diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 21:04:39 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 21:04:39 +0200 |
| commit | 0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 (patch) | |
| tree | d53579b0791112483560517399736388733df305 /packages/meshbay-hub/src/meshbay_hub/static/app.js | |
| parent | d692db441680eef8969573047cf5da00cfb61362 (diff) | |
| download | meshbay-0ed56d3a1b4f71cf622d3e27edc87a15ef33c185.tar.gz | |
fix(hub): the pepper and a device key take the passphrase, not a token
POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key.
A refreshed or lifted token could otherwise fetch the pepper, or register a
device whose every sign-in carries it. Both callers have just been given the
passphrase.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/app.js')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/static/app.js | 11 |
1 files changed, 6 insertions, 5 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/app.js b/packages/meshbay-hub/src/meshbay_hub/static/app.js index c101ec9..72dd123 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/app.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/app.js @@ -1139,8 +1139,8 @@ function App() { * exactly what a browser does, and is a worse experience rather than a * broken one. */ - const registerThisDevice = useCallback(async (token) => { - if (!platform.device.available) return; + const registerThisDevice = useCallback(async (token, authKey) => { + if (!platform.device.available || !authKey) return; try { const backend = await platform.secrets.backend(); if (backend === 'unavailable') return; @@ -1148,7 +1148,7 @@ function App() { if (!pk) return; await hubFetch('/v1/users/devices', { method: 'POST', token, - body: { pk_auth_ed25519: pk, label: t('device.this_device') }, + body: { pk_auth_ed25519: pk, label: t('device.this_device'), auth_key: authKey }, }); } catch (err) { console.warn('device not registered:', err.message); @@ -1158,11 +1158,12 @@ function App() { const authCtx = { user, login: async (username, password) => { - let token, refreshToken; + let token, refreshToken, authKey; if (window.MeshBayKeys) { const data = await window.MeshBayKeys.loginAndRecover(username, password); token = data.accessToken; refreshToken = data.refreshToken; + authKey = data.authKey; // The only thing sign-in produces: the key that opens a node's bundle. // Which identity we use is decided per node, when we get there. session.bundleKey = data.bundleKey; @@ -1180,7 +1181,7 @@ function App() { // On a desktop build, remember this device so the next launch does not ask // for the passphrase again. The key is generated and held by the main // process; what travels here is only its public half. - await registerThisDevice(token); + await registerThisDevice(token, authKey); // Before the session lands, so the idle watch starting with it does not // read the last-active time of whoever used this browser before. markActive(true); |