aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
commit0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 (patch)
treed53579b0791112483560517399736388733df305 /packages/meshbay-hub/src/meshbay_hub/static/profile-page.js
parentd692db441680eef8969573047cf5da00cfb61362 (diff)
downloadmeshbay-0ed56d3a1b4f71cf622d3e27edc87a15ef33c185.tar.gz
fix(hub): the pepper and a device key take the passphrase, not a token
POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key. A refreshed or lifted token could otherwise fetch the pepper, or register a device whose every sign-in carries it. Both callers have just been given the passphrase. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/profile-page.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/profile-page.js4
1 files changed, 2 insertions, 2 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js b/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js
index 7c36951..1800d72 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js
@@ -147,7 +147,8 @@ export function ProfilePage({ user, onLogout }) {
// In the desktop application both are kept by its main process, the new
// one set aside until the hub has accepted the change.
const K = window.MeshBayKeys;
- const { pepper, version } = await K.fetchBundlePepper(user.token);
+ const oldAuthKey = await K.deriveAuthKey(cpOld, user.username);
+ const { pepper, version } = await K.fetchBundlePepper(user.token, oldAuthKey);
const oldKey = await K.sessionBundleKey(
cpOld, user.username, user.userId, pepper, version);
const newKey = await K.sessionBundleKey(
@@ -160,7 +161,6 @@ export function ProfilePage({ user, onLogout }) {
bundleKey: oldKey, newBundleKey: newKey,
onProgress: setCpProgress,
});
- const oldAuthKey = await window.MeshBayKeys.deriveAuthKey(cpOld, user.username);
const newAuthKey = await window.MeshBayKeys.deriveAuthKey(cpNew, user.username);
resp = await hubFetch('/v1/users/password', {
method: 'POST', token: user.token,