!NPRUEisLjcaMtHIzDr:kamax.io

mxisd

259 Members
Federated Matrix Identity Server | https://github.com/kamax-io/mxisd | Version: 0.8.2 | Dev discussions: #mxisd-dev:kamax.io | Related: #matrix-identity:matrix.org104 Servers

Load older messages


SenderMessageTime
2 Jun 2019
@perflyst:snopyta.orgperflysti did not read them since v1.3, right16:19:44
@atreatis:novaim.comAtreatis
In reply to @max:kamax.io
Atreatis: that's not that
My bad, currently doing a barbecue and kids are distracting a lot :(
16:20:17
@max:kamax.ioMaximusmake sure you follow each step and double check your mxisd and reverse proxy config since you had an older version16:20:18
@perflyst:snopyta.orgperflystbut somehow this makes no sense 172.16.1.78 is the machine where mxisd runs16:21:25
@perflyst:snopyta.orgperflystsynapse runs somewhere else and the dns override is in the config16:21:39
@max:kamax.ioMaximus it means most likely there is no Host header at all 16:22:10
@perflyst:snopyta.orgperflyst so it needs proxy_set_header Host $host; in nginx 16:22:36
@max:kamax.ioMaximusagain: make sure you follow each step from the doc and you do not skip any line or the likes16:23:28
@max:kamax.ioMaximusthey are all needed16:23:31
@max:kamax.ioMaximus and from the nginx config you pasted, you have one extra line whcih is not documented, and you are missing at least two lines accross both location blocks 16:25:09
@perflyst:snopyta.orgperflyst it was documented at some time somewhere, quite sure
and i will not set proxy_set_header X-Forwarded-For $remote_addr;, because than real IP addresses are logged forever in synapse's database
16:27:00
@perflyst:snopyta.orgperflystseems like it was enough to set proxy_set_header Host $host16:27:30
@max:kamax.ioMaximusGlad it's fixed16:28:42
@perflyst:snopyta.orgperflyst one question
why do you recommend to set proxy_set_header X-Forwarded-For $remote_addr;?
16:29:11
@max:kamax.ioMaximusboth mxisd and synapse have some access control/rate limiting that rely on the caller IP. Without that header, given that mxisd expect to be behind a reverse proxy, the actual caller will never be known. For small/unique user setup, it might not be relevant, but it becomes quickly needed16:31:02
@max:kamax.ioMaximusif you don't want to set it it's fine, just know that you might see failed requests now and then because of it16:31:32
3 Jun 2019
@yogsi:matrix.orgyogsihi07:11:27
@yogsi:matrix.orgyogsi
nimogit: if there are things you feel are lacking for your use case for the register/invite limitation features, let me know. We try to improve support for servers with limited registration/invites
any chance we could limit the "create new room" option to a certain group of users?
07:12:20
@max:kamax.ioMaximus yogsi: that has nothing to do with the identity server I'm afraid 07:12:58
@max:kamax.ioMaximushttps://github.com/kamax-matrix/mxgwd this is more what you're looking for, even tho it's still consider alpha07:13:52
@max:kamax.ioMaximus it even has a configuration example for what you want. Come to #mxgwd:kamax.io if you have more questions 07:14:24
@yogsi:matrix.orgyogsithanks! will definitely check it out07:15:32
@mextor:matrix.orgmextorhi mxisd works fine23:03:38
@mextor:matrix.orgmextorthx for the work :)23:03:48
@mextor:matrix.orgmextorquestion: where should I insert custom template conf ? in the /etc/mxisd/mxisd.yaml ?23:04:51
@mextor:matrix.orgmextorat the end ? somehing like :23:05:14
@mextor:matrix.orgmextorthreepid: medium: email: generators: template: invite: '/etc/mxisd/invite-template.eml' etc... ?23:05:59
@max:kamax.ioMaximusyes23:06:28
@mextor:matrix.orgmextorok, I try23:07:39
@mextor:matrix.orgmextorooops: Failed to remove threepid23:08:56

Show newer messages


Back to Room ListRoom Version: