aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_bundle_pepper.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 15:06:14 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 15:06:14 +0200
commit91297944791a36f30302ef8c86dd69ebeb177671 (patch)
tree568188114baf438059458f1bc87903f4894cec90 /packages/meshbay-hub/tests/test_bundle_pepper.py
parenta55d40b74bda77dff6ec565abdd551607fc665d6 (diff)
downloadmeshbay-91297944791a36f30302ef8c86dd69ebeb177671.tar.gz
feat: bundles sealed per node under the passphrase and the hub's pepper
The session key is M = HKDF(Argon2(passphrase) || pepper, account id); each node's bundle key and the playlist key derive from it. Bundles are MBK3, bound to account and node; MBK1/MBK2 are refused by name, never replaced silently. Playlists move to key v2 and are re-sealed over unreadable node copies. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests/test_bundle_pepper.py')
-rw-r--r--packages/meshbay-hub/tests/test_bundle_pepper.py12
1 files changed, 0 insertions, 12 deletions
diff --git a/packages/meshbay-hub/tests/test_bundle_pepper.py b/packages/meshbay-hub/tests/test_bundle_pepper.py
index e7b126f..e99799f 100644
--- a/packages/meshbay-hub/tests/test_bundle_pepper.py
+++ b/packages/meshbay-hub/tests/test_bundle_pepper.py
@@ -105,18 +105,6 @@ async def test_an_open_session_may_ask_and_a_node_may_not(client):
@pytest.mark.asyncio
-async def test_a_passphrase_change_carries_it(client):
- """The new passphrase makes a new bundle key, and the client does not keep
- the pepper to re-seal under it."""
- await _register(client, "pepper_chg")
- login = await _login(client, "pepper_chg")
- r = await client.post("/v1/users/password", headers=_bearer(login["access_token"]),
- json={"old_auth_key": KEY, "new_auth_key": "n" * 44})
- assert r.status_code == 200, r.text
- assert r.json()["bundle_pepper"] == login["bundle_pepper"]
-
-
-@pytest.mark.asyncio
async def test_it_is_sealed_at_rest_and_bound_to_its_account(client, db_session):
await _register(client, "pepper_rest")
login = await _login(client, "pepper_rest")