured?
    • Do HTTP endpoints use_underscores_like_this?
    • Will the endpoint return unbounded data? If so, has pagination been considered?
    • If the endpoint utilises pagination, is it consistent with the appendices?
  • An introduction exists and clearly outlines the problem being solved. Ideally, the first paragraph should be understandable by a non-technical audience.
  • All outstanding threads are resolved
    • All feedback is incorporated into the proposal text itself, either as a fix or noted as an alternative
  • While the exact sections do not need to be present, the details implied by the proposal template are covered. Namely:
    • Introduction
    • Proposal text
    • Potential issues
    • Alternatives
    • Dependencies
  • Stable identifiers are used throughout the proposal, except for the unstable prefix section
    • Unstable prefixes consider the awkward accepted-but-not-merged state
    • Chosen unstable prefixes do not pollute any global namespace (use “org.matrix.mscXXXX”, not “org.matrix”).
  • Changes have applicable Sign Off from all authors/editors/contributors
  • There is a dedicated "Security Considerations" section which detail any possible attacks/vulnerabilities this proposal may introduce, even if this is "None.". See RFC3552 for things to think about, but in particular pay attention to the OWASP Top Ten.

Comment on lines +96 to +98
If a requested delay exceeds this maximum, the homeserver will respond with HTTP 400
and a [standard error response](https://spec.matrix.org/v1.18/client-server-api/#standard-error-response)
with an `errcode` of `M_INVALID_PARAM`.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To go even further with #4140 (comment), how about returning M_FORBIDDEN & HTTP 403 even for this case of requesting a delay longer than allowed?

This would prevent needing a special case error response for delayed events being entirely disallowed, as both that case & this one would then both give the same response.

It also looks like the spec uses M_INVALID_PARAM only for parameter values that are always invalid (like a malformed room alias or MXID), as opposed to values that are disallowed by server config that may change later.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Erm, actually, the special case would still be needed for when the maximum per-user amount of delayed events is 0, lest the response would be M_LIMIT_EXCEEDED & HTTP 429 for a limit that can never be satisfied.

But the point stands about M_FORBIDDEN & HTTP 403 potentially being more appropriate than M_INVALID_PARAM / HTTP 400.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the interest of progressing with the Synapse implementation of MSC4140 error codes (PR), I've committed this change as 9447ee0.

I've also updated the PR description accordingly.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But the point stands about M_FORBIDDEN & HTTP 403 potentially being more appropriate than M_INVALID_PARAM / HTTP 400.

This sounds sensible to me.

Also reword the special case error response now that only the 0-limit
case is special

The `delay_id` is an [opaque identifier](https://spec.matrix.org/v1.18/appendices/#opaque-identifiers)
generated by the homeserver.
It MUST be globally unique and SHOULD be cryptographically secure (in the sense that it is infeasible to predict).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's a mismatch here with the wording in the Security considerations – Authentication section below, which says

As such, generated delay_ids MUST be cryptographically random such that they are difficult to guess.

  1. "cryptographically random" vs. "cryptographically secure" – I think a more accurate and unambiguous wording in both places would be something like

    generated using a CSPRNG (Cryptographically Secure Pseudorandom Number Generator) and has sufficient entropy

  2. MUST vs. SHOULD – I would change the SHOULD here to MUST, because that's what the authentication for these endpoints through knowledge of delay_id relies on.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A bit later, "the cryptographic security of the delay_id" is mentioned again, which reads a bit weird to me. Alternatives that would sound better to me are for example

  • the CSPRNG-generated delay_id, or
  • the cryptographic randomness of the delay_id, or
  • the unpredictability of the delay_id.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A bit later, "the cryptographic security of the delay_id" is mentioned again, which reads a bit weird to me. Alternatives that would sound better to me are for example

* the CSPRNG-generated `delay_id`, or

* the cryptographic randomness of the `delay_id`, or

* the unpredictability of the `delay_id`.

