aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_account_deletion.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/tests/test_account_deletion.py')
-rw-r--r--packages/meshbay-hub/tests/test_account_deletion.py37
1 files changed, 14 insertions, 23 deletions
diff --git a/packages/meshbay-hub/tests/test_account_deletion.py b/packages/meshbay-hub/tests/test_account_deletion.py
index 2653f0d..632c133 100644
--- a/packages/meshbay-hub/tests/test_account_deletion.py
+++ b/packages/meshbay-hub/tests/test_account_deletion.py
@@ -12,6 +12,7 @@ command.
import hashlib
import pytest
+from membership import add_member
from meshbay_hub.db.models import GroupMember, Notification, RefreshToken, User
from sqlalchemy import select
@@ -107,8 +108,7 @@ async def test_deletion_clears_memberships_notifications_and_tokens(
g = await client.post("/v1/groups", json={"name": "shared"},
headers={"Authorization": f"Bearer {owner_token}"})
gid = g.json()["group_id"]
- await client.post(f"/v1/groups/{gid}/members/member1_test", json={},
- headers={"Authorization": f"Bearer {owner_token}"})
+ await add_member(client, gid, 'member1_test', {"Authorization": f"Bearer {owner_token}"})
uid = (await db_session.execute(
select(User.id).where(User.username == "member1_test"))).scalar_one()
@@ -130,16 +130,9 @@ def _device_pk() -> str:
@pytest.mark.asyncio
-async def test_deletion_clears_device_keys_and_swarm_sources(client, db_session):
- """
- The privacy statement says every account row goes but the IP log. Swarm
- sources are keyed by the *user* id despite the column's name, and carry the
- node's transport and port — `webrtc:<port>`, which is what `daemon.py`
- actually sends. This asked with `192.0.2.7:4433`, from the days when the
- field was free text documented as "ip:port": a shape no node has ever
- produced, and one that let a caller name a third party's address.
- """
- from meshbay_hub.db.models import SwarmSource, UserDevice
+async def test_deletion_clears_device_keys(client, db_session):
+ """The privacy statement says every account row goes but the IP log."""
+ from meshbay_hub.db.models import UserDevice
token, password = await _register(client, "devicer_test")
headers = {"Authorization": f"Bearer {token}"}
@@ -147,17 +140,13 @@ async def test_deletion_clears_device_keys_and_swarm_sources(client, db_session)
select(User.id).where(User.username == "devicer_test"))).scalar_one()
r = await client.post("/v1/users/devices", headers=headers,
- json={"pk_auth_ed25519": _device_pk(), "label": "desktop"})
- assert r.status_code == 201, r.text
- r = await client.post("/v1/swarm/register", headers=headers,
- json={"content_hash": "ab" * 32, "endpoint": "webrtc:4433"})
+ json={"pk_auth_ed25519": _device_pk(), "label": "desktop",
+ "auth_key": _auth_key(password, "devicer_test")})
assert r.status_code == 201, r.text
# Present before, or the emptiness asserted below proves nothing.
assert (await db_session.execute(
select(UserDevice).where(UserDevice.user_id == uid))).scalars().all()
- assert (await db_session.execute(
- select(SwarmSource).where(SwarmSource.node_id == uid))).scalars().all()
r = await client.request("DELETE", "/v1/users/me", headers=headers,
json={"auth_key": _auth_key(password, "devicer_test")})
@@ -166,8 +155,6 @@ async def test_deletion_clears_device_keys_and_swarm_sources(client, db_session)
db_session.expire_all()
assert (await db_session.execute(
select(UserDevice).where(UserDevice.user_id == uid))).scalars().all() == []
- assert (await db_session.execute(
- select(SwarmSource).where(SwarmSource.node_id == uid))).scalars().all() == []
@pytest.mark.asyncio
@@ -180,15 +167,19 @@ async def test_a_new_account_can_reuse_the_deleted_accounts_device(client):
"""
pk = _device_pk()
token, password = await _register(client, "firstlife")
- r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk},
+ r = await client.post("/v1/users/devices",
+ json={"pk_auth_ed25519": pk,
+ "auth_key": _auth_key(password, "firstlife")},
headers={"Authorization": f"Bearer {token}"})
assert r.status_code == 201, r.text
await client.request("DELETE", "/v1/users/me",
headers={"Authorization": f"Bearer {token}"},
json={"auth_key": _auth_key(password, "firstlife")})
- token2, _ = await _register(client, "secondlife")
- r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk},
+ token2, password2 = await _register(client, "secondlife")
+ r = await client.post("/v1/users/devices",
+ json={"pk_auth_ed25519": pk,
+ "auth_key": _auth_key(password2, "secondlife")},
headers={"Authorization": f"Bearer {token2}"})
assert r.status_code == 201, r.text