Skip to content

feat(federation_domain_whitelist): support wildcards - #289

Open
lukaslihotzki-f wants to merge 1 commit into
masterfrom
ll/wildcard
Open

lukaslihotzki-f wants to merge 1 commit into
masterfrom
ll/wildcard

Conversation

@lukaslihotzki-f

Copy link
Copy Markdown
Contributor

Pull Request Checklist

  • In the description of your pull request:
    • Describe your change in a way that makes sense to users. "Fixed a bug that prevented receiving messages from other servers." instead of "Moved X method from EventStore to EventWorkerStore.".
    • Use markdown where necessary, mostly for code blocks.
    • End with either a period (.) or an exclamation mark (!).
    • Start with a capital letter.
    • Feel free to credit yourself, by adding a sentence "Contributed by @github_username." or "Contributed by [Your Name]." to the end of the entry.
  • Code style is correct (run the linters)

@lukaslihotzki-f
lukaslihotzki-f requested a review from a team as a code owner October 1, 2026 22:09
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 47.82609% with 12 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.06%. Comparing base (9005cfc) to head (f34d155).

Files with missing lines Patch % Lines
synapse/config/federation.py 53.33% 5 Missing and 2 partials ⚠️
synapse/media/media_repository.py 33.33% 0 Missing and 2 partials ⚠️
synapse/federation/transport/server/_base.py 50.00% 0 Missing and 1 partial ⚠️
synapse/http/matrixfederationclient.py 0.00% 0 Missing and 1 partial ⚠️
synapse/rest/key/v2/remote_key_resource.py 50.00% 0 Missing and 1 partial ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master     #289      +/-   ##
==========================================
- Coverage   81.07%   81.06%   -0.02%     
==========================================
  Files         509      509              
  Lines       73447    73459      +12     
  Branches    11124    11128       +4     
==========================================
+ Hits        59546    59548       +2     
- Misses      10588    10596       +8     
- Partials     3313     3315       +2     
Files with missing lines Coverage Δ
synapse/federation/transport/server/_base.py 75.64% <50.00%> (ø)
synapse/http/matrixfederationclient.py 83.22% <0.00%> (-0.21%) ⬇️
synapse/rest/key/v2/remote_key_resource.py 82.95% <50.00%> (ø)
synapse/media/media_repository.py 75.57% <33.33%> (ø)
synapse/config/federation.py 82.22% <53.33%> (-11.72%) ⬇️

... and 3 files with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 9005cfc...f34d155. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jason-famedly

Copy link
Copy Markdown
Member

This will need a few more tests, at the very least. Need to check the wildcard behavior does not include the naked bare domain. So if *.example.com is in the allow list, example.com is successfully rejected and etc.

I wonder if this would be better served with a regex solution? Perhaps with an in-memory cache to assist long term avoiding re-processing the same server name repeatedly. Even if we keep the existing parsing solution, this may be worth the effort. 🤔 Needs thought

Prior (unfinished) art: matrix-org/synapse#13424

Upstream issues for this:

I have no opinion on if it should be upstreamed or not

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants