Skip to content

Commit

Permalink
fix!: Only room creator can set the E2EE room key for the first time (#…
Browse files Browse the repository at this point in the history
  • Loading branch information
KevLehman authored and ggazzo committed Oct 11, 2024
1 parent bab25f7 commit 09c1b34
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 2 deletions.
5 changes: 5 additions & 0 deletions .changeset/soft-planets-cross.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@rocket.chat/meteor": major
---

Fixes a behavior of E2EE room creation that allowed any user on the room to define room keys before the room creator, causing race conditions.
4 changes: 2 additions & 2 deletions apps/meteor/app/e2e/client/rocketchat.e2e.room.js
Original file line number Diff line number Diff line change
Expand Up @@ -245,8 +245,8 @@ export class E2ERoom extends Emitter {

try {
const room = ChatRoom.findOne({ _id: this.roomId });
if (!room.e2eKeyId) {
// TODO CHECK_PERMISSION
// Only room creator can set keys for room
if (!room.e2eKeyId && room.u._id === this.userId) {
this.setState(E2ERoomState.CREATING_KEYS);
await this.createGroupKey();
this.setState(E2ERoomState.READY);
Expand Down

0 comments on commit 09c1b34

Please sign in to comment.