aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/group-page.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/group-page.js9
1 files changed, 5 insertions, 4 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
index 4510848..fe858b2 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
@@ -257,10 +257,11 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs,
setError('');
try {
// Same derivation as sign-in — the token is already ours, only the key
- // that opens node bundles is missing here, and the pepper that goes into
- // it is asked for with that token. Persisted so this browser is set up
- // from now on.
- const { pepper, version } = await window.MeshBayKeys.fetchBundlePepper(token);
+ // that opens node bundles is missing here. The hub hands the pepper that
+ // goes into it only against the passphrase proof, never the token alone.
+ // Persisted so this browser is set up from now on.
+ const authKey = await window.MeshBayKeys.deriveAuthKey(pass, username);
+ const { pepper, version } = await window.MeshBayKeys.fetchBundlePepper(token, authKey);
session.bundleKey = await window.MeshBayKeys.sessionBundleKey(
pass, username, userId, pepper, version);
await _storeBundleKey(session.bundleKey);