aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_email_change_requires_passphrase.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-25 14:28:03 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-25 17:24:16 +0200
commit6b9b5394c5ec01c5de01b7bf23bc161792f38278 (patch)
tree56536e2d30723aaec1852ba5cf19e24a886c815f /packages/meshbay-hub/tests/test_email_change_requires_passphrase.py
parent43c72cf9e8853cd5b2f59d4a4acd87729b0ddae0 (diff)
downloadmeshbay-6b9b5394c5ec01c5de01b7bf23bc161792f38278.tar.gz
fix(hub): require the passphrase to change the e-mail on file
A member hands its hub access token to every node it connects to (the MNP handshake), so a node operator holds a live bearer token for that member. PATCH /v1/users/me {email} needed only that token, and the confirmation code goes to the new address — so an operator could point the account's e-mail at their own inbox, confirm it, and then use the passphrase-reset path to take the account over. This is the immediate mitigation of that chain; the full fix (a node-audience token distinct from the API session token) follows. Changing the address now requires the passphrase-derived auth_key, verified through the same throttle as a passphrase change or an account deletion — the hub still never sees the passphrase. A PATCH that does not change the address is unaffected. The profile page prompts for the passphrase and derives auth_key with the existing MeshBayKeys.deriveAuthKey, as the delete and change-password flows already do. test_email_change_requires_passphrase.py: refused without / with a wrong passphrase, proceeds with the right one, and a no-email PATCH still works; red before, green after. test_mail_is_not_a_relay.py updated to pass the auth_key. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests/test_email_change_requires_passphrase.py')
-rw-r--r--packages/meshbay-hub/tests/test_email_change_requires_passphrase.py55
1 files changed, 55 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_email_change_requires_passphrase.py b/packages/meshbay-hub/tests/test_email_change_requires_passphrase.py
new file mode 100644
index 0000000..697e6f9
--- /dev/null
+++ b/packages/meshbay-hub/tests/test_email_change_requires_passphrase.py
@@ -0,0 +1,55 @@
+"""Changing the address on file requires the passphrase, not merely a token.
+
+A member hands its hub access token to every node it connects to (the MNP
+handshake), so a node operator holds a live bearer token for that member.
+`PATCH /v1/users/me {email}` used to need only that token, and the confirmation
+code goes to the *new* address — so an operator could point the account's e-mail
+at their own inbox, confirm it, and then use the passphrase-reset path to take
+the account over. The passphrase (as the derived auth_key, which is all the hub
+ever sees) is now required, exactly as for a passphrase change or an account
+deletion.
+"""
+
+import pytest
+
+
+async def _account(client, username="mail_pass_test", auth_key="k" * 44):
+ await client.post("/v1/users/register", json={
+ "username": username, "email": f"{username}@test.local", "auth_key": auth_key})
+ r = await client.post("/v1/users/login", json={
+ "username": username, "auth_key": auth_key})
+ return r.json()["access_token"]
+
+
+@pytest.mark.asyncio
+async def test_email_change_without_passphrase_is_refused(client):
+ tok = await _account(client)
+ r = await client.patch("/v1/users/me", headers={"Authorization": f"Bearer {tok}"},
+ json={"email": "attacker@evil.invalid"})
+ assert r.status_code == 403
+
+
+@pytest.mark.asyncio
+async def test_email_change_with_wrong_passphrase_is_refused(client):
+ tok = await _account(client)
+ r = await client.patch("/v1/users/me", headers={"Authorization": f"Bearer {tok}"},
+ json={"email": "attacker@evil.invalid", "auth_key": "z" * 44})
+ assert r.status_code == 403
+
+
+@pytest.mark.asyncio
+async def test_email_change_with_correct_passphrase_proceeds(client):
+ tok = await _account(client, username="mail_ok_test", auth_key="k" * 44)
+ r = await client.patch("/v1/users/me", headers={"Authorization": f"Bearer {tok}"},
+ json={"email": "new@real.invalid", "auth_key": "k" * 44})
+ assert r.status_code == 200
+ assert r.json().get("email_verification_required") is True
+
+
+@pytest.mark.asyncio
+async def test_profile_patch_without_email_needs_no_passphrase(client):
+ """Regression: a PATCH that does not change the address is unaffected."""
+ tok = await _account(client, username="mail_noop_test")
+ r = await client.patch("/v1/users/me", headers={"Authorization": f"Bearer {tok}"},
+ json={})
+ assert r.status_code == 200