Skip to content

feat(federation): ignore remote contacts - #65224

Open
ArtificialOwl wants to merge 1 commit into
masterfrom
feat/noid/config-to-disable-trusted-server-sync
Open

ArtificialOwl wants to merge 1 commit into
masterfrom
feat/noid/config-to-disable-trusted-server-sync

Conversation

@ArtificialOwl

@ArtificialOwl ArtificialOwl commented Oct 6, 2026 •

Copy link
Copy Markdown
Member
  • It seems that trusted servers were historically implemented to allow sync of contacts between multiple instances,
  • trusted servers is now used - and therefor required - for other features like
    • federated shares without yes/no confirmation
    • federated teams
    • collabora
  • The token/key exchange to confirm the 2 way trust between servers is linked to the sync of contacts,
  • contacts can be now be shared via OCM,

On some setup, the sync of all remote contacts is not something wanted

This patch ignore the list of remote contacts.
It does not limit your instance to send your local contact to remote trusted server, but will maks your instance not storing the incoming list from others trusted servers.

@ArtificialOwl
ArtificialOwl marked this pull request as ready for review October 6, 2026 19:41
@ArtificialOwl
ArtificialOwl requested review from Altahrim, icewind1991, leftybournes and salmart-dev and removed request for a team October 6, 2026 19:41
Comment thread apps/federation/lib/ConfigLexicon.php Outdated
@SebastianKrupinski

SebastianKrupinski commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
  • It seems that trusted servers were historically implemented to allow sync of contacts between multiple instances,

It was not to share contacts, but to share users between the systems, and we do this by synchronizing the system address book

* The token/key exchange to confirm the 2 way trust between servers is linked to the sync of contacts,
* contacts can be now be shared via OCM,

User contacts are not the same as "system contacts" although they are represented as an address book

On some setup, the sync of all remote contacts is not something wanted

In general, i agree that the token exchange should be separated from the any sync but at the moment the "system user sync" is what initiates the initial token exchange.

That said implementing this means that users will not be able to search for users on other systems to share with, essentially breaking federate user search

@ArtificialOwl
ArtificialOwl force-pushed the feat/noid/config-to-disable-trusted-server-sync branch from 63dbb8a to 1268804 Compare October 6, 2026 19:58
Signed-off-by: Maxence Lange <maxence@artificial-owl.com>
@ArtificialOwl
ArtificialOwl force-pushed the feat/noid/config-to-disable-trusted-server-sync branch from 1268804 to 392c335 Compare October 6, 2026 20:20
@ArtificialOwl

Copy link
Copy Markdown
Member Author

That said implementing this means that users will not be able to search for users on other systems to share with, essentially breaking federate user search

This is the main purpose, the federated user search will be done using OCM invite system.

A bigger improvement would be to have a list of options on the Admin Settings / Sharing / Trusted Servers to enable/disable feature related to Trusted Servers.

@SebastianKrupinski

Copy link
Copy Markdown
Contributor

This is the main purpose, the federated user search will be done using OCM invite system.

Has this been implemented?

@ArtificialOwl

Copy link
Copy Markdown
Member Author

This is the main purpose, the federated user search will be done using OCM invite system.

Has this been implemented?

It should be since 34, via the contacts app.

@ArtificialOwl

Copy link
Copy Markdown
Member Author

As said, some people just want to enjoy the other features requiring trusted servers without providing extra sharing contacts to their users.

Currently, the only known/documented solution to avoid this behavior is to remove OCA\Federation\SyncJob from the list of background jobs after each upgrade
In globalscale, the results are already returned by the lookup server.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants