{"id":20218031,"url":"https://github.com/matrix-org/matrix-user-verification-service","last_synced_at":"2025-04-10T15:45:30.272Z","repository":{"id":48482891,"uuid":"290480507","full_name":"matrix-org/matrix-user-verification-service","owner":"matrix-org","description":"Service to verify details of a user based on a Open ID token.","archived":false,"fork":false,"pushed_at":"2023-07-05T13:29:42.000Z","size":165,"stargazers_count":24,"open_issues_count":11,"forks_count":21,"subscribers_count":8,"default_branch":"master","last_synced_at":"2025-03-24T13:36:14.614Z","etag":null,"topics":["matrix","microservice","synapse"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/matrix-org.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-08-26T11:41:54.000Z","updated_at":"2025-01-11T04:04:52.000Z","dependencies_parsed_at":"2023-01-21T18:46:55.886Z","dependency_job_id":null,"html_url":"https://github.com/matrix-org/matrix-user-verification-service","commit_stats":null,"previous_names":[],"tags_count":5,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matrix-org%2Fmatrix-user-verification-service","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matrix-org%2Fmatrix-user-verification-service/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matrix-org%2Fmatrix-user-verification-service/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/matrix-org%2Fmatrix-user-verification-service/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/matrix-org","download_url":"https://codeload.github.com/matrix-org/matrix-user-verification-service/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248243509,"owners_count":21071055,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["matrix","microservice","synapse"],"created_at":"2024-11-14T06:36:53.808Z","updated_at":"2025-04-10T15:45:30.251Z","avatar_url":"https://github.com/matrix-org.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Matrix User Verification Service\n\nService to verify details of a user based on an Open ID Connect token.\n\nMain features:\n\n* Verifies a C2S [Open ID token](https://matrix.org/docs/spec/client_server/r0.6.1#id154)\n  using the S2S [UserInfo endpoint](https://matrix.org/docs/spec/server_server/r0.1.4#openid).\n* Can verify user is a member in a given room (Synapse only currently, requires admin level token).\n  In addition to returning membership status, returned will be user power level, the room power \n  defaults and required power for events.\n\n## How to use\n\n### Dependencies\n\n```\nnpm install\n```\n\n### Configuration\n\nCopy the default `.env.default` to `.env` and modify as needed.\n\n```\n## REQUIRED\n# Homeserver client API admin token (synapse only)\n# Required for the service to verify room membership\nUVS_ACCESS_TOKEN=foobar\n# Homeserver client API URL\nUVS_HOMESERVER_URL=https://matrix.org\n# Disable check for non private IP range of homeserver. E.g. set to `true` if your homeserver domain resolves to a private IP.\nUVS_DISABLE_IP_BLACKLIST=true\n\n## OPTIONAL\n# Auth token to protect the API\n# If this is set any calls to the provided API endpoints\n# need have the header \"Authorization: Bearer changeme\".\nUVS_AUTH_TOKEN=changeme\n# Matrix server name to verify OpenID tokens against. See below section.\n# Defaults to empty value which means verification is made against\n# whatever Matrix server name passed in with the token.\nUVS_OPENID_VERIFY_SERVER_NAME=matrix.org\n# Listen address of the bot\nUVS_LISTEN_ADDRESS=127.0.0.1\n# Listen port of the bot\nUVS_PORT=3000\n# Log level, defaults to 'info'\n# See choices here: https://github.com/winstonjs/winston#logging-levels\nUVS_LOG_LEVEL=info\n```\n\n#### OpenID token verification\n\nUVS can run in a single homeserver mode or be configured to trust any\nhomeserver OpenID token. Default is to trust the any Matrix server name\nthat is given with the OpenID token.\n\nTo disable this and ensure only OpenID tokens from a single Matrix homeserver\nwill be trusted, set the homeserver Matrix server name in the variable\n`UVS_OPENID_VERIFY_SERVER_NAME`. Note, this is the server name of the homeserver,\nnot the client or federation API's domain.\n\nIn either mode, the [UserInfo endpoint](https://matrix.org/docs/spec/server_server/r0.1.4#openid)\nis determined by [resolving server names in the usual way](https://matrix.org/docs/spec/server_server/latest#resolving-server-names)\nso a `/.well-known/matrix/server` file may be needed even if the homeserver\nisn't otherwise federating. If the homeserver config doesn't have the `federation`\nlistener setup, the `openid` listener can be added on the same port as the `client`\nlistener.\n\nRoom membership is still currently limited to be verified from a single\nconfigured homeserver client API via `UVS_HOMESERVER_URL`.\n\n### API's available\n\n### Authentication\n\nIf `UVS_AUTH_TOKEN` is set, you'll need to provide an authorization header as follows:\n\n    Authorization: Bearer \u003cvalue of UVS_AUTH_TOKEN\u003e\n\n#### Verify OpenID token\n\nVerifies a user OpenID token.\n\n    POST /verify/user\n    Content-Type: application/json\n\nRequest body:\n\n```json\n{\n  \"matrix_server_name\": \"domain.tld\",\n  \"token\": \"secret OpenID token provided by the user\"\n}\n```\n\nSuccessful validation response:\n\n```json\n{\n  \"results\": {\n    \"user\": true\n  },\n  \"user_id\": \"@user:domain.tld\"\n}\n```\n\nFailed validation:\n\n```json\n{\n  \"results\": {\n    \"user\": false\n  },\n  \"user_id\": null\n}\n```\n\n#### Verify OpenID token and room membership\n\nVerifies a user OpenID token and membership in a room.\n\n    POST /verify/user_in_room\n    Content-Type: application/json\n\nRequest body:\n\n```json\n{\n  \"matrix_server_name\": \"domain.tld\",\n  \"room_id\": \"!foobar:domain.tld\",\n  \"token\": \"secret OpenID token provided by the user\"\n}\n```\n\nSuccessful validation response:\n\n```json\n{\n  \"results\": {\n    \"room_membership\": true,\n    \"user\": true\n  },\n  \"user_id\": \"@user:domain.tld\",\n  \"power_levels\": {\n    \"room\": {\n      \"ban\": 50,\n      \"events\": {\n        \"m.room.avatar\": 50,\n        \"m.room.canonical_alias\": 50,\n        \"m.room.history_visibility\": 100,\n        \"m.room.name\": 50,\n        \"m.room.power_levels\": 100\n      },\n      \"events_default\": 0,\n      \"invite\": 0,\n      \"kick\": 50,\n      \"redact\": 50,\n      \"state_default\": 50,\n      \"users_default\": 0\n    },\n    \"user\": 50\n  }\n}\n```\n\nFailed validation, in case token is not valid:\n\n```json\n{\n  \"results\": {\n    \"room_membership\": false,\n    \"user\": false\n  },\n  \"user_id\": null,\n  \"power_levels\": null\n}\n```\n\nIn the token was validated but user is not in room, the failed response is:\n\n```json\n{\n  \"results\": {\n    \"room_membership\": false,\n    \"user\": true\n  },\n  \"user_id\": \"@user:domain.tld\",\n  \"power_levels\": null\n}\n```\n\n### Running\n\n```\nnpm start\n```\n\n### Development\n\nRun in watch mode.\n\n```\nnpm run dev\n```\n\n## License\n\nApache 2.0\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmatrix-org%2Fmatrix-user-verification-service","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmatrix-org%2Fmatrix-user-verification-service","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmatrix-org%2Fmatrix-user-verification-service/lists"}