This part was resolved in 5dac49c. The original comment above is still open though.

Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
Comment thread proposals/4140-delayed-events-futures.md Outdated
However, this is not strictly necessary for delayed events to be usable, and may thus be discussed in a separate MSC
in the interest of keeping this MSC focused on the core functionality of delayed events.

## Security considerations

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

An aspect I'm missing here is the fact that the POST /delayed_events/{delay_id}/{action} and GET /_matrix/client/v1/delayed_events/{delay_id} endpoints are including the delay_id, which is aptly described to "behave as a scoped access token". This risks a delay_id, i.e. an access token, getting leaked to various logs.

Can this risk be avoided / reduced by putting the delay_id in a header field or the request body instead? If there's technical reasons to not do that, this should at least be mentioned in the Security Considerations.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I suspect the main reason is that in the path in makes for a very natural REST API shape.

I think putting it into the body would require changing GET /_matrix/client/v1/delayed_events/{delay_id} to POST. It's not as nice an API but would probably work.

As a header, we could leave the HTTP method unchanged. The API shape strikes me as equally odd but technically it should also be possible.

@AndrewFerr curious what you think? Have I missed any reasons why this needs to be in the path?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, the main reason is to be able to use the delay_id as a typical "identifier" token.

Besides, there's limited effectiveness in trying to hide a delay_id by moving it into request headers / body / elsewhere, because it will nevertheless appear in client logs via /sync responses once its associated event gets sent, as per delay_id in unsigned event data.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it will nevertheless appear in client logs via /sync responses once its associated event gets sent

But once the event gets sent, is there even a need to keep the delay_id secret any longer? Aren't all of the delay_id's access token capabilities void once the respective event is finalised?

See this part of the MSC:

If the target delayed event is already finalised with an outcome that conflicts with the action, i.e. if the action is send or restart and the delayed event has already been cancelled, or if the action is cancel and the delayed event has already been sent, the homeserver will respond with HTTP 409 and a standard error response with an errcode of M_UNKNOWN.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But once the event gets sent, is there even a need to keep the delay_id secret any longer? Aren't all of the delay_id's access token capabilities void once the respective event is finalised?

Good point, that's correct.

In the interest of unblocking this, I'll split off the delegation feature into its own MSC. For now, I've moved it to an alternative: cd878d2


With that out of the way, I'll say that I'm still hesitant to protect delay_ids as much as access tokens, for a few reasons:

  • It would preclude future endpoints from being able to use delay_ids in ways that would "leak" them by design. A realistic possible addition is for /sync to include information about newly-scheduled delayed events (so that clients other than the one that scheduled an event would be notified of it, instead of having to manually hit the lookup endpoint to discover it).
  • It may add friction against migrating to using OAuth 2.0 scopes for the management endpoints.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

With the delegation removed from this MSC, and the management endpoints being authenticated, I'm obviously fine with the security considerations in this MSC 👍

I'd be interested to see the additional delegation MSC when it's ready though – especially how it plans to deal with the authentication for the management endpoints prescribed in this MSC – and I think it would be good the mention the concerns form your comment about the handling of the delay_id there.


#### `delay_id` in `unsigned` event data
The `delay_id` of a sent delayed event MUST be included in the resulting room event's `unsigned` data
if, and only if, the client being given the event is authenticated as the event's sender.

This comment was marked as resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

00-weekly-pings Tracking for weekly pings in the SCT office. 00 to make it first in the labels list. A-Client Server Client-Server API A-VOIP disposition-merge Process state. kind:feature MSC for not-core and not-maintenance stuff matrix-2.0 Required for Matrix 2.0 (note: do not rename - used in reports/links) proposal A matrix spec change proposal. Process state. proposed-final-comment-period Currently awaiting signoff of a majority of team members in order to enter the FCP. Process state.

Projects

Status: Ready for FCP ticks

Development

Successfully merging this pull request may close these issues.