matrix.org/content/blog/2023/05/2023-05-05-twim.md

249 lines
15 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

+++
date = "2023-05-05"
title = "This Week in Matrix 2023-05-05"
path = "/blog/2023/05/05/this-week-in-matrix-2023-05-05"
[taxonomies]
category = ["This Week in Matrix"]
author = ["Thib"]
+++
## Matrix Live
{{ youtube_player(video_id="4KlNILNItGQ") }}
## Dept of Social Good 🙆
[Denise](https://matrix.to/#/@denisea:element.io) announces
> we know there have been some questions about the recent ban on Element by the Indian Central Government. We are still trying to get answers ourselves and have put out a public statement on our understanding of the situation so far: https://element.io/blog/india-bans-flagship-client-for-the-matrix-network/
## Dept of Spec 📜
[Andrew Morgan (anoa)](https://matrix.to/#/@andrewm:element.io) reports
> Here's your weekly spec update! The heart of Matrix is the specification - and this is modified by Matrix Spec Change (MSC) proposals. Learn more about how the process works at https://spec.matrix.org/proposals.
>
>
> ## MSC Status
>
> **New MSCs:**
> * [MSC4011: Thumbnail media negotiation](https://github.com/matrix-org/matrix-spec-proposals/pull/4011)
> * [MSC4010: Push rules and account data](https://github.com/matrix-org/matrix-spec-proposals/pull/4010)
> * [MSC4009: E.164 Matrix IDs](https://github.com/matrix-org/matrix-spec-proposals/pull/4009)
> * [MSC4006: "completed elsewhere" hangup reason.](https://github.com/matrix-org/matrix-spec-proposals/pull/4006)
> * [MSC4005: Explicit read receipts for sent events](https://github.com/matrix-org/matrix-spec-proposals/pull/4005)
>
> **MSCs in Final Comment Period:**
> * [MSC3882: Allow an existing session to sign in a new session](https://github.com/matrix-org/matrix-spec-proposals/pull/3882) (merge)
> * [MSC3860: Media Download Redirects](https://github.com/matrix-org/matrix-spec-proposals/pull/3860) (merge)
> * [MSC2659: Application service ping endpoint](https://github.com/matrix-org/matrix-spec-proposals/pull/2659) (merge)
> * [MSC2463: Exclusion of MXIDs in push rules content matching](https://github.com/matrix-org/matrix-spec-proposals/pull/2463) (close)
> * [MSC2249: Require users to have visibility on an event when submitting reports](https://github.com/matrix-org/matrix-spec-proposals/pull/2249) (merge)
>
> **Accepted MSCs:**
> * *No MSCs were accepted this week.*
>
> **Closed MSCs:**
> * *No MSCs were closed/rejected this week.*
>
> ## Spec Updates
> Lots of MSCs moving through the pipeline this week! Plus a myriad of [spec changes](https://github.com/matrix-org/matrix-spec/pulls?q=is%3Apr+is%3Aclosed) too! The spec seems to be gently humming along.
>
> In other news, the next release of the spec, v1.7, is coming up in the not-too-distant future. In keeping with our roughly quarterly release schedule - the release of v1.6 was on February 14th, 2023 - a new release of the spec should come some time in next few weeks.
>
> We haven't set a date yet, but expect to do so soon. So watch this space!
>
> ## Random MSC of the Week
>
> The random MSC of the week is... [MSC3741: Revealing the useful login flows to clients after a soft logout](https://github.com/matrix-org/matrix-spec-proposals/pull/3741)!
>
> This MSC fixes an edge case in the spec. Imagine the following scenario. You're logged into your homeserver via an SSO flow (let's say by signing into GitLab), and then you try to change your password on GitLab. Doing so may cause a "soft logout" to occur for your Matrix client. A soft logout, by the way, happens when your access token is invalidated, but your client is told explicitly not to wipe its local state (including encryption keys).
>
> Your Matrix client is telling you to log back in again, and in doing so calls out to the [`GET /_matrix/client/v3/login`](https://spec.matrix.org/v1.6/client-server-api/#get_matrixclientv3login) endpoint to see what login methods are available. Your homeserver supports both password-based and SSO-based login, so that's what you get back. Your client happily presents you both options. You try to type your GitLab password, but it's incorrect. And you've just given your GitLab password to this Matrix homeserver in plaintext - oh no!
>
> The problem here stems from the fact that `GET /login` is unauthenticated. The homeserver doesn't know who you are when you attempt to log in again, and thus can't tailor the available login methods to those that make sense for you. This MSC aims to fix this by having your Matrix client, upon trying to learn how to log in again after a soft logout, provide your expired access token in an `Authorization` request header. The homeserver can then check and see that 1) you were just soft logout'd and 2) you are an account that is authorised via SSO - so it doesn't make sense to suggest you log in again via a password specific to your Matrix homeserver!
>
> While this MSC discusses a valuable solution, it is worth considering that the [User-Interactive Authentication system](https://spec.matrix.org/v1.6/client-server-api/#user-interactive-authentication-api) as a whole is going to be completely replaced by OpenID Connect instead, which will make this problem (and solution) moot. Still, that day is not here yet, so if you suffer from this problem today, this may be one method to deal with it.
