diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 13:55:59 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 13:55:59 +0200 |
| commit | a55d40b74bda77dff6ec565abdd551607fc665d6 (patch) | |
| tree | eaab3cf9434be8bdcd67a9cddc7218050a6874e4 /packages/meshbay-hub/src/meshbay_hub/db/migrations | |
| parent | f211a13dc2e5dd82eaba49222171d6f29d858eb5 (diff) | |
| download | meshbay-a55d40b74bda77dff6ec565abdd551607fc665d6.tar.gz | |
feat(hub): a bundle pepper per account, handed only to a proven session
Sealed at rest and bound to the account; returned by sign-in, device sign-in,
a passphrase change and GET /me/bundle-pepper, never by a refresh, to a node
token, in a token or in a log. Erasure clears it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/db/migrations')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py | 28 |
1 files changed, 28 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py new file mode 100644 index 0000000..dbf1718 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py @@ -0,0 +1,28 @@ +"""a bundle pepper per account, so a node cannot test passphrase guesses + +Revision ID: c3d4e5f6a7b9 +Revises: b2c3d4e5f6a8 +""" + +from collections.abc import Sequence + +import sqlalchemy as sa +from alembic import op + +revision: str = "c3d4e5f6a7b9" +down_revision: str | Sequence[str] | None = "b2c3d4e5f6a8" +branch_labels: str | Sequence[str] | None = None +depends_on: str | Sequence[str] | None = None + + +def upgrade() -> None: + with op.batch_alter_table("users") as batch: + batch.add_column(sa.Column("bundle_pepper", sa.String(128), nullable=True)) + batch.add_column(sa.Column("bundle_pepper_version", sa.Integer(), nullable=False, + server_default="1")) + + +def downgrade() -> None: + with op.batch_alter_table("users") as batch: + batch.drop_column("bundle_pepper_version") + batch.drop_column("bundle_pepper") |