diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-08-10 03:07:56 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-08-10 03:07:56 +0200 |
| commit | 4b3e8c3b8b9d10c8ac333dd8db614a7569052472 (patch) | |
| tree | 8828d7d549adc8bb21d8a7f6533c8e9db9c298b9 /packages/meshbay-hub/tests | |
| parent | 8ccbe262ecf4a8f7545cbf1e9f1cc5a485acae67 (diff) | |
| download | meshbay-4b3e8c3b8b9d10c8ac333dd8db614a7569052472.tar.gz | |
feat: Phase 7 — Node v2 (multi-group, Sender Keys, 0-RTT, chat, denylist)
Implements all 8 milestones (7.0-7.7):
- 7.0: JWT carries `groups` claim; node verifies group membership at
MNP handshake (QUIC + TCP+TLS). Resolves security review C2.
- 7.1: QUIC 0-RTT session resumption via stored session tickets
(17-21ms reconnect vs 47ms cold).
- 7.2: Hub→node WebSocket signaling for NAT punch coordination
(`client_incoming`/`punch_ready`) + jti denylist push. Denylist
class blocks revoked users/jtis at handshake.
- 7.3: Multi-group daemon — one QUIC port serves N groups with
per-group GEK, shared_root, and index routing.
- 7.4: HLS streaming via QUIC (STREAM_SEGMENT message type, ffmpeg
segment extraction).
- 7.5: Sender Keys protocol for group chat (Signal Groups approach).
Each member has own sending chain key, HKDF chain ratchet, AES-256-GCM
encryption, Ed25519 signing. Resolves security review C1.
- 7.6: Chat store (SQLite via aiosqlite), CHAT_MESSAGE MNP wire type
with peer broadcast, web UI with WebSocket push.
- 7.7: Argon2id calibration CLI.
First security review included (first-review.md). 109 tests, demo-v3
validated against meshbay.org production hub.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests')
| -rw-r--r-- | packages/meshbay-hub/tests/test_hub_api.py | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_hub_api.py b/packages/meshbay-hub/tests/test_hub_api.py index ea59f17..568d5d9 100644 --- a/packages/meshbay-hub/tests/test_hub_api.py +++ b/packages/meshbay-hub/tests/test_hub_api.py @@ -261,3 +261,53 @@ async def test_non_admin_cannot_add_member(client): json=bundle, headers={"Authorization": f"Bearer {dan_token}"}) assert r.status_code == 403 + + +@pytest.mark.asyncio +async def test_jwt_contains_groups_claim(client): + """JWT must contain a 'groups' list with group_ids the user is a member of.""" + import jwt as pyjwt + pk_ed_a, pk_x_a, _ = _gen_user_keys() + pk_ed_b, pk_x_b, sk_x_b = _gen_user_keys() + + await client.post("/v1/users/register", json={ + "username": "grp_alice", "email": "ga@x.com", "password": "alicepass99", + "pk_user_ed25519": pk_ed_a, "pk_user_x25519": pk_x_a}) + await client.post("/v1/users/register", json={ + "username": "grp_bob", "email": "gb@x.com", "password": "bobpass99", + "pk_user_ed25519": pk_ed_b, "pk_user_x25519": pk_x_b}) + + # Login before joining any group — groups should be empty + r = await client.post("/v1/users/login", json={ + "username": "grp_bob", "password": "bobpass99"}) + token_pre = r.json()["access_token"] + r_pk = await client.get("/v1/hub/pubkey") + hub_pk = r_pk.json()["pk_hub_pem"].encode() + decoded_pre = pyjwt.decode(token_pre, hub_pk, algorithms=["EdDSA"]) + assert decoded_pre["groups"] == [] + + # Alice creates a group and adds Bob + alice_token = (await client.post("/v1/users/login", + json={"username": "grp_alice", "password": "alicepass99"})).json()["access_token"] + r = await client.post("/v1/groups", json={"name": "testgroup"}, + headers={"Authorization": f"Bearer {alice_token}"}) + group_id = r.json()["group_id"] + + gek = generate_gek() + bundle = wrap_gek(gek, base64.b64decode(pk_x_b)) + await client.post(f"/v1/groups/{group_id}/members/grp_bob/gek", + json=bundle, + headers={"Authorization": f"Bearer {alice_token}"}) + + # Login again — groups should contain the new group + r = await client.post("/v1/users/login", json={ + "username": "grp_bob", "password": "bobpass99"}) + token_post = r.json()["access_token"] + decoded_post = pyjwt.decode(token_post, hub_pk, algorithms=["EdDSA"]) + assert group_id in decoded_post["groups"] + + # Alice (admin) should also have the group in her JWT + r = await client.post("/v1/users/login", json={ + "username": "grp_alice", "password": "alicepass99"}) + decoded_alice = pyjwt.decode(r.json()["access_token"], hub_pk, algorithms=["EdDSA"]) + assert group_id in decoded_alice["groups"] |