aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/harness/playlist_ui_probe.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 15:06:14 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 15:06:14 +0200
commit91297944791a36f30302ef8c86dd69ebeb177671 (patch)
tree568188114baf438059458f1bc87903f4894cec90 /packages/meshbay-hub/tests/harness/playlist_ui_probe.py
parenta55d40b74bda77dff6ec565abdd551607fc665d6 (diff)
downloadmeshbay-91297944791a36f30302ef8c86dd69ebeb177671.tar.gz
feat: bundles sealed per node under the passphrase and the hub's pepper
The session key is M = HKDF(Argon2(passphrase) || pepper, account id); each node's bundle key and the playlist key derive from it. Bundles are MBK3, bound to account and node; MBK1/MBK2 are refused by name, never replaced silently. Playlists move to key v2 and are re-sealed over unreadable node copies. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests/harness/playlist_ui_probe.py')
-rw-r--r--packages/meshbay-hub/tests/harness/playlist_ui_probe.py7
1 files changed, 3 insertions, 4 deletions
diff --git a/packages/meshbay-hub/tests/harness/playlist_ui_probe.py b/packages/meshbay-hub/tests/harness/playlist_ui_probe.py
index c705244..6e3be1e 100644
--- a/packages/meshbay-hub/tests/harness/playlist_ui_probe.py
+++ b/packages/meshbay-hub/tests/harness/playlist_ui_probe.py
@@ -173,12 +173,11 @@ const clickMenu = async (i) => {
try {
await initLocale();
- // A real HKDF handle, so the store derives its key the way it really does.
+ // A real master key, so the store derives its key the way it really does.
const raw = new Uint8Array(32).fill(3);
session.bundleKey = {
- v2: await crypto.subtle.importKey('raw', raw, { name: 'AES-GCM' }, false,
- ['encrypt', 'decrypt']),
- v2hkdf: await crypto.subtle.importKey('raw', raw, 'HKDF', false, ['deriveKey']),
+ v3: await crypto.subtle.importKey('raw', raw, 'HKDF', false, ['deriveKey', 'deriveBits']),
+ pepperVersion: 1,
};
// Deleting a playlist asks, in the page (ask.js) — so the probe answers the
// dialog the way a person would, by clicking its OK button.