aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_device_auth.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/tests/test_device_auth.py')
-rw-r--r--packages/meshbay-hub/tests/test_device_auth.py24
1 files changed, 22 insertions, 2 deletions
diff --git a/packages/meshbay-hub/tests/test_device_auth.py b/packages/meshbay-hub/tests/test_device_auth.py
index f9b172e..04012ee 100644
--- a/packages/meshbay-hub/tests/test_device_auth.py
+++ b/packages/meshbay-hub/tests/test_device_auth.py
@@ -46,10 +46,11 @@ async def _account(client, username="alice_test") -> str:
return resp.json()["access_token"]
-async def _register_device(client, token: str, pk: str, label: str = ""):
+async def _register_device(client, token: str, pk: str, label: str = "",
+ auth_key: str = "k" * 44):
return await client.post(
"/v1/users/devices",
- json={"pk_auth_ed25519": pk, "label": label},
+ json={"pk_auth_ed25519": pk, "label": label, "auth_key": auth_key},
headers={"Authorization": f"Bearer {token}"})
@@ -275,3 +276,22 @@ async def test_the_hub_states_a_minimum_client_version(client):
assert resp.status_code == 200
client_floor = resp.json()["client"]
assert client_floor["minimum"] and client_floor["recommended"]
+
+
+async def test_a_session_alone_cannot_register_a_device(client):
+ """
+ A registered key signs in with no passphrase for as long as it stays, and
+ each of those sign-ins carries the bundle pepper. So a token — refreshed,
+ or lifted from a page — must not be enough to add one: the passphrase is.
+ """
+ token = await _account(client)
+ sk, pk = _device()
+
+ bare = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk},
+ headers={"Authorization": f"Bearer {token}"})
+ wrong = await _register_device(client, token, pk, auth_key="w" * 44)
+
+ assert bare.status_code == 422
+ assert wrong.status_code == 403
+ assert (await client.post("/v1/users/auth",
+ json=_sign(sk, "alice_test"))).status_code == 401