Skip to content
This repository was archived by the owner on Apr 26, 2024. It is now read-only.

Raise the default power levels for invites, tombstones and server acls#6834

Merged
anoadragon453 merged 6 commits into
developfrom
anoa/update_default_pls
Feb 17, 2020
Merged

Raise the default power levels for invites, tombstones and server acls#6834
anoadragon453 merged 6 commits into
developfrom
anoa/update_default_pls

Conversation

@anoadragon453
Copy link
Copy Markdown
Member

@anoadragon453 anoadragon453 commented Feb 3, 2020

This PR makes the following changes to the default power levels power levels generated by /createRoom by default:

  • Raises invites to be PL 50
  • Raises tombstones to be PL 100
  • Raises server ACLs to be PL 100

Sytests: matrix-org/sytest#805

@anoadragon453 anoadragon453 requested a review from a team February 3, 2020 15:51
Comment thread synapse/handlers/room.py Outdated
Comment thread synapse/handlers/room.py Outdated
Comment thread synapse/handlers/room.py Outdated
@aaronraimist
Copy link
Copy Markdown
Contributor

Why is invite changing?

@richvdh
Copy link
Copy Markdown
Member

richvdh commented Feb 17, 2020

@aaronraimist: spam, in a word.

Copy link
Copy Markdown
Member

@richvdh richvdh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@anoadragon453 anoadragon453 merged commit 3404ad2 into develop Feb 17, 2020
@anoadragon453 anoadragon453 deleted the anoa/update_default_pls branch February 17, 2020 13:23
@jplatte
Copy link
Copy Markdown
Contributor

jplatte commented Oct 26, 2020

@aaronraimist: spam, in a word.

Is there a detailed explanation about this somewhere?

@richvdh
Copy link
Copy Markdown
Member

richvdh commented Apr 5, 2022

Is there a detailed explanation about this somewhere?

From an internal issue:

This means that an invite spammer can sabotage a public room by joining it and then inviting thousands of users to it, encouraging moderators to shutdown the room to mitigate the spam.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants