aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_desktop_keyring.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-02 11:54:56 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-02 11:54:56 +0200
commitd7b7f1049d95e45e6316ac419cb434088c15bd5e (patch)
tree77da46e2fe3cb70af5fb2eebcbb1d69dad410b88 /packages/meshbay-hub/tests/test_desktop_keyring.py
parent56a8cf9167e8c7b0f2df15afed88031608adf782 (diff)
parent754387590fa1754436b4648f969915888c6f6c9e (diff)
downloadmeshbay-d7b7f1049d95e45e6316ac419cb434088c15bd5e.tar.gz
Merge branch 'main' of meshbay.org:meshbayHEADmain
Diffstat (limited to 'packages/meshbay-hub/tests/test_desktop_keyring.py')
-rw-r--r--packages/meshbay-hub/tests/test_desktop_keyring.py22
1 files changed, 22 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_desktop_keyring.py b/packages/meshbay-hub/tests/test_desktop_keyring.py
index e55e6d0..af7cc37 100644
--- a/packages/meshbay-hub/tests/test_desktop_keyring.py
+++ b/packages/meshbay-hub/tests/test_desktop_keyring.py
@@ -13,6 +13,7 @@ page, and a reference written from the specification in Python.
import base64
import hashlib
import json
+import re
import shutil
import subprocess
from pathlib import Path
@@ -93,6 +94,9 @@ const v = JSON.parse(fs.readFileSync(input, 'utf8'));
other_node: await refusal('join', { ...F.join, nodePk: 'T3RoZXJOb2Rl' }),
other_account: await refusal('join', { ...F.join, userId: 'someone-else' }),
stale: await refusal('join', { ...F.join, ts: ts - 3600 }),
+ root_add: await refusal('admin', { ...F.admin, op: 'root_add' }),
+ root_update: await refusal('admin', { ...F.admin, op: 'root_update' }),
+ group_attach: await refusal('admin', { ...F.admin, op: 'group_attach' }),
};
const eph = require('crypto').generateKeyPairSync('x25519');
@@ -268,6 +272,24 @@ def test_the_page_names_a_kind_and_never_the_bytes(out):
assert "not now" in r["stale"]
+def test_what_widens_a_nodes_sharing_is_never_signed(out):
+ """Gone from MNP 6.0, and refused here as well: a node older than that
+ still accepts them, and a script in the page must not be able to get one
+ signed for it."""
+ for op in ("root_add", "root_update", "group_attach"):
+ assert "not an operation" in out["refused"][op], op
+
+
+def test_the_application_signs_exactly_the_nodes_operations():
+ from meshbay_common import adminop
+ src = (Path(__file__).resolve().parents[2] / "meshbay-client" / "src"
+ / "transcripts.js").read_text(encoding="utf-8")
+ listed = set(re.findall(r"'([a-z_]+)'",
+ src.split("const ADMIN_OPS = new Set([")[1].split("]);")[0]))
+ catalogue = {v for k, v in vars(adminop).items() if k.startswith("OP_")}
+ assert listed == catalogue
+
+
def test_nothing_is_sealed_for_a_browser_while_browser_access_is_off(out):
for what, err in out["sealing_while_access_off"].items():
assert err and "browser access is off" in err, what