aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-08-10 03:07:56 +0200
committerChristophe Besson <cbesson@gmail.com>2026-08-10 03:07:56 +0200
commit4b3e8c3b8b9d10c8ac333dd8db614a7569052472 (patch)
tree8828d7d549adc8bb21d8a7f6533c8e9db9c298b9 /packages/meshbay-hub/tests
parent8ccbe262ecf4a8f7545cbf1e9f1cc5a485acae67 (diff)
downloadmeshbay-4b3e8c3b8b9d10c8ac333dd8db614a7569052472.tar.gz
feat: Phase 7 — Node v2 (multi-group, Sender Keys, 0-RTT, chat, denylist)
Implements all 8 milestones (7.0-7.7): - 7.0: JWT carries `groups` claim; node verifies group membership at MNP handshake (QUIC + TCP+TLS). Resolves security review C2. - 7.1: QUIC 0-RTT session resumption via stored session tickets (17-21ms reconnect vs 47ms cold). - 7.2: Hub→node WebSocket signaling for NAT punch coordination (`client_incoming`/`punch_ready`) + jti denylist push. Denylist class blocks revoked users/jtis at handshake. - 7.3: Multi-group daemon — one QUIC port serves N groups with per-group GEK, shared_root, and index routing. - 7.4: HLS streaming via QUIC (STREAM_SEGMENT message type, ffmpeg segment extraction). - 7.5: Sender Keys protocol for group chat (Signal Groups approach). Each member has own sending chain key, HKDF chain ratchet, AES-256-GCM encryption, Ed25519 signing. Resolves security review C1. - 7.6: Chat store (SQLite via aiosqlite), CHAT_MESSAGE MNP wire type with peer broadcast, web UI with WebSocket push. - 7.7: Argon2id calibration CLI. First security review included (first-review.md). 109 tests, demo-v3 validated against meshbay.org production hub. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests')
-rw-r--r--packages/meshbay-hub/tests/test_hub_api.py50
1 files changed, 50 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_hub_api.py b/packages/meshbay-hub/tests/test_hub_api.py
index ea59f17..568d5d9 100644
--- a/packages/meshbay-hub/tests/test_hub_api.py
+++ b/packages/meshbay-hub/tests/test_hub_api.py
@@ -261,3 +261,53 @@ async def test_non_admin_cannot_add_member(client):
json=bundle,
headers={"Authorization": f"Bearer {dan_token}"})
assert r.status_code == 403
+
+
+@pytest.mark.asyncio
+async def test_jwt_contains_groups_claim(client):
+ """JWT must contain a 'groups' list with group_ids the user is a member of."""
+ import jwt as pyjwt
+ pk_ed_a, pk_x_a, _ = _gen_user_keys()
+ pk_ed_b, pk_x_b, sk_x_b = _gen_user_keys()
+
+ await client.post("/v1/users/register", json={
+ "username": "grp_alice", "email": "ga@x.com", "password": "alicepass99",
+ "pk_user_ed25519": pk_ed_a, "pk_user_x25519": pk_x_a})
+ await client.post("/v1/users/register", json={
+ "username": "grp_bob", "email": "gb@x.com", "password": "bobpass99",
+ "pk_user_ed25519": pk_ed_b, "pk_user_x25519": pk_x_b})
+
+ # Login before joining any group — groups should be empty
+ r = await client.post("/v1/users/login", json={
+ "username": "grp_bob", "password": "bobpass99"})
+ token_pre = r.json()["access_token"]
+ r_pk = await client.get("/v1/hub/pubkey")
+ hub_pk = r_pk.json()["pk_hub_pem"].encode()
+ decoded_pre = pyjwt.decode(token_pre, hub_pk, algorithms=["EdDSA"])
+ assert decoded_pre["groups"] == []
+
+ # Alice creates a group and adds Bob
+ alice_token = (await client.post("/v1/users/login",
+ json={"username": "grp_alice", "password": "alicepass99"})).json()["access_token"]
+ r = await client.post("/v1/groups", json={"name": "testgroup"},
+ headers={"Authorization": f"Bearer {alice_token}"})
+ group_id = r.json()["group_id"]
+
+ gek = generate_gek()
+ bundle = wrap_gek(gek, base64.b64decode(pk_x_b))
+ await client.post(f"/v1/groups/{group_id}/members/grp_bob/gek",
+ json=bundle,
+ headers={"Authorization": f"Bearer {alice_token}"})
+
+ # Login again — groups should contain the new group
+ r = await client.post("/v1/users/login", json={
+ "username": "grp_bob", "password": "bobpass99"})
+ token_post = r.json()["access_token"]
+ decoded_post = pyjwt.decode(token_post, hub_pk, algorithms=["EdDSA"])
+ assert group_id in decoded_post["groups"]
+
+ # Alice (admin) should also have the group in her JWT
+ r = await client.post("/v1/users/login", json={
+ "username": "grp_alice", "password": "alicepass99"})
+ decoded_alice = pyjwt.decode(r.json()["access_token"], hub_pk, algorithms=["EdDSA"])
+ assert group_id in decoded_alice["groups"]