diff options
Diffstat (limited to 'packages/meshbay-hub/tests/test_account_deletion.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_account_deletion.py | 37 |
1 files changed, 14 insertions, 23 deletions
diff --git a/packages/meshbay-hub/tests/test_account_deletion.py b/packages/meshbay-hub/tests/test_account_deletion.py index 2653f0d..632c133 100644 --- a/packages/meshbay-hub/tests/test_account_deletion.py +++ b/packages/meshbay-hub/tests/test_account_deletion.py @@ -12,6 +12,7 @@ command. import hashlib import pytest +from membership import add_member from meshbay_hub.db.models import GroupMember, Notification, RefreshToken, User from sqlalchemy import select @@ -107,8 +108,7 @@ async def test_deletion_clears_memberships_notifications_and_tokens( g = await client.post("/v1/groups", json={"name": "shared"}, headers={"Authorization": f"Bearer {owner_token}"}) gid = g.json()["group_id"] - await client.post(f"/v1/groups/{gid}/members/member1_test", json={}, - headers={"Authorization": f"Bearer {owner_token}"}) + await add_member(client, gid, 'member1_test', {"Authorization": f"Bearer {owner_token}"}) uid = (await db_session.execute( select(User.id).where(User.username == "member1_test"))).scalar_one() @@ -130,16 +130,9 @@ def _device_pk() -> str: @pytest.mark.asyncio -async def test_deletion_clears_device_keys_and_swarm_sources(client, db_session): - """ - The privacy statement says every account row goes but the IP log. Swarm - sources are keyed by the *user* id despite the column's name, and carry the - node's transport and port — `webrtc:<port>`, which is what `daemon.py` - actually sends. This asked with `192.0.2.7:4433`, from the days when the - field was free text documented as "ip:port": a shape no node has ever - produced, and one that let a caller name a third party's address. - """ - from meshbay_hub.db.models import SwarmSource, UserDevice +async def test_deletion_clears_device_keys(client, db_session): + """The privacy statement says every account row goes but the IP log.""" + from meshbay_hub.db.models import UserDevice token, password = await _register(client, "devicer_test") headers = {"Authorization": f"Bearer {token}"} @@ -147,17 +140,13 @@ async def test_deletion_clears_device_keys_and_swarm_sources(client, db_session) select(User.id).where(User.username == "devicer_test"))).scalar_one() r = await client.post("/v1/users/devices", headers=headers, - json={"pk_auth_ed25519": _device_pk(), "label": "desktop"}) - assert r.status_code == 201, r.text - r = await client.post("/v1/swarm/register", headers=headers, - json={"content_hash": "ab" * 32, "endpoint": "webrtc:4433"}) + json={"pk_auth_ed25519": _device_pk(), "label": "desktop", + "auth_key": _auth_key(password, "devicer_test")}) assert r.status_code == 201, r.text # Present before, or the emptiness asserted below proves nothing. assert (await db_session.execute( select(UserDevice).where(UserDevice.user_id == uid))).scalars().all() - assert (await db_session.execute( - select(SwarmSource).where(SwarmSource.node_id == uid))).scalars().all() r = await client.request("DELETE", "/v1/users/me", headers=headers, json={"auth_key": _auth_key(password, "devicer_test")}) @@ -166,8 +155,6 @@ async def test_deletion_clears_device_keys_and_swarm_sources(client, db_session) db_session.expire_all() assert (await db_session.execute( select(UserDevice).where(UserDevice.user_id == uid))).scalars().all() == [] - assert (await db_session.execute( - select(SwarmSource).where(SwarmSource.node_id == uid))).scalars().all() == [] @pytest.mark.asyncio @@ -180,15 +167,19 @@ async def test_a_new_account_can_reuse_the_deleted_accounts_device(client): """ pk = _device_pk() token, password = await _register(client, "firstlife") - r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk}, + r = await client.post("/v1/users/devices", + json={"pk_auth_ed25519": pk, + "auth_key": _auth_key(password, "firstlife")}, headers={"Authorization": f"Bearer {token}"}) assert r.status_code == 201, r.text await client.request("DELETE", "/v1/users/me", headers={"Authorization": f"Bearer {token}"}, json={"auth_key": _auth_key(password, "firstlife")}) - token2, _ = await _register(client, "secondlife") - r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk}, + token2, password2 = await _register(client, "secondlife") + r = await client.post("/v1/users/devices", + json={"pk_auth_ed25519": pk, + "auth_key": _auth_key(password2, "secondlife")}, headers={"Authorization": f"Bearer {token2}"}) assert r.status_code == 201, r.text |