Add labs option to exclude unverified devices (#92)
Add a labs option which will, when set, switch into the "invisible crypto" mode of refusing to send keys to, or decrypt messages from, devices that have not been signed by their owner.
This commit is contained in:
parent
8962e8cdd3
commit
be2c1fcf64
7 changed files with 89 additions and 0 deletions
|
@ -11,6 +11,7 @@ import React, { ReactNode } from "react";
|
|||
import { UNSTABLE_MSC4133_EXTENDED_PROFILES } from "matrix-js-sdk/src/matrix";
|
||||
|
||||
import { _t, _td, TranslationKey } from "../languageHandler";
|
||||
import DeviceIsolationModeController from "./controllers/DeviceIsolationModeController.ts";
|
||||
import {
|
||||
NotificationBodyEnabledController,
|
||||
NotificationsEnabledController,
|
||||
|
@ -309,6 +310,16 @@ export const SETTINGS: { [setting: string]: ISetting } = {
|
|||
supportedLevelsAreOrdered: true,
|
||||
default: false,
|
||||
},
|
||||
"feature_exclude_insecure_devices": {
|
||||
isFeature: true,
|
||||
labsGroup: LabGroup.Encryption,
|
||||
controller: new DeviceIsolationModeController(),
|
||||
displayName: _td("labs|exclude_insecure_devices"),
|
||||
description: _td("labs|exclude_insecure_devices_description"),
|
||||
supportedLevels: LEVELS_DEVICE_ONLY_SETTINGS_WITH_CONFIG_PRIORITISED,
|
||||
supportedLevelsAreOrdered: true,
|
||||
default: false,
|
||||
},
|
||||
"useOnlyCurrentProfiles": {
|
||||
supportedLevels: LEVELS_ACCOUNT_SETTINGS,
|
||||
displayName: _td("settings|disable_historical_profile"),
|
||||
|
|
37
src/settings/controllers/DeviceIsolationModeController.ts
Normal file
37
src/settings/controllers/DeviceIsolationModeController.ts
Normal file
|
@ -0,0 +1,37 @@
|
|||
/*
|
||||
Copyright 2024 New Vector Ltd.
|
||||
SPDX-License-Identifier: AGPL-3.0-only OR GPL-3.0-only
|
||||
Please see LICENSE files in the repository root for full details.
|
||||
*/
|
||||
|
||||
import { AllDevicesIsolationMode, OnlySignedDevicesIsolationMode } from "matrix-js-sdk/src/crypto-api";
|
||||
import { MatrixClient } from "matrix-js-sdk/src/matrix";
|
||||
|
||||
import SettingController from "./SettingController";
|
||||
import { MatrixClientPeg } from "../../MatrixClientPeg";
|
||||
import { SettingLevel } from "../SettingLevel";
|
||||
|
||||
/**
|
||||
* A controller for the "exclude_insecure_devices" setting, which will
|
||||
* update the crypto stack's device isolation mode on change.
|
||||
*/
|
||||
export default class DeviceIsolationModeController extends SettingController {
|
||||
public onChange(level: SettingLevel, roomId: string, newValue: any): void {
|
||||
setDeviceIsolationMode(MatrixClientPeg.safeGet(), newValue);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Set the crypto stack's device isolation mode based on the current value of the
|
||||
* "exclude_insecure_devices" setting.
|
||||
*
|
||||
* @param client - MatrixClient to update to the new setting.
|
||||
* @param settingValue - value of the "exclude_insecure_devices" setting.
|
||||
*/
|
||||
export function setDeviceIsolationMode(client: MatrixClient, settingValue: boolean): void {
|
||||
client
|
||||
.getCrypto()
|
||||
?.setDeviceIsolationMode(
|
||||
settingValue ? new OnlySignedDevicesIsolationMode() : new AllDevicesIsolationMode(true),
|
||||
);
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue