diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-12 12:14:15 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-12 16:36:54 +0200 |
| commit | 6260825bf6d8340549de53905de3bd0b84d97d0a (patch) | |
| tree | 7c2fc96613f3b499c15e9e2728ffaf7afdf4385b /packages/meshbay-hub/tests/test_recovery_email.py | |
| parent | 28548dcbde50f7cee471d6962e16115bb87b056f (diff) | |
| download | meshbay-6260825bf6d8340549de53905de3bd0b84d97d0a.tar.gz | |
fix(hub): the mail server is not a relay
The previous commit metered the paths that send mail. It was not enough, and
saying it was would have been wrong: a 60-second cooldown per account still
allows one stranger a minute — 1440 a day — and registration is open, so
"per account" is a bound an attacker buys more of. And there was a third door
nobody had counted.
POST /v1/users/register an address nobody has verified
PATCH /v1/users/me an address nobody has verified, signed in
POST /v1/users/password/reset only the address already on file
POST /v1/groups/{id}/invite-notify only a registered member's address
The widest was the register *resend* branch: no token, no captcha, and the
username and address are the caller's own from a moment ago — registering a
victim's address once bought the right to mail them at the endpoint's rate
limit for as long as the account stayed pending.
So the bound moves into `mail.py`, where every message passes one function.
`purpose` is keyword-required and checked against a closed list, so a helper
that names anything else does not send and one that names nothing is a
TypeError rather than an unrestricted send. Under it:
- a bound per **recipient**, across every purpose, account and endpoint —
what a person being mail-bombed actually experiences, and the only bound
that describes it. Keyed on a hash, because this would otherwise be the
one place in the hub holding plaintext addresses in memory (S2)
- an instance-wide hourly ceiling, which cannot be bought with more accounts
- a cooldown on the resend branch, a cooldown and a daily ceiling on the
address change, and the IP-log entry that endpoint never wrote — alone
among the ones that mail
The ceiling on address changes counts IP-log rows, not EmailVerification: the
handler deletes this account's unverified rows before writing a new one, so
counting those counts one, always. Which is what the first version of it did.
Refusals never carry the address: that line goes to the journal.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T4YmK41VsEURWFdop4EEeT
Diffstat (limited to 'packages/meshbay-hub/tests/test_recovery_email.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_recovery_email.py | 9 |
1 files changed, 7 insertions, 2 deletions
diff --git a/packages/meshbay-hub/tests/test_recovery_email.py b/packages/meshbay-hub/tests/test_recovery_email.py index e4288a1..c6dab97 100644 --- a/packages/meshbay-hub/tests/test_recovery_email.py +++ b/packages/meshbay-hub/tests/test_recovery_email.py @@ -31,7 +31,12 @@ def _skip_email_verification(monkeypatch): run so the e-mail is actually built. Capture it instead of sending. """ sent = [] - monkeypatch.setattr("meshbay_hub.mail._send", lambda msg: sent.append(msg) or True) + # `**_` swallows the `purpose` keyword `_send` now requires — the gate + # that keeps this hub off the open-relay list. What this module is + # about is the body of the message, so the gate is stubbed away with + # the socket; `test_mail_is_not_a_relay.py` is where it is exercised. + monkeypatch.setattr("meshbay_hub.mail._send", + lambda msg, **_: sent.append(msg) or True) return sent @@ -84,7 +89,7 @@ async def test_the_recovery_key_is_not_persisted( def test_mail_body_with_and_without_the_key(monkeypatch): captured = [] monkeypatch.setattr("meshbay_hub.mail._send", - lambda msg: captured.append(msg) or True) + lambda msg, **_: captured.append(msg) or True) mail.send_verification_code("x@example.com", "123456", recovery_key="MY-RECOVERY-KEY") |