diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 21:04:39 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 21:04:39 +0200 |
| commit | 0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 (patch) | |
| tree | d53579b0791112483560517399736388733df305 /packages/meshbay-hub/tests/test_device_auth.py | |
| parent | d692db441680eef8969573047cf5da00cfb61362 (diff) | |
| download | meshbay-0ed56d3a1b4f71cf622d3e27edc87a15ef33c185.tar.gz | |
fix(hub): the pepper and a device key take the passphrase, not a token
POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key.
A refreshed or lifted token could otherwise fetch the pepper, or register a
device whose every sign-in carries it. Both callers have just been given the
passphrase.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests/test_device_auth.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_device_auth.py | 24 |
1 files changed, 22 insertions, 2 deletions
diff --git a/packages/meshbay-hub/tests/test_device_auth.py b/packages/meshbay-hub/tests/test_device_auth.py index f9b172e..04012ee 100644 --- a/packages/meshbay-hub/tests/test_device_auth.py +++ b/packages/meshbay-hub/tests/test_device_auth.py @@ -46,10 +46,11 @@ async def _account(client, username="alice_test") -> str: return resp.json()["access_token"] -async def _register_device(client, token: str, pk: str, label: str = ""): +async def _register_device(client, token: str, pk: str, label: str = "", + auth_key: str = "k" * 44): return await client.post( "/v1/users/devices", - json={"pk_auth_ed25519": pk, "label": label}, + json={"pk_auth_ed25519": pk, "label": label, "auth_key": auth_key}, headers={"Authorization": f"Bearer {token}"}) @@ -275,3 +276,22 @@ async def test_the_hub_states_a_minimum_client_version(client): assert resp.status_code == 200 client_floor = resp.json()["client"] assert client_floor["minimum"] and client_floor["recommended"] + + +async def test_a_session_alone_cannot_register_a_device(client): + """ + A registered key signs in with no passphrase for as long as it stays, and + each of those sign-ins carries the bundle pepper. So a token — refreshed, + or lifted from a page — must not be enough to add one: the passphrase is. + """ + token = await _account(client) + sk, pk = _device() + + bare = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk}, + headers={"Authorization": f"Bearer {token}"}) + wrong = await _register_device(client, token, pk, auth_key="w" * 44) + + assert bare.status_code == 422 + assert wrong.status_code == 403 + assert (await client.post("/v1/users/auth", + json=_sign(sk, "alice_test"))).status_code == 401 |