diff options
Diffstat (limited to 'packages/meshbay-hub/tests/test_desktop_keyring.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_desktop_keyring.py | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_desktop_keyring.py b/packages/meshbay-hub/tests/test_desktop_keyring.py index e55e6d0..af7cc37 100644 --- a/packages/meshbay-hub/tests/test_desktop_keyring.py +++ b/packages/meshbay-hub/tests/test_desktop_keyring.py @@ -13,6 +13,7 @@ page, and a reference written from the specification in Python. import base64 import hashlib import json +import re import shutil import subprocess from pathlib import Path @@ -93,6 +94,9 @@ const v = JSON.parse(fs.readFileSync(input, 'utf8')); other_node: await refusal('join', { ...F.join, nodePk: 'T3RoZXJOb2Rl' }), other_account: await refusal('join', { ...F.join, userId: 'someone-else' }), stale: await refusal('join', { ...F.join, ts: ts - 3600 }), + root_add: await refusal('admin', { ...F.admin, op: 'root_add' }), + root_update: await refusal('admin', { ...F.admin, op: 'root_update' }), + group_attach: await refusal('admin', { ...F.admin, op: 'group_attach' }), }; const eph = require('crypto').generateKeyPairSync('x25519'); @@ -268,6 +272,24 @@ def test_the_page_names_a_kind_and_never_the_bytes(out): assert "not now" in r["stale"] +def test_what_widens_a_nodes_sharing_is_never_signed(out): + """Gone from MNP 6.0, and refused here as well: a node older than that + still accepts them, and a script in the page must not be able to get one + signed for it.""" + for op in ("root_add", "root_update", "group_attach"): + assert "not an operation" in out["refused"][op], op + + +def test_the_application_signs_exactly_the_nodes_operations(): + from meshbay_common import adminop + src = (Path(__file__).resolve().parents[2] / "meshbay-client" / "src" + / "transcripts.js").read_text(encoding="utf-8") + listed = set(re.findall(r"'([a-z_]+)'", + src.split("const ADMIN_OPS = new Set([")[1].split("]);")[0])) + catalogue = {v for k, v in vars(adminop).items() if k.startswith("OP_")} + assert listed == catalogue + + def test_nothing_is_sealed_for_a_browser_while_browser_access_is_off(out): for what, err in out["sealing_while_access_off"].items(): assert err and "browser access is off" in err, what |