aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_recovery_email.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-12 12:14:15 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-12 16:36:54 +0200
commit6260825bf6d8340549de53905de3bd0b84d97d0a (patch)
tree7c2fc96613f3b499c15e9e2728ffaf7afdf4385b /packages/meshbay-hub/tests/test_recovery_email.py
parent28548dcbde50f7cee471d6962e16115bb87b056f (diff)
downloadmeshbay-6260825bf6d8340549de53905de3bd0b84d97d0a.tar.gz
fix(hub): the mail server is not a relay
The previous commit metered the paths that send mail. It was not enough, and saying it was would have been wrong: a 60-second cooldown per account still allows one stranger a minute — 1440 a day — and registration is open, so "per account" is a bound an attacker buys more of. And there was a third door nobody had counted. POST /v1/users/register an address nobody has verified PATCH /v1/users/me an address nobody has verified, signed in POST /v1/users/password/reset only the address already on file POST /v1/groups/{id}/invite-notify only a registered member's address The widest was the register *resend* branch: no token, no captcha, and the username and address are the caller's own from a moment ago — registering a victim's address once bought the right to mail them at the endpoint's rate limit for as long as the account stayed pending. So the bound moves into `mail.py`, where every message passes one function. `purpose` is keyword-required and checked against a closed list, so a helper that names anything else does not send and one that names nothing is a TypeError rather than an unrestricted send. Under it: - a bound per **recipient**, across every purpose, account and endpoint — what a person being mail-bombed actually experiences, and the only bound that describes it. Keyed on a hash, because this would otherwise be the one place in the hub holding plaintext addresses in memory (S2) - an instance-wide hourly ceiling, which cannot be bought with more accounts - a cooldown on the resend branch, a cooldown and a daily ceiling on the address change, and the IP-log entry that endpoint never wrote — alone among the ones that mail The ceiling on address changes counts IP-log rows, not EmailVerification: the handler deletes this account's unverified rows before writing a new one, so counting those counts one, always. Which is what the first version of it did. Refusals never carry the address: that line goes to the journal. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01T4YmK41VsEURWFdop4EEeT
Diffstat (limited to 'packages/meshbay-hub/tests/test_recovery_email.py')
-rw-r--r--packages/meshbay-hub/tests/test_recovery_email.py9
1 files changed, 7 insertions, 2 deletions
diff --git a/packages/meshbay-hub/tests/test_recovery_email.py b/packages/meshbay-hub/tests/test_recovery_email.py
index e4288a1..c6dab97 100644
--- a/packages/meshbay-hub/tests/test_recovery_email.py
+++ b/packages/meshbay-hub/tests/test_recovery_email.py
@@ -31,7 +31,12 @@ def _skip_email_verification(monkeypatch):
run so the e-mail is actually built. Capture it instead of sending.
"""
sent = []
- monkeypatch.setattr("meshbay_hub.mail._send", lambda msg: sent.append(msg) or True)
+ # `**_` swallows the `purpose` keyword `_send` now requires — the gate
+ # that keeps this hub off the open-relay list. What this module is
+ # about is the body of the message, so the gate is stubbed away with
+ # the socket; `test_mail_is_not_a_relay.py` is where it is exercised.
+ monkeypatch.setattr("meshbay_hub.mail._send",
+ lambda msg, **_: sent.append(msg) or True)
return sent
@@ -84,7 +89,7 @@ async def test_the_recovery_key_is_not_persisted(
def test_mail_body_with_and_without_the_key(monkeypatch):
captured = []
monkeypatch.setattr("meshbay_hub.mail._send",
- lambda msg: captured.append(msg) or True)
+ lambda msg, **_: captured.append(msg) or True)
mail.send_verification_code("x@example.com", "123456",
recovery_key="MY-RECOVERY-KEY")