Provision Matrix bot via shared-secret admin API (OIDC-only homeserver)

The homeserver authenticates humans via Keycloak OIDC and has password
login disabled, so register-matrix-bot.sh's password-login flow could
never obtain a token. Rewrite it to create the bot and mint a standalone
access token through Synapse's shared-secret admin API
(/_synapse/admin/v1/register), which works with registration + password
login turned off.

- Use the claude-code identity (@claude-code:semprini.me) as the bot.
- Avoid the admin "login as user" API: it returns a puppet token that
  Synapse revokes when the issuing admin is deactivated.
- Make re-runs idempotent: reuse a still-valid token/room; only recreate
  the account when no valid token is on hand.
- Read the registration shared secret from the running synapse container.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-21 18:24:11 +12:00
co-authored by Claude Opus 4.8
parent e91b129841
commit d6c315d353
2 changed files with 129 additions and 69 deletions
+1 -1
View File
@@ -22,7 +22,7 @@
"matrix": {
"homeserver": "https://matrix.semprini.me",
"user_id": "@maintainer:semprini.me",
"user_id": "@claude-code:semprini.me",
"access_token": "FILLED_BY_register-matrix-bot.sh",
"room_id": "FILLED_BY_register-matrix-bot.sh",
"admin_user_id": "@paul:semprini.me"