aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_bundle_pepper.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 17:13:40 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 17:13:40 +0200
commitb1ebcdeb9082457972c41a47e77494902335d262 (patch)
treeb19384b868197ecda88ce79765a0f60812dbc815 /packages/meshbay-hub/tests/test_bundle_pepper.py
parent6d167392f6f8ede37e2794a68a3738f8ba03131d (diff)
downloadmeshbay-b1ebcdeb9082457972c41a47e77494902335d262.tar.gz
feat: browser access, decided in the desktop application
Off for an account made there: its identities stay on the device and nothing is left on nodes. Turned on from the Profile page behind a native confirmation; each node is settled when its group next opens. The hub keeps a mirror a browser reads to say why a group will not open; it grants nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests/test_bundle_pepper.py')
-rw-r--r--packages/meshbay-hub/tests/test_bundle_pepper.py16
1 files changed, 16 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_bundle_pepper.py b/packages/meshbay-hub/tests/test_bundle_pepper.py
index e99799f..be9da19 100644
--- a/packages/meshbay-hub/tests/test_bundle_pepper.py
+++ b/packages/meshbay-hub/tests/test_bundle_pepper.py
@@ -167,3 +167,19 @@ async def test_it_is_never_logged(client):
lg.disabled = disabled
assert seen, "the handler saw nothing, so it proves nothing"
assert not any(login["bundle_pepper"] in m for m in seen)
+
+
+@pytest.mark.asyncio
+async def test_the_browser_access_mirror_is_a_preference_like_any_other(client):
+ """The desktop application writes what it holds, and a browser reads it to
+ say why it cannot open a group. Nothing on the hub or a node acts on it."""
+ await _register(client, "pepper_mirror")
+ login = await _login(client, "pepper_mirror")
+ headers = _bearer(login["access_token"])
+ r = await client.put("/v1/users/me/preferences/browser_access", headers=headers,
+ json={"value": "off"})
+ assert r.status_code == 200, r.text
+ prefs = (await client.get("/v1/users/me/preferences", headers=headers)).json()
+ assert prefs["browser_access"] == "off"
+ # Still handed the pepper: the mirror decides nothing.
+ assert "bundle_pepper" in await _login(client, "pepper_mirror")