summaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_hub_api.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/tests/test_hub_api.py')
-rw-r--r--packages/meshbay-hub/tests/test_hub_api.py50
1 files changed, 50 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_hub_api.py b/packages/meshbay-hub/tests/test_hub_api.py
index ea59f17..568d5d9 100644
--- a/packages/meshbay-hub/tests/test_hub_api.py
+++ b/packages/meshbay-hub/tests/test_hub_api.py
@@ -261,3 +261,53 @@ async def test_non_admin_cannot_add_member(client):
json=bundle,
headers={"Authorization": f"Bearer {dan_token}"})
assert r.status_code == 403
+
+
+@pytest.mark.asyncio
+async def test_jwt_contains_groups_claim(client):
+ """JWT must contain a 'groups' list with group_ids the user is a member of."""
+ import jwt as pyjwt
+ pk_ed_a, pk_x_a, _ = _gen_user_keys()
+ pk_ed_b, pk_x_b, sk_x_b = _gen_user_keys()
+
+ await client.post("/v1/users/register", json={
+ "username": "grp_alice", "email": "ga@x.com", "password": "alicepass99",
+ "pk_user_ed25519": pk_ed_a, "pk_user_x25519": pk_x_a})
+ await client.post("/v1/users/register", json={
+ "username": "grp_bob", "email": "gb@x.com", "password": "bobpass99",
+ "pk_user_ed25519": pk_ed_b, "pk_user_x25519": pk_x_b})
+
+ # Login before joining any group — groups should be empty
+ r = await client.post("/v1/users/login", json={
+ "username": "grp_bob", "password": "bobpass99"})
+ token_pre = r.json()["access_token"]
+ r_pk = await client.get("/v1/hub/pubkey")
+ hub_pk = r_pk.json()["pk_hub_pem"].encode()
+ decoded_pre = pyjwt.decode(token_pre, hub_pk, algorithms=["EdDSA"])
+ assert decoded_pre["groups"] == []
+
+ # Alice creates a group and adds Bob
+ alice_token = (await client.post("/v1/users/login",
+ json={"username": "grp_alice", "password": "alicepass99"})).json()["access_token"]
+ r = await client.post("/v1/groups", json={"name": "testgroup"},
+ headers={"Authorization": f"Bearer {alice_token}"})
+ group_id = r.json()["group_id"]
+
+ gek = generate_gek()
+ bundle = wrap_gek(gek, base64.b64decode(pk_x_b))
+ await client.post(f"/v1/groups/{group_id}/members/grp_bob/gek",
+ json=bundle,
+ headers={"Authorization": f"Bearer {alice_token}"})
+
+ # Login again — groups should contain the new group
+ r = await client.post("/v1/users/login", json={
+ "username": "grp_bob", "password": "bobpass99"})
+ token_post = r.json()["access_token"]
+ decoded_post = pyjwt.decode(token_post, hub_pk, algorithms=["EdDSA"])
+ assert group_id in decoded_post["groups"]
+
+ # Alice (admin) should also have the group in her JWT
+ r = await client.post("/v1/users/login", json={
+ "username": "grp_alice", "password": "alicepass99"})
+ decoded_alice = pyjwt.decode(r.json()["access_token"], hub_pk, algorithms=["EdDSA"])
+ assert group_id in decoded_alice["groups"]