<!-- more -->
## Dept of Servers 🏢
### Synapse ([website](https://github.com/matrix-org/synapse/))
Synapse is a Matrix homeserver implementation developed by the matrix.org core team
[Shay](https://matrix.to/#/@shayshay:matrix.org) reports
> It's yet another Friday which means TWIM day. This week the backend team
> released Synapse v1.83.0rc1. Notable highlights include:
>
> * Add an [admin API endpoint](https://matrix-org.github.io/synapse/v1.83/admin_api/statistics.html#get-largest-rooms-by-size-in-database) to query the largest rooms by disk space used in the database.
> * Add Nginx loadbalancing example with sticky mxid for workers
> * Disable push rule evaluation for rooms excluded from sync.
> * Add experimental support for [MSC3970](https://github.com/matrix-org/matrix-spec-proposals/pull/3970): Scope transaction IDs to devices.
>
> And so much more! To read about everything in the release, take a look at the release notes [here](https://github.com/matrix-org/synapse/releases) and otherwise have a great week.
## Dept of Clients 📱
### Quadrix ([website](https://github.com/alariej/quadrix))
A Minimal, simple, multi-platform chat client for the Matrix protocol.
[JFA](https://matrix.to/#/@alariej:matrix.org) says
> Version 1.6.5 of Quadrix (Matrix client for mobiles and desktops) has been released and is available in the respective app stores.
>
> The latest changes include the replacement of the Jitsi Meet videoconferencing functionality with an embedded version of Element Call, using matrix-widget-api. Quadrix loads the Element Call web app located at https://element-call.netlify.app, which is the continually updated dev version. The Quadrix implementation is not quite compatible with Element Web, since it uses non-encrypted WebRTC signalling, but that's something I'll be working on in the next weeks.
>
> Please go test-drive Element Call in Quadrix and leave feedback/comments at [#quadrix:matrix.org](https://matrix.to/#/#quadrix:matrix.org) or in the issues at https://github.com/alariej/quadrix (stars welcome :-)
### Element Web/Desktop ([website](https://github.com/vector-im/element-web))
Secure and independent communication, connected via Matrix. Come talk with us in [#element-web:matrix.org](https://matrix.to/#/#element-web:matrix.org)!
[andybalaam](https://matrix.to/#/@andybalaam:matrix.org) reports
> Were still on our stability drive!
>
> * Lots of bug fixing, including some progress on stuck unread messages. When were done, well ask people to check for incorrect unreads. Were not there yet, but were getting closer
> * Weve been improving the correctness of our Typescript code by updating it to conform to strict checking
> * Our accessibility work continues, with more small fixes
> * Were working on making our automated tests work better by fixing unreliable tests
> * We tightened our Content Security Policy to protect against the kinds of vulnerabilities we fixed in the last release
### Element Android ([website](https://github.com/vector-im/element-android))
Secure and independent communication for Android, connected via Matrix. Come talk with us in [#element-android:matrix.org](https://matrix.to/#/#element-android:matrix.org)!
[benoit](https://matrix.to/#/@benoit.marty:matrix.org) reports
> * We are getting ready to release Element Android 1.6.0 with the new Crypto Rust SDK (aka ElementR). This will delay the regular release. Also we will do a progressive roll out, as a safety measure.
> * This week we welcome Marco, who has started to work on the display of invitations in the list of members of a room in ElementX
### Element X Android ([website](https://github.com/vector-im/element-x-android))
Secure and independent communication for Android, connected via Matrix. Come talk with us in [#element-android:matrix.org](https://matrix.to/#/#element-android:matrix.org)!
[benoit](https://matrix.to/#/@benoit.marty:matrix.org) says
> On ElementX, we are working on media and file attachments. We are adding the picker and we are adding support for rendering attachment in the timeline.
> * On ElementX, we are working on media and file attachments. We are adding the picker and we are adding support for rendering attachment in the timeline.
### Element X iOS ([website](https://github.com/vector-im/element-x-ios))
Everything related to Element but not strictly bound to a client
[Ștefan](https://matrix.to/#/@stefan.ceriu:matrix.org) announces
> Happy Friday and happy Element X update day. This week we:
> * [Added support for uploading media](https://github.com/vector-im/element-x-ios/pull/851)
> * [Introduced a brand new room list contextual menu](https://github.com/vector-im/element-x-ios/pull/842)
> * [Got our first look at decrypting remote background notifications](https://github.com/vector-im/element-x-ios/pull/854)
> * Continued to make very good progress on OIDC support
> * And started working on rendering rich replies in the timeline
## Dept of SDKs and Frameworks 🧰
### libolm 🦎 ([website](https://gitlab.matrix.org/matrix-org/olm))
[uhoreg](https://matrix.to/#/@hubert:uhoreg.ca) says
> libolm is an implementation of the Olm and Megolm cryptographic ratchets used for end-to-end encryption in Matrix. libolm 3.2.15 has been released. This is mainly a maintenance release that improves the Python packaging and fixes a TypeScript issue. The biggest change is that the Python package can now be installed from pypi.org, the default repository for Python packages. The source package includes the libolm sources, so you do not need libolm to be installed separately any more. All you need is cmake (or possibly GNU make) and a C/C++ compiler, and run `pip install python-olm`. It unfortunately does not yet work on Windows, but should work on UNIX-like operating systems such as Linux and \*BSD, and even macOS.
