MatrixSynapse/synapse/config
Andrew Morgan 094896a69d
Add a config option for validating 'next_link' parameters against a domain whitelist (#8275)
This is a config option ported over from DINUM's Sydent: https://github.com/matrix-org/sydent/pull/285

They've switched to validating 3PIDs via Synapse rather than Sydent, and would like to retain this functionality.

This original purpose for this change is phishing prevention. This solution could also potentially be replaced by a similar one to https://github.com/matrix-org/synapse/pull/8004, but across all `*/submit_token` endpoint.

This option may still be useful to enterprise even with that safeguard in place though, if they want to be absolutely sure that their employees don't follow links to other domains.
2020-09-08 16:03:09 +01:00
..
__init__.py
__main__.py
_base.py Stop sub-classing object (#8249) 2020-09-04 06:54:56 -04:00
_base.pyi Revert "Add experimental support for sharding event persister. (#8170)" (#8242) 2020-09-04 10:19:42 +01:00
_util.py Implement login blocking based on SAML attributes (#8052) 2020-08-11 16:08:10 +01:00
api.py
appservice.py
cache.py Stop sub-classing object (#8249) 2020-09-04 06:54:56 -04:00
captcha.py
cas.py
consent_config.py
database.py Rename database classes to make some sense (#8033) 2020-08-05 21:38:57 +01:00
emailconfig.py Use the default templates when a custom template file cannot be found (#8037) 2020-08-17 17:05:00 +01:00
federation.py Update worker docs with recent enhancements (#7969) 2020-07-29 23:22:13 +01:00
groups.py
homeserver.py Update worker docs with recent enhancements (#7969) 2020-07-29 23:22:13 +01:00
jwt_config.py
key.py Stop sub-classing object (#8249) 2020-09-04 06:54:56 -04:00
logger.py Fix stack overflow when logging system encounters an error (#8268) 2020-09-07 16:54:30 +01:00
metrics.py Stop sub-classing object (#8249) 2020-09-04 06:54:56 -04:00
oidc_config.py
password.py
password_auth_providers.py
push.py
ratelimiting.py Stop sub-classing object (#8249) 2020-09-04 06:54:56 -04:00
redis.py Update worker docs with recent enhancements (#7969) 2020-07-29 23:22:13 +01:00
registration.py Various improvements to the docs (#7899) 2020-07-29 10:35:44 -04:00
repository.py
room.py Stop sub-classing object (#8249) 2020-09-04 06:54:56 -04:00
room_directory.py Stop sub-classing object (#8249) 2020-09-04 06:54:56 -04:00
saml2_config.py Fix a regression from calling read_templates. (#8252) 2020-09-04 09:10:33 -04:00
server.py Add a config option for validating 'next_link' parameters against a domain whitelist (#8275) 2020-09-08 16:03:09 +01:00
server_notices_config.py
spam_checker.py
sso.py Use the default templates when a custom template file cannot be found (#8037) 2020-08-17 17:05:00 +01:00
stats.py
third_party_event_rules.py
tls.py
tracer.py
user_directory.py
voip.py
workers.py Revert "Add experimental support for sharding event persister. (#8170)" (#8242) 2020-09-04 10:19:42 +01:00