The Federation request authentication scheme (X-Matrix authentication header) depends on getting a copy of the request body and putting it as the content key into a JSON object, which is then serialised as Canonical JSON and signed.
This process implies that the server has to buffer the request body in order to re-emit it as Canonical JSON.
It's a performance hurdle as it means you can't start processing or streaming request bodies before they are fully buffered. This is therefore an impediment to proposals like MSC4512, but also seems to block some optimisations in high-performance homeservers.
However, it seems that it would more or less be fine if the X-Matrix header didn't depend on the content at all.
A signature of the message {origin, destination}, signed by the origin's signing key, would be sufficient at first glance to prove that the origin wanted to issue a request to the destination. A signature of this shape essentially creates a stateless access token.
There is a risk of this signature being leaked and re-used. (There is already the equivalent risk of a signing key being leaked, or of an entire request being leaked right now and replayed — although less interesting.)
But maybe this is fine as neither the origin nor destination is motivated to leak the signature as it has no use outside of that context.
A better improvement would be to add a validity timestamp, so a leaked signature can't be reused indefinitely. (At the end of the day, it essentially becomes a JWT, which has nbf and exp properties for this purpose.)
The Federation request authentication scheme (
X-Matrixauthentication header) depends on getting a copy of the request body and putting it as thecontentkey into a JSON object, which is then serialised as Canonical JSON and signed.This process implies that the server has to buffer the request body in order to re-emit it as Canonical JSON.
It's a performance hurdle as it means you can't start processing or streaming request bodies before they are fully buffered. This is therefore an impediment to proposals like MSC4512, but also seems to block some optimisations in high-performance homeservers.
However, it seems that it would more or less be fine if the
X-Matrixheader didn't depend on the content at all.A signature of the message
{origin, destination}, signed by the origin's signing key, would be sufficient at first glance to prove that the origin wanted to issue a request to the destination. A signature of this shape essentially creates a stateless access token.There is a risk of this signature being leaked and re-used. (There is already the equivalent risk of a signing key being leaked, or of an entire request being leaked right now and replayed — although less interesting.)
But maybe this is fine as neither the origin nor destination is motivated to leak the signature as it has no use outside of that context.
A better improvement would be to add a validity timestamp, so a leaked signature can't be reused indefinitely. (At the end of the day, it essentially becomes a JWT, which has
nbfandexpproperties for this purpose.)