mirror of
https://github.com/spantaleev/matrix-docker-ansible-deploy.git
synced 2026-09-12 19:03:14 +00:00
Enable the appservice encryption MSCs on Synapse for Hookshot too
Hookshot's end-to-bridge encryption needs MSC2409 and MSC3202 enabled on the homeserver, but the playbook only turned them on for Meowlnir. Hookshot's encryption defaults to the playbook-wide `matrix_bridges_encryption_enabled` toggle, so turning that on gave Hookshot encryption against a Synapse which was not set up for it, and Hookshot then struggled in encrypted rooms. The playbook already wires up Hookshot's other encryption prerequisite (Valkey) and fails the run when the Redis settings are missing, so being only half-automatic here was the odd one out. Synapse sends the extra data only to appservices which ask for it in their registration file, so turning these on affects no other component. The documentation told Hookshot users to set the two Synapse variables by hand, and argued they should be enabled deliberately. That contradicted what we already do for Meowlnir, so it is gone; the note now matches the Meowlnir one and points out that other homeserver implementations still need arranging by hand. Closes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/5506 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
fdf3c13e66
commit
aef0fad8b5
@@ -5161,9 +5161,21 @@ matrix_synapse_ext_synapse_http_antispam_config_enabled_callbacks: "{{ matrix_bo
|
||||
matrix_synapse_ext_synapse_http_antispam_config_fail_open: "{{ matrix_bot_draupnir_synapse_http_antispam_config_fail_open if matrix_bot_draupnir_config_web_synapseHTTPAntispam_enabled else (matrix_bot_meowlnir_synapse_http_antispam_config_fail_open if matrix_bot_meowlnir_synapse_http_antispam_enabled else {}) }}"
|
||||
matrix_synapse_ext_synapse_http_antispam_config_async: "{{ matrix_bot_draupnir_synapse_http_antispam_config_async if matrix_bot_draupnir_config_web_synapseHTTPAntispam_enabled else (matrix_bot_meowlnir_synapse_http_antispam_config_async if matrix_bot_meowlnir_synapse_http_antispam_enabled else {}) }}"
|
||||
|
||||
# Meowlnir's bots need these to support end-to-end encryption.
|
||||
matrix_synapse_experimental_features_msc2409_to_device_messages_enabled: "{{ matrix_bot_meowlnir_enabled and matrix_bot_meowlnir_config_encryption_enable }}"
|
||||
matrix_synapse_experimental_features_msc3202_transaction_extensions_enabled: "{{ matrix_bot_meowlnir_enabled and matrix_bot_meowlnir_config_encryption_enable }}"
|
||||
# Meowlnir's bots and Hookshot need these to support end-to-end encryption.
|
||||
# Synapse only sends the extra data to appservices which ask for it in their registration file,
|
||||
# so enabling these affects no other component.
|
||||
matrix_synapse_experimental_features_msc2409_to_device_messages_enabled: |-
|
||||
{{
|
||||
(matrix_bot_meowlnir_enabled and matrix_bot_meowlnir_config_encryption_enable)
|
||||
or
|
||||
(matrix_bridge_hookshot_enabled and matrix_bridge_hookshot_encryption_enabled)
|
||||
}}
|
||||
matrix_synapse_experimental_features_msc3202_transaction_extensions_enabled: |-
|
||||
{{
|
||||
(matrix_bot_meowlnir_enabled and matrix_bot_meowlnir_config_encryption_enable)
|
||||
or
|
||||
(matrix_bridge_hookshot_enabled and matrix_bridge_hookshot_encryption_enabled)
|
||||
}}
|
||||
|
||||
# Enable Synapse statistics reporting when using synapse-usage-exporter
|
||||
matrix_synapse_report_stats: "{{ matrix_synapse_usage_exporter_enabled }}"
|
||||
|
||||
Reference in New Issue
Block a user