diff options
Diffstat (limited to 'packages/meshbay-hub/tests/test_hub_api.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_hub_api.py | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_hub_api.py b/packages/meshbay-hub/tests/test_hub_api.py index ea59f17..568d5d9 100644 --- a/packages/meshbay-hub/tests/test_hub_api.py +++ b/packages/meshbay-hub/tests/test_hub_api.py @@ -261,3 +261,53 @@ async def test_non_admin_cannot_add_member(client): json=bundle, headers={"Authorization": f"Bearer {dan_token}"}) assert r.status_code == 403 + + +@pytest.mark.asyncio +async def test_jwt_contains_groups_claim(client): + """JWT must contain a 'groups' list with group_ids the user is a member of.""" + import jwt as pyjwt + pk_ed_a, pk_x_a, _ = _gen_user_keys() + pk_ed_b, pk_x_b, sk_x_b = _gen_user_keys() + + await client.post("/v1/users/register", json={ + "username": "grp_alice", "email": "ga@x.com", "password": "alicepass99", + "pk_user_ed25519": pk_ed_a, "pk_user_x25519": pk_x_a}) + await client.post("/v1/users/register", json={ + "username": "grp_bob", "email": "gb@x.com", "password": "bobpass99", + "pk_user_ed25519": pk_ed_b, "pk_user_x25519": pk_x_b}) + + # Login before joining any group — groups should be empty + r = await client.post("/v1/users/login", json={ + "username": "grp_bob", "password": "bobpass99"}) + token_pre = r.json()["access_token"] + r_pk = await client.get("/v1/hub/pubkey") + hub_pk = r_pk.json()["pk_hub_pem"].encode() + decoded_pre = pyjwt.decode(token_pre, hub_pk, algorithms=["EdDSA"]) + assert decoded_pre["groups"] == [] + + # Alice creates a group and adds Bob + alice_token = (await client.post("/v1/users/login", + json={"username": "grp_alice", "password": "alicepass99"})).json()["access_token"] + r = await client.post("/v1/groups", json={"name": "testgroup"}, + headers={"Authorization": f"Bearer {alice_token}"}) + group_id = r.json()["group_id"] + + gek = generate_gek() + bundle = wrap_gek(gek, base64.b64decode(pk_x_b)) + await client.post(f"/v1/groups/{group_id}/members/grp_bob/gek", + json=bundle, + headers={"Authorization": f"Bearer {alice_token}"}) + + # Login again — groups should contain the new group + r = await client.post("/v1/users/login", json={ + "username": "grp_bob", "password": "bobpass99"}) + token_post = r.json()["access_token"] + decoded_post = pyjwt.decode(token_post, hub_pk, algorithms=["EdDSA"]) + assert group_id in decoded_post["groups"] + + # Alice (admin) should also have the group in her JWT + r = await client.post("/v1/users/login", json={ + "username": "grp_alice", "password": "alicepass99"}) + decoded_alice = pyjwt.decode(r.json()["access_token"], hub_pk, algorithms=["EdDSA"]) + assert group_id in decoded_alice["groups"] |