aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_account_deletion.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
commit0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 (patch)
treed53579b0791112483560517399736388733df305 /packages/meshbay-hub/tests/test_account_deletion.py
parentd692db441680eef8969573047cf5da00cfb61362 (diff)
downloadmeshbay-0ed56d3a1b4f71cf622d3e27edc87a15ef33c185.tar.gz
fix(hub): the pepper and a device key take the passphrase, not a token
POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key. A refreshed or lifted token could otherwise fetch the pepper, or register a device whose every sign-in carries it. Both callers have just been given the passphrase. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests/test_account_deletion.py')
-rw-r--r--packages/meshbay-hub/tests/test_account_deletion.py13
1 files changed, 9 insertions, 4 deletions
diff --git a/packages/meshbay-hub/tests/test_account_deletion.py b/packages/meshbay-hub/tests/test_account_deletion.py
index a31aaff..632c133 100644
--- a/packages/meshbay-hub/tests/test_account_deletion.py
+++ b/packages/meshbay-hub/tests/test_account_deletion.py
@@ -140,7 +140,8 @@ async def test_deletion_clears_device_keys(client, db_session):
select(User.id).where(User.username == "devicer_test"))).scalar_one()
r = await client.post("/v1/users/devices", headers=headers,
- json={"pk_auth_ed25519": _device_pk(), "label": "desktop"})
+ json={"pk_auth_ed25519": _device_pk(), "label": "desktop",
+ "auth_key": _auth_key(password, "devicer_test")})
assert r.status_code == 201, r.text
# Present before, or the emptiness asserted below proves nothing.
@@ -166,15 +167,19 @@ async def test_a_new_account_can_reuse_the_deleted_accounts_device(client):
"""
pk = _device_pk()
token, password = await _register(client, "firstlife")
- r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk},
+ r = await client.post("/v1/users/devices",
+ json={"pk_auth_ed25519": pk,
+ "auth_key": _auth_key(password, "firstlife")},
headers={"Authorization": f"Bearer {token}"})
assert r.status_code == 201, r.text
await client.request("DELETE", "/v1/users/me",
headers={"Authorization": f"Bearer {token}"},
json={"auth_key": _auth_key(password, "firstlife")})
- token2, _ = await _register(client, "secondlife")
- r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk},
+ token2, password2 = await _register(client, "secondlife")
+ r = await client.post("/v1/users/devices",
+ json={"pk_auth_ed25519": pk,
+ "auth_key": _auth_key(password2, "secondlife")},
headers={"Authorization": f"Bearer {token2}"})
assert r.status_code == 201, r.text