>
> In other news: with Element iOS and Element Android switching to the rust crypto SDK, and hence using vodozemac, I'm considering deprecating the iOS and Android bindings for libolm. If you still need those bindings, please let me know.
## Dept of Ops 🛠
### Synapse Kubernetes Operator ([website](https://github.com/opdev/synapse-operator/))
[mgoerens](https://matrix.to/#/@mgoerens:matrix.org) says
> The Synapse operator provides a way to deploy Synapse, the Heisenbridge, and the Mautrix-Signal bridge on Kubernetes.
>
> ## Release v0.5.0 & v0.5.1
>
> It was time to cut a new release, though most of the changes are related to various internal improvements and experiments.
>
> Release v0.5.0 & v0.5.1 come with only a few user-facing changes:
>
> * Secrets in homeserver.yaml are now randomly generated.
> * When a bridge is deleted, it is now unregistered from Synapse.
> * Update container images to their latest available version to date, now deploying:
>
> - Synapse v1.82.0
> - Mautrix-signal v0.4.2
> - Signald 0.32.2
> - Heisenbridge 1.14 (no update since v0.4.0)
>
> If you want to learn more about internal changes, check the [release notes](https://github.com/opdev/synapse-operator/releases/tag/v0.5.1)
>
> And join the matrix room to chat about the project: https://matrix.to/#/#synapse-operator:matrix.org
>
> ## FOSDEM Video
>
> The replay of the presentation of this Kubernetes operator at FOSDEM, in the Matrix online devroom, is now available on Youtube: https://www.youtube.com/watch?v=Vsb18jr\_VDc
## Dept of Services 🚀
### MatrixRooms.info ([website](https://matrixrooms.info/))
A developers-managed instance of the standalone search engine built for matrix rooms discovery.
[Aine](https://matrix.to/#/@aine:etke.cc) reports
> During this week at [etke.cc](https://etke.cc/?utm_source=twim) we polished the Matrix Rooms Search service and implemented the following improvements:
>
> * Enabled language detection for all (75) supported languages and language analysis for all (29) supported languages by search engine
> * Added ability to report illegal rooms (please, keep in mind that we know nothing about the contents of the indexed rooms, so if you think something is illegal - describe it like ELI5, so anyone can read the reason and know for sure if that room should be removed or not)
> * Optimized avatars processing on UI
>
> Current index status: **233513** indexed rooms from **19919** matrix servers
>
> One more thing - we've created [Liberapay team](https://liberapay.com/mrs) to crowdfund the project's existence and we welcome everyone to donate and fund the future development and infrastructure costs 🙂
>
> [MatrixRooms.info](https://matrixrooms.info/), [Source code](https://gitlab.com/etke.cc/mrs), [#mrs:etke.cc](https://matrix.to/#/#mrs:etke.cc)
## Dept of Ping
Here we reveal, rank, and applaud the homeservers with the lowest ping, as measured by [pingbot](https://github.com/maubot/echo), a [maubot](https://github.com/maubot/maubot) that you can host on your own server.
### [#ping:maunium.net](https://matrix.to/#/#ping:maunium.net)
Join [#ping:maunium.net](https://matrix.to/#/#ping:maunium.net) to experience the fun live, and to find out how to add YOUR server to the game.
|Rank|Hostname|Median MS|
|:---:|:---:|:---:|
|1|test.zemos.net|418|
|2|norrland.xyz|426|
|3|matrix.weebl.me|652|
|4|matrix.lukeog.com|758|
|5|envs.net|845|
|6|willy.club|915|
|7|wcore.org|971|
|8|plocki.org|1191|
|9|poldrack.dev|1315.5|
|10|zemos.net|1665|
### [#ping-no-synapse:maunium.net](https://matrix.to/#/#ping-no-synapse:maunium.net)
Join [#ping-no-synapse:maunium.net](https://matrix.to/#/#ping-no-synapse:maunium.net) to experience the fun live, and to find out how to add YOUR server to the game.
|Rank|Hostname|Median MS|
|:---:|:---:|:---:|
|1|test.zemos.net|118|
|2|l1qu1d.net|160.5|
|3|pyrox.dev|388.5|
|4|777.tf|467|
|5|rustybever.be|513|
|6|zemos.net|514.5|
|7|matrix.org|583.5|
|8|herkulessi.de|816.5|
|9|chat.eutampieri.eu|1389.5|
## That's all I know
See you next week, and be sure to stop by [#twim:matrix.org](https://matrix.to/#/#twim:matrix.org) with your updates!