Skip to content

Exempt named Taskcluster Matrix bots from LDAP enforcement - #565

Merged
bheesham merged 1 commit into
mozilla-iam:masterfrom
petemoore:taskcluster-matrix-bot-exemption
Sep 30, 2026
Merged

bheesham merged 1 commit into
mozilla-iam:masterfrom
petemoore:taskcluster-matrix-bot-exemption

Conversation

@petemoore

Copy link
Copy Markdown
Contributor

@gcoxmoz
gcoxmoz requested a review from bheesham September 23, 2026 11:52
@gcoxmoz

gcoxmoz commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Conceptually seems fine; I wonder if it'll run afoul of anything wrt how we require mozilla.com accounts tie back to LDAP, and/or the email_verified check between the two stanzas.

@skyschub

Copy link
Copy Markdown

I'm very aware I might open a big rabbithole: but is there some way to turn that into a generalized solutions for other Mozilla Matrix bot users? We have a few other bots (botzilla being one), and I kinda dislike the current state where we have to create third-party accounts (or in this case still first-party technically?) just to sign in.

Would this list of email addresses be something we can, in theory, expand to other addresses? I don't expect a lot here, but we have a few other bots who at some point need to be able to "sign in" again. :/

@skyschub

Copy link
Copy Markdown

Extra note: Some accounts currently have @matrix-bot.mozilla.org email addresses. Was that valid at some point? There is no MX record for that subdomain, so I don't think that ever received emails (or it was removed), but if there is a way to allow bare username+password sign-ups for only that domain, maybe that's an alternative?

const email = event.user.email.toLowerCase();
const exemptEmails =
SERVICE_ACCOUNT_EXEMPTIONS[event.client.client_id] || [];
if (event.user.email_verified && exemptEmails.includes(email)) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have yet to see a case where event.user.email_verified has been false.

I did some investigation for bhearsum a while back, that's still in Slack (ref).

My take: if we've exempted an email we probably don't care if it's been verified or not.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My take: if we've exempted an email we probably don't care if it's been verified or not.

My reasoning is mostly: it looks like we want to use these more as an API/username for a bot account, in which case if it can receive email is sort of not important. Other IdPs may rely on that, for granting an account.

@bheesham

Copy link
Copy Markdown
Contributor

I'm very aware I might open a big rabbithole: but is there some way to turn that into a generalized solutions for other Mozilla Matrix bot users? We have a few other bots (botzilla being one), and I kinda dislike the current state where we have to create third-party accounts (or in this case still first-party technically?) just to sign in.

Yeah, we can make it into something more general. Auth0 recently released some features which make this simpler.

Would this list of email addresses be something we can, in theory, expand to other addresses? I don't expect a lot here, but we have a few other bots who at some point need to be able to "sign in" again. :/

Yeah, that would be fine. My preference would be to merge this PR first, then as a follow-up the rest of the bot accounts exempted afterwards. Would you be able to file a ticket with any additional details?

One (minor) caveat is: any work we do here we'll need to port over to Okta.

Extra note: Some accounts currently have @matrix-bot.mozilla.org email addresses. Was that valid at some point? There is no MX record for that subdomain, so I don't think that ever received emails (or it was removed), but if there is a way to allow bare username+password sign-ups for only that domain, maybe that's an alternative?

Hmm... re: bare username+password: we can probably do that, but I'd prefer to use FxA.

Weird handwavy stuff: it looks like we try not to use the built-in Auth0 database. I'm not sure why this is the case. That's just a thing I've noticed. There are now good reasons though, mainly: an even more complicated login screen.

@skyschub

Copy link
Copy Markdown

Hmm... re: bare username+password: we can probably do that, but I'd prefer to use FxA.

Totally fine by me! I just wanted to raise this point because I'm 100% sure this will come up again in the future. I have no problems pointing people to create an FxA and allow-listing the address here. :) This also isn't something that's coming up now, all the existing bots still run fine without being touched, but we all know that's gonna change in the future.

Thanks for the feedback! :)

@bheesham

Copy link
Copy Markdown
Contributor

I had a quick chat with @petemoore, and he's okay with this being deployed on Monday.

@bheesham
bheesham merged commit 523a5ac into mozilla-iam:master Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants