aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/app.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
commit0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 (patch)
treed53579b0791112483560517399736388733df305 /packages/meshbay-hub/src/meshbay_hub/static/app.js
parentd692db441680eef8969573047cf5da00cfb61362 (diff)
downloadmeshbay-0ed56d3a1b4f71cf622d3e27edc87a15ef33c185.tar.gz
fix(hub): the pepper and a device key take the passphrase, not a token
POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key. A refreshed or lifted token could otherwise fetch the pepper, or register a device whose every sign-in carries it. Both callers have just been given the passphrase. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/app.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/app.js11
1 files changed, 6 insertions, 5 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/app.js b/packages/meshbay-hub/src/meshbay_hub/static/app.js
index c101ec9..72dd123 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/app.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/app.js
@@ -1139,8 +1139,8 @@ function App() {
* exactly what a browser does, and is a worse experience rather than a
* broken one.
*/
- const registerThisDevice = useCallback(async (token) => {
- if (!platform.device.available) return;
+ const registerThisDevice = useCallback(async (token, authKey) => {
+ if (!platform.device.available || !authKey) return;
try {
const backend = await platform.secrets.backend();
if (backend === 'unavailable') return;
@@ -1148,7 +1148,7 @@ function App() {
if (!pk) return;
await hubFetch('/v1/users/devices', {
method: 'POST', token,
- body: { pk_auth_ed25519: pk, label: t('device.this_device') },
+ body: { pk_auth_ed25519: pk, label: t('device.this_device'), auth_key: authKey },
});
} catch (err) {
console.warn('device not registered:', err.message);
@@ -1158,11 +1158,12 @@ function App() {
const authCtx = {
user,
login: async (username, password) => {
- let token, refreshToken;
+ let token, refreshToken, authKey;
if (window.MeshBayKeys) {
const data = await window.MeshBayKeys.loginAndRecover(username, password);
token = data.accessToken;
refreshToken = data.refreshToken;
+ authKey = data.authKey;
// The only thing sign-in produces: the key that opens a node's bundle.
// Which identity we use is decided per node, when we get there.
session.bundleKey = data.bundleKey;
@@ -1180,7 +1181,7 @@ function App() {
// On a desktop build, remember this device so the next launch does not ask
// for the passphrase again. The key is generated and held by the main
// process; what travels here is only its public half.
- await registerThisDevice(token);
+ await registerThisDevice(token, authKey);
// Before the session lands, so the idle watch starting with it does not
// read the last-active time of whoever used this browser before.
markActive